Okta and OneLogin score high in test of eight SSO solutions that cut help desk calls and boost password security
We are awash in passwords, and as the number of Web services increases, things are only going to get worse. Trying to manage all these individual passwords is a major problem for enterprise security. Many end users cope by re-using their passwords, which exposes all sorts of security holes.
One solution is a single sign-on (SSO) tool to automate the logins of enterprise applications and also beef up password complexity, without taxing end users to try to remember dozens of different logins.
SSO isn’t new: we have had various products for more than a decade. What is new is that several products now combine both cloud-based SaaS logins with local desktop Windows logins, and add improved two-factor authentication and smoother federated identity integration.
Also helping is a wider adoption of the open standard Security Assertion Markup Language (SAML), which allows for automated sign-ons via exchanging XML information between websites.
Cloud-based single sign-on: A business perk for customers?
The SSO market includes more than a dozen products from boutique shops to large software vendors. We tested eight products: SecureAuth, OneLogin, Okta, Symplified, Intel’s McAfee Cloud Identity Manager, Numina Application Framework, SmartSignin and Radiant Logic. Several other SSO vendors were contacted but decided not to participate, including IBM, CA, Oracle and Ping Identity. (Watch a slideshow version of this story.)
The products all work in a similar fashion. First, they connect to one or more directory services, such as Active Directory, or an identity provider with an existing collection of users, such as Google Apps. They grab the user lists from these sources and then apply various rules in terms of what applications each user can access and whether they make use of advanced passwords, such as multifactor or one-time tokens to login to each app.
Users typically sign in to a Web-based portal, or the products grab their Windows desktop login credentials and use that as the basis for the authentication of the SSO app portfolio. This means that users don’t have to remember or even in some cases need to know what their Google or Box passwords are to gain access to these apps.
It sounds simple but there is a great deal of behind-the-scenes software magic to make all the logins operate seamlessly and to connect the dots among the different pieces. And all of the user data “grabbing” should happen over encrypted connections to prevent man-in-the-middle and other attacks.
Trials and Pricing
Most of the vendors we tested offer free trial accounts with certain limitations beyond the two weeks’ time frame, so you can get a feel for how they operate. And vendors are very willing to work with your own collection of apps to ensure that their products cover the ones you want to automate the sign-ons for. Some offer enticements such as unlimited number of users for a single app to deploy across your organization and get your end users used to the SSO apparatus, and then they start charging when you add new apps to the portal.
Vendors have somewhat different plans for their products. Some charge per user per month, others have more standard per-server site licensing fees. Some include live support for at least the regular workday, others only have online support and charge extra for live help past normal working hours. Some have different levels of pricing plans that cover a limited number of directory linkages, apps, or policy roles, and charge extra when you exceed these limits. Almost every vendor had incomplete pricing information published on their website, although SmartSignin’s pricing page was superior. SecureAuth has the most complex pricing scheme.
All this makes comparing and calculating the cost of a total SSO rollout difficult. Also know that these products aren’t cheap: plan on spending multiple tens of thousands of dollars annually for them, even for a relatively small installation. We have put together our best guess at what it would cost for a 500-seat installation for the first and subsequent years: some vendor’s fees drop significantly in the outlying years. The reason why we call it a guess is because given the way prices aren’t published online, it is clear that vendors often give discounts to get your business.
Cloud and on-premises winners
Two vendors rose to the top in our testing: Okta and OneLogin. Both were flexible, had great app and browser support, and handled sign ons for the widest variety of situations. These are mostly cloud-based products. The two best on-premises products were SecureAuth and McAfee.
Numina and SmartSignin are both from very small companies that are trying to break into the SSO space, and generally speaking need more work and polish. But Numina has superior reports and the nicest SAML settings sheets of any of the products, making it easier to set up websites that support that protocol. And SmartSignin has the most serious approach to keeping user data private of the products tested.
RadiantOne has very limited app support and its documentation could be better. On the other hand, RadiantOne and Symplified have impressive identity architectures that can handle a wide variety of situations, useful in cases where companies want to merge and still keep separate Active Directory forests, for example.
The subtleties with these SSO products can be daunting. For example, McAfee’s SSO product supports Adobe’s Echosign document signing service, but accounts must have their own subdomains for the SAML magic to work properly. The same is true for Box.net and Verisign’s VIP token service for Okta: you need the full enterprise account with subdomains enabled. So if you are trying to support users who already have their own individual accounts on these services, you might run up against problems.
