E-Guide DO YOU HAVE THE RIGHT AUTHENTICATION

Transcription

E-GuideDO YOU HAVETHE RIGHTAUTHENTICATIONTOOLS TO KEEPTHE BAD GUYSOUT?SearchSecurity

DO YOU HAVE THE RIGHT AUTHENTICATION TOOLS TO KEEP THE BAD GUYS OUT?HomeThe top multifactorauthenticationproductsEMC RSAAuthenticationManager andSecurID Multifactorauthenticationproduct overviewMbe acritical component of an enterprisesecurity strategy. In this e-guide, we takea look at the top MFA products in theindustry to help you make the right purchasing decision for yourorganization.PA G E 2 O F 1 6ultifactor authentication canSPONSORED BY

DO YOU HAVE THE RIGHT AUTHENTICATION TOOLS TO KEEP THE BAD GUYS OUT?THE TOP MULTIFACTOR AUTHENTICATION PRODUCTSJames Miller, Senior Products EditorHomeThe top multifactorauthenticationproductsEMC RSAAuthenticationManager andSecurID Multifactorauthenticationproduct overviewMultifactor authentication (MFA) is a method of boosting IT security that requires end users to provide multiple methods of identification to confirm theiridentity for gaining access to corporate resources and applications, as well asperform online transactions. By requiring an additional factor beyond a simplepassword (such as software on a smartphone, a fingerprint, a voiceprint, a keyfob or a security code), MFA technology makes it far more difficult for hackersto exploit the login process and wreak havoc by stealing corporate, customer orpartner data -- even when a password has been compromised or shared amonga number of different services by an end user.Organizations that have made (or are in the process of making) the decisionto deploy MFA technology should bone up on the criteria for evaluating andprocuring multifactor authentication products. That way, when it comes timeto select the right MFA product, the company will be well-versed on what MFAproduct features best match the use cases (Active Directory augmentation,strong identity verification and/or the strengthening of Web server logons)PA G E 3 O F 1 6SPONSORED BY

DO YOU HAVE THE RIGHT AUTHENTICATION TOOLS TO KEEP THE BAD GUYS OUT?HomeThe top multifactorauthenticationproductsEMC RSAAuthenticationManager andSecurID Multifactorauthenticationproduct overviewthat apply to its environment and authentication needs.With so many vendors offering MFA products and services, choosing theright product can be overwhelming -- no matter how knowledgeable and prepared an organization is going into the evaluation process. Here is a list of thetop multifactor products in the market to help get enterprises started.EMC RSA AUTHENTICATION MANAGER AND RSA SECURIDRSA SecurID -- the token-side EMC RSA Authentication Manager -- is theMFA product that has been around the longest. It has a large number of supported applications that can be secured with its multiple factors and has thelargest market share of hardware tokens. For its part, EMC RSA Authentication Manager can be set up for some very complex token approval workflows,and it sports a self-service Web portal that end users can use to perform common token management tasks. To learn more about EMC RSA AuthenticationManager and RSA SecurID, read the full review.SYMANTEC VALIDATION AND ID PROTECTION SERVICELike EMC RSA, Symantec is a top-tier multifactor vendor that has been in theMFA game a long time. Symantec Validation and ID Protection Service (VIP)PA G E 4 O F 1 6SPONSORED BY

DO YOU HAVE THE RIGHT AUTHENTICATION TOOLS TO KEEP THE BAD GUYS OUT?HomeThe top multifactorauthenticationproductsEMC RSAAuthenticationManager andSecurID Multifactorauthenticationproduct overviewsupports a wide selection of hardware and software tokens, including desktopand smartphone apps (using both SMS service and voice calls). And, not onlydoes the service provide more than 30 different integration methods for common apps, its credentials are so popular, they are currently used to authenticate more than 100 different websites. To learn more about the Symantec VIPService, read the full review.CA STRONG AUTHENTICATIONCA Strong Authentication from CA Technologies comes in both a Windowsversion and as a Software as a Service (SaaS) version called CA Secure Cloud.It includes full administration capabilities to configure policies, monitor activity and investigate suspected attacks, making it easier to keep track of tokensand to understand which applications support tighter MFA security. A moreunique feature to Strong Authentication allows organizations to not store ortransmit passwords. This, in effect, makes passwords "unbreachable." To learnmore about CA Strong Authentication, read the full review.VASCO IDENTIKEY SERVER AND DIGIPASSIDENTIKEY Server includes multifactor software tools and DIGIPASS tokensPA G E 5 O F 1 6SPONSORED BY