Logins can be further protected with multiple-factor tools: these take the form of various hardware or software-based tokens. OneLogin and Okta have the widest multi-factor authentication support, including their own iPhone soft token apps, RSA’s SecurID, SMS text messages, Vasco tokens, Yubico YubiKey and browser certificates. This important because by using one of these tokens, you strengthen all of your associated logins through the SSO process, without having to constantly find a different multifactor token for each individual login circumstance.
However, each product employs multifactor tokens somewhat differently. Okta, Radiant Logic and OneLogin use it to protect the entire user’s account while McAfee, Symplified and SecureAuth can protect individual apps.
Speaking of multifactor tokens, there are additional issues. One of our test accounts was with Paypal using their supplied SecurID token. In order for any of the SSO products to login automatically to our account, we would first have to remove this token requirement. Some of the other SaaS services that use multifactor authentication, such as Google Apps and Facebook, might also need similar treatment to work with some of the SSO services.
One thing to also look at is how each product recovers from mistakes that you make in specifying the various login parameters. Given the amount of information that each product requires to enable SSO, it is easy to make small mistakes that can take time to find and correct. You will need to iterate back through the login process of the SSO in your own testing, to ensure that actual users can access their apps, and then make changes with the configuration screens in the management interfaces. Some, such as Okta, are particularly a problem here. This means if you test any of these SSO products on your live network, be careful. If you have set up your Active Directory failed login policy to lockout users after a small number of attempts, you might run into trouble while you are testing these products.
Individual reviews
Intel has rebranded its Cloud SSO offerings as part of its McAfee division, and it sells two versions: one cloud-based, which is newer and has fewer features, and one that installs on-premises.
The cloud version has fewer applications connectors: for example, it doesn’t support Office 365 yet. And the cloud version’s Active Directory integration is in beta at the moment. The cloud offering is based on the Force.com platform and there are no browser plug-ins needed.
The older on-premises version from McAfee has probably one of the largest collection of identity providers of any product we’ve seen, including AD, LDAP, Google, OpenID, Salesforce, various SQL databases and others.
One of the interesting things is how flexible and complex the product can be: you can set up separate policies for particular apps that connect to particular identity providers, and add two-factor authentication for just specific apps. If you are in need of its sophisticated policies, you probably want to only look at the on-premises version because it can do a lot more than what is offered in the cloud product.
As an example, you can restrict logins per app by IP address range, to specific mobile devices, and by day of the week and time of day. All of these settings are collected together into one place for easy configuration.
Both McAfee products allow for just-in-time user provisioning provided you have set things up correctly and exchanged the necessary digital certificates between McAfee and the intended SaaS app.
The online cloud documentation is rather sparse but the printed manuals go into more detail on how to setup both Google and Salesforce accounts on their service.
For both products, McAfee has one of the simplest pricing models around, albeit one that isn’t published on their website. They include everything in the per-user subscription fee, which starts at $5 per user per month and drops to $1 in quantity and over multiple years.
And by everything we mean live 24×7 support, as many application connectors or identity providers as you desire, and unlimited roles and policies. So pricing for 500 users would be $18,000 for one year. A three-year contract would drop the cost to $13,300 per year.
Numina had the smallest feature set of the products we tested. It is more of a developer’s toolkit than a fully complete product. It comes with both on-premises pieces, mainly a Web service that runs on an IIS server, and a cloud piece. Unlike most of the other products in this review, it doesn’t offer two-way synchronization with Active Directory or LDAP directories: it can only update its own user accounts. It also supports OpenID authentication methods.
Setting up an app that supports SAML, such as Google Apps, is very straightforward and the information to share with the corresponding fields on Google’s Web form is clearly displayed.
One limitation with SAML is that the user ID that Numina uses must match the ID that the app provider requires. This could be a big issue if you are going to use it to login to a lot of different SAML apps. The other products allow for more flexible configuration.
Numina supports a single multifactor authentication, SMS text message, although there are plans for more. However, it excels in the number of reporting choices, something the far more feature-rich products should take a closer look at.
Numina has a very simple pricing scheme, based on a single server license, so our sample 500 seats would cost $25,000 for the first year and a $5,000 maintenance fee for subsequent years.
Okta has been in the identity management business a long time, and it shows. They have mostly a cloud-based service with several pieces that are installed on your network, including browser plug-ins. There are clear workflow diagrams showing what you need to finish your tasks, and separate tabs for setting up apps and users and running reports. This is one of the best features of the product.