DO YOU HAVE THE RIGHT AUTHENTICATION TOOLS TO KEEP THE BAD GUYS OUT?HomeThe top multifactorauthenticationproductsEMC RSAAuthenticationManager andSecurID Multifactorauthenticationproduct overviewfrom Vasco Data Security Inc. As one of the most comprehensive MFA products on the market, it supports a wide selection of token and server types,mobile operating systems and smartphones, and authentication methods.Meanwhile, in addition to providing authentication plug-ins for Outlook WebAccess, Citrix, Microsoft's Internet Information Web Server and Remote Desktop Web interfaces, Vasco offers an API-based product that allows customers tointegrate multifactor authentication into existing applications. To learn moreabout Vasco Identikey Server and DIGIPASS, read the full review.SECUREAUTH IDPSomewhat unique among the products in this article (Okta Verify is the onlyother one), SecureAuth IdP is both a multifactor and a single sign-on authentication product. So in addition to offering a solid array of MFA features, suchas support for multiple hardware and software tokens, organizations can connect SecureAuth IdP to directory services such as Active Directory to allowusers to sign into a Web-based portal that authenticates them for a portfolioof applications. That way these users don't have to remember -- or even know(in some instances) -- their individual passwords for these programs. To learnmore about SecureAuth IdP, read the full review.PA G E 6 O F 1 6SPONSORED BY

DO YOU HAVE THE RIGHT AUTHENTICATION TOOLS TO KEEP THE BAD GUYS OUT?DELL DEFENDERHomeThe top multifactorauthenticationproductsEMC RSAAuthenticationManager andSecurID Multifactorauthenticationproduct overviewAcquired with Dell's acquisition of Quest Software, Dell Defender is a mid-tierauthentication product that combines a good assortment of features with support for the common multifactor use cases at good price. When an organizationenables users, they can go to a self-service portal to either request a softwaretoken or register a hardware token. Defender also integrates with Dell's CloudAccess Manager, which supports Security Assertion Markup Language loginsto cloud-based services and extends multifactor authentication to those services. To learn more about Dell Defender, read the full review.SAFENET AUTHENTICATION SERVICEThe SafeNet Authentication Service supports a wide variety of token, mobileand desktop authenticators. The service is also unique in that it supports aninteresting "grid" hardware-based token that asks users to type in a patternand offers subscription-based pricing, which includes a single copy of its serversoftware and one SMS token per user. This makes it easier for organizationsto calculate expected deployment costs. In addition, SafeNet has the mostextensive policies, role assignments and user groups of any of the MFA products highlighted in this article, which makes it easier for IT to set up differentPA G E 7 O F 1 6SPONSORED BY

DO YOU HAVE THE RIGHT AUTHENTICATION TOOLS TO KEEP THE BAD GUYS OUT?authentication levels for different individuals and groups. To learn more onSafeNet Authentication Service, read the full review.HomeThe top multifactorauthenticationproductsEMC RSAAuthenticationManager andSecurID Multifactorauthenticationproduct overviewOKTA VERIFYLike SecureAuth IdP, Okta Verify is both an MFA and SSO product. As an MFAtool, it adds security measures to standard username/password logins to avariety of servers and services. And, as an SSO tool, it allows end users to signinto a Web-based portal that serves as the basis of the authentication of an organization's SSO app portfolio. Unlike other MFA products, Okta has a uniquefeature called Just in Time provisioning that allows customers to import alltheir Active Directory accounts and set authentication up so that when endusers are ready to start using the SSO component, Verify can attempt to createtheir accounts on the fly. To learn more on Okta Verify, read the full review.CONCLUSIONAll the products highlighted in this article are solid MFA platforms. They support multiple token types and provide flexibility in terms of authenticationmethods supported.There are differences between them, however -- including in pricing,PA G E 8 O F 1 6SPONSORED BY