Okta has the ability to support two Active Directory connectors to the same directory store for redundancy. When you set these up they are read-only, but you can quickly turn on two-way synchronization. The Active Directory connector has its own user interface and monitoring application, and can be run from any Windows server. There is also a separate piece of software to handle the desktop Windows login integration that needs to be installed on an IIS server.
The product also has wide multifactor authentication support, including its own mobile soft tokens, a security question, and Google Authenticator. You can enforce the multiple factors when users are outside the corporate network, or for specific groups, but not for specific applications. And you can ask for the multiple factors on a specific time schedule (say once a day) too.
They have a unique feature called Just in Time provisioning. This means you can import all your Active Directory accounts and set things up so that when users are ready to start using their SSO solution, it will try to authenticate them with their Active Directory logins and create their accounts on the fly. This can be useful if you are turning on SSO for a large population at once.
Okta has excellent documentation, with plenty of screencast videos showing you how to set things up. They have a catalog of more than 1,000 apps that have already been pre-configured. There is also a table showing browser support that can be reached from the help screens inside the Okta app itself, a nice touch.
Reports show you the last month’s worth of app usage and suspicious activities and how many users have never signed into the system.
The Okta dashboard gives a range of application reports that can show unused apps for particular users. It also has a nice task list showing what you still need to do to on their service, alerts to any apps that weren’t setup properly, and other items.
Okta’s biggest downfall is how poorly it can recover from errors in the configuration process. Once you select an app you can’t actually delete it, just deactivate it. If you haven’t set it up properly this can give you fits. Okta claims this is a feature, to aid with its logging capabilities. We disagree.
Okta has several pricing plans, starting at $1 per user per month for basic SSO and moving up to $10 per user per month for enterprise-level features such as user provisioning and more detailed reports. Pricing for 500 users would be $60,000 for the first and subsequent years. Live 12×5 support is included, and there are three additional support plans if you want to go to 24×7 support.
OneLogin is a cloud-based service with several on-premises pieces including browser extensions, a special IIS-based authentication script that is used for Windows logins, and an Active Directory connector for Windows servers to establish the two-way directory synchronization.
It has one of the largest app catalogs, supporting more than 2,600 apps, and also has the ability to be easily customized for forms-based secure Web authentication by creating custom app connectors. That is a nice touch, because with some of its competitors, you either can’t create new app connectors or else you have to wait for the vendor to create them and add to the product.
One unique feature to OneLogin is a new addition called Federated Cloud Search. This makes it easier to find particular content across your entire apps portfolio without having to index each specific site. If you ever tried to look for a document in one of your SaaS-based providers, you will understand how effective this feature can be. Not all of OneLogin’s apps support this feature yet. Like some of its competitors, it also supports just-in-time app provisioning.
Another is the ability for an SSO administrator to login as a particular end user to do troubleshooting, called “assumed sign in.” You have to enable this individually by application, though. You don’t need to know the end user’s credentials but you can test out the access to a particular app.
The directory synchronization is very easy to setup, and OneLogin supports Active Directory, OpenLDAP, Google Apps and Workday. You can set up rules to map users to particular roles and groups.
Its documentation is awesome with loads of help files on a Zendesk server that has copious screen shots and illustrations on how to set up various services. There’s a large selection of reports including all provisioning activities, various ones on user status (suspended, active or whatnot), and a nice report on weak passwords. You can customize each report and download each as a CSV. There are also custom notification rules, so you can email users when they have been locked out of OneLogin, for example.
A wide variety of multifactor authentication methods is supported, including Yubikey, Verisign VIP, FireID, SecurID and OneLogin’s own mobile-based soft tokens. It can be required for every login or for unknown browsers, which is not as flexible as some of its competitors. Browser PKI certificates can be required as an additional factor. You can also prevent the browser from caching passwords for applications where OneLogin uses form-based authentication, a nice feature. Finally, it integrates with various SSL VPNs (we didn’t test this) and you can specify which apps can be accessed through the VPN gateway.
OneLogin offers several pricing plans, including a free plan for unlimited users with three company apps and limited online support. The $5 per user per month enterprise plan widens this to support unlimited roles and directories but only includes daytime live support: if you want 24×7 that bumps you up to $7 per user. That works out for 500 users to be $35,000 for the first year and subsequent years.
Radiant started in the directory management space and is slowly moving into SSO. Its solution is for on-premises, and has two main pieces: a Virtual Directory Server (VDS) that handles identity federation and a Cloud Federation Service (CFS) that handles applications.
CFS requires VDS to work: think of VDS as handling the authentication of the user’s identity, then CFS contains a bunch of secure tokens that can access your various apps. It isn’t as elegant as the other vendors, but it can be flexible if you understand which piece of software does what. There are a few other tools to set up the integration and deployment, such as the Radiant Trust Connector that handles the Windows desktop logins and the CFS Deployment Manager that does what its name says. Everything runs on Windows 2008 R2 Servers with at least IIS v7.5 and .Net Framework v4 and goes under the name of RadiantOne.
That is a lot of different pieces to keep track of. Each piece has its own printed documentation, so there is a lot to review and understand the various relationships before you can get started. If you are still running earlier Windows Server versions, this isn’t the product to upgrade them.
RadiantOne handles its trusted relationships with its apps via certificates that have to be downloaded and installed separately using the Deployment Manager. This means that users are authenticating once with CFS and then gain access to the various trusted apps. Using certificates is cumbersome but avoids the browser plug-ins that many of the other vendors use for encrypting the login credentials.
But as a result it offers a paltry set of apps that it can automate logins with, including Google, Salesforce, Webex, and a few others. There is no mechanism for secure Web access or automatically adding a new app, as there is with some of its competitors. You can also protect your user login with SecurID tokens too.
Reports are poor. There is a log export to Excel feature in CFS but that is more for events than anything a manager would understand. The dashboard is bare-bones and just indicates which services and connectors are running.
Pricing is based on a per-server basis: for 500 users it would be $25,000 for the first year and $6,250 for subsequent years, which includes 24×7 live support.
SecureAuth has a collection of on-premises pieces for its SSO product. You need to setup its own server on your network, and you can use one that comes as a virtual machine or run their software on physical hardware. Because of this you will need to review the documentation on how their SSO product interacts with the built-in Windows Server firewall and make sure both are configured properly. There are also browser extensions to download.
Its admin console is Web-based and perhaps the least attractive of all the products we tested, but beyond cosmetics it has lots of parameters and configuration options to make it a very powerful SSO product. The trick is in finding the right menu and place on the appropriate form to fill out properly. For example, to enable two-way Active Directory synchronization you set the “read only account” to false on the membership connection settings.
There are numerous multi-factor authentication methods that are supported, including Yubikeys, SMS text messaging, telephone, question and answer sessions, and email dialogs. Like some of its competitors, you can block or allow specific IP address ranges, and setup workflows depending on whether you are using a trusted computer or accessing your apps from a public network. It supports a wide range of identity providers including AD, Lotus Notes, OpenLDAP, Novell eDirectory and others.
SecureAuth has the most complex pricing plan of any of the vendors we tested. There is a per user fee, which starts out at $19.50 per user per year and can drop quickly to a few dollars a year for the largest installations. There are one-time per server and per-app fees, both of which start at $2,600. So for a 500-seat installation, the damage would be $20,000 for the first year and $10,000 for subsequent years. They need to simplify this scheme with far fewer options to make it more competitive, and understandable.
Like McAfee, SmartSignin has two separate offerings: one cloud-based and one for on-premises. The latter is only available at the higher Enterprise price. The product is still in beta and features are being added rapidly. They integrate with three identity providers at the moment: Google Apps, AD, and Salesforce.com. The company is small but seems to be on the right track.
For example, SmartSignin seems to be paying a lot of attention to various security exploits, which is a good thing. It is the only one of the SSO products we tested that not only requires a password but a separate passphrase that you and you alone have knowledge of, and that you have to enter when you sign-on to their SSO portal. All security information is stored on your desktop. Their Active Directory connector doesn’t transmit information in the clear in order to protect against man-in-the-middle attacks of your directory content.
They are weak in terms of browser support and are just getting started on their multifactor integration. The Enterprise package has a single option for out of band authentication using text SMS messages. They claim more than 400 applications are supported and pre-configured.
Their dashboard is well-designed and easy to navigate. There is a single report that is just a listing of events, which is less than satisfying.
Pricing for the Enterprise plan for 500 users would be $43,200 for the first and subsequent years. If you can do without the Enterprise features (multiple roles and on-premises server), then the Pro plan will bring this down to less than half that amount.
Symplified has two offerings: one that is cloud-based using an Amazon AMI and one that can be installed on-premises as a VM. Unlike the other vendors with separate offerings, Symplified has the same feature set. There are no browser extensions but the product has its own Active Directory connector called SimpleLink, which also supports LDAP connections and is a piece