DO YOU HAVE THE RIGHT AUTHENTICATION TOOLS TO KEEP THE BAD GUYS OUT?Homeadministration and reporting -- and in how they support mobile devices andnew technologies like risk-based authentication and standards such as FIDO.So it behooves organizations that are looking to deploy multifactor authentication technology to take all those elements and more into consideration whenmaking an MFA product selection.The top multifactorauthenticationproductsEMC RSAAuthenticationManager andSecurID Multifactorauthenticationproduct overviewPA G E 9 O F 1 6SPONSORED BY

DO YOU HAVE THE RIGHT AUTHENTICATION TOOLS TO KEEP THE BAD GUYS OUT?EMC RSA AUTHENTICATION MANAGER AND SECURID MULTIFACTOR AUTHENTICATION PRODUCT OVERVIEWHomeThe top multifactorauthenticationproductsEMC RSAAuthenticationManager andSecurID Multifactorauthenticationproduct overviewDavid Strom, ContributorRSA Authentication Manager from EMC is a multifactor authentication (MFA)software tool that adds additional security measures (via smartphones andbiometrics) to standard user name/password logins for a number of servicesand servers. By doing so, it prevents unauthorized logins, even when passwordshave been compromised and were shared among many different services.Like a number of other MFA products examined in this series, EMC RSAAuthentication Manager is especially suitable for those organizations thatwant to make use of a variety of external software as a service (SaaS) products,such as Google Docs, Salesforce.com and Outlook Web App.SecurID is the token side of RSA Authentication Manager and handles theconfiguration of the individual tokens. Given the wide range of token types supported, IT managers will want to spend some time with this tool to understandhow it works.PA G E 1 0 O F 1 6SPONSORED BY

DO YOU HAVE THE RIGHT AUTHENTICATION TOOLS TO KEEP THE BAD GUYS OUT?AUTHENTICATION MANAGER PRICING AND LICENSINGHomeThe top multifactorauthenticationproductsEMC RSAAuthenticationManager andSecurID Multifactorauthenticationproduct overviewRSA offers two different licenses for Authentication Manager: base and enterprise. A base license supports one replica of the primary user data store,while the enterprise license supports up to 15 different replicas for better loadbalancing and backup purposes.The retail price is nearly ten times as expensive as the least pricey MFAproducts, such as CA's Strong Authentication. This includes a perpetual software license and an annual fee for the software tokens. The quote price inthe table below doesn't include an annual maintenance contract, which addsanother 1,785 to the fee. Additional tokens cost 17 per user per year. AndRSA sells Authentication Manager primarily through more than 500 channelpartners worldwide, not directly.PA G E 1 1 O F 1 6SPONSORED BY

DO YOU HAVE THE RIGHT AUTHENTICATION TOOLS TO KEEP THE BAD GUYS OUT?EMC RSA AUTHENTICATION MANAGER AND SECURIDHomeThe top multifactorauthenticationproductsEMC RSAAuthenticationManager andSecurID Multifactorauthenticationproduct overviewToken typesSMS text messages, mobile app, email message, hardware tokensServer typesA physical or virtual applianceMobile OS/phonesupportWindows Phone, Apple iOS, Android, BlackBerryAuthenticationmethodsRadius, Active Directory, web code, (SAML support with AdaptiveFederation Manager)PricingFor 100 tokens 11,050, and a free 90-day trial for 25 users.AUTHENTICATION MANAGER ADMINISTRATION AND MANAGEMENTIn addition to the various ways the software can be licensed, there are manybasic pieces to RSA multifactor authentication: Authentication Manager, which is the server side providing the authentication management tasks and the self-service user portal,PA G E 1 2 O F 1 6SPONSORED BY

DO YOU HAVE THE RIGHT AUTHENTICATION TOOLS TO KEEP THE BAD GUYS OUT? Adaptive Federation Manager, used for Security Assertion Markup Language (SAML) logins,HomeThe top multifactorauthenticationproductsEMC RSAAuthenticationManager andSecurID Multifactorauthenticationproduct overview Various agents for Web servers (including a Microsoft ManagementConsole snap-in), and SecurID, which handles the token management.RSA SecurID is the market leader in terms of the following: It has beenaround the longest has a large number of supported applications that can besecured with its multiple factors (see table above), and it has the largest marketshare of hardware tokens -- with over 25,000 deployments with more than 55million tokens in service.Most of these products have Web-based management front ends, which isnice, but use various user interfaces, which is not. EMC RSA customers can buythese multifactor authentication servers as virtual machines or as hardwarebased appliances.There is an administrative dashboard, which provides a consolidated viewof a particular user: what tokens they have assigned, what groups they belongPA G E 1 3 O F 1 6SPONSORED BY

DO YOU HAVE THE RIGHT AUTHENTICATION TOOLS TO KEEP THE BAD GUYS OUT?HomeThe top multifactorauthenticationproductsEMC RSAAuthenticationManager andSecurID Multifactorauthenticationproduct overviewto, what protected resources they can access and what authentication activitythey have performed in the last seven days.Navigating around the admin console is somewhat painful, given the numerous configuration options and menu branches. Admin can easily get lost ifhe or she isn’t familiar with the workflows.RSA Authentication Manager can be set up for some very complex tokenapproval workflows, reflecting its long-standing support for a wide collectionof various types of hardware tokens from third-party partners. This can beuseful if a company wants lost or additional token requests to be approved byadministrators. There is also a self-service Web portal that end-users can bringup for common token management tasks, such as the ability to reset PINs ormove from hardware to software-based tokens.Another good feature: Because of Authentication Manager’s popularity,there are numerous managed service providers who offer a hosted version ofthe software. This makes for a very powerful ecosystem to support EMC’s RSAmultifactor authentication solution.AUTHENTICATION MANAGER REPORTINGReports are one of the weak areas of Authentication Manger. While there arePA G E 1 4 O F 1 6SPONSORED BY

DO YOU HAVE THE RIGHT AUTHENTICATION TOOLS TO KEEP THE BAD GUYS OUT?more than 30 of them, most are glorified log files. These reports can be scheduled and exported in numerous formats, however, which is a plus. There arealso real-time monitors of authentication and system activities.HomeThe top multifactorauthenticationproductsEMC RSAAuthenticationManager andSecurID Multifactorauthenticationproduct overviewAUTHENTICATION MANAGER APPLICATION SUPPORTRSA Authentication Manager supports a wide variety of applications and usecases, including VPNs, Outlook Web App, Salesforce, Sharepoint, MicrosoftIIS and others. It claims more than 400 application partnerships with leadingindustry vendors, so RSA can support nearly any technology in place today.There is also a web agent, which can sit on a web server and direct authentication requests to the EMC RSA Authentication Manager server. This expandsthe ability to authenticate home-grown applications that aren’t explicitly supported via other methods.CONCLUSIONEMC RSA’s MFA product has been around a long time and offers a wide varietyof token types, supported applications and workflow and use methods. Whilesome of the user interfaces are showing their age, this is still a solid, if somewhat pricey solution for handling multifactor authentication.PA G E 1 5 O F 1 6SPONSORED BY

DO YOU HAVE THE RIGHT AUTHENTICATION TOOLS TO KEEP THE BAD GUYS OUT?FREE RESOURCES FOR TECHNOLOGY PROFESSIONALSHomeThe top multifactorauthenticationproductsEMC RSAAuthenticationManager andSecurID Multifactorauthenticationproduct overviewTechTarget publishes targeted technology media that addressyour need for information and resources for researching products, developing strategy and making cost-effective purchasedecisions. Our network of technology-specific Web sites givesyou access to industry experts, independent content and analysis and the Web’s largest library of vendor-provided white papers, webcasts, podcasts, videos, virtual trade shows, researchreports and more —drawing on the rich R&D resources of technology providers to addressmarket trends, challenges and solutions. Our live events and virtual seminars give you access to vendor neutral, expert commentary and advice on the issues and challenges youface daily. Our social community IT Knowledge Exchange allows you to share real worldinformation in real time with peers and experts.WHAT MAKES TECHTARGET UNIQUE?TechTarget is squarely focused on the enterprise IT space. Our team of editors and network of industry experts provide the richest, most relevant content to IT professionals andmanagement. We leverage the immediacy of the Web, the networking and face-to-face opportunities of events and virtual events, and the ability to interact with peers—all to createcompelling and actionable information for enterprise IT professionals across all industriesand markets.PA G E 1 6 O F 1 6SPONSORED BY

EMC RSA Authentication Manager and SecurID Multifactor authentication product overview. DO O HAE THE RIGHT ATHETICATIO TOOS TO EEP THE AD GS OT. AUTHENTICATION MANAGER PRICING AND LICENSING. RSA offers two different licenses for Authentication Manager: base and en-terprise. A base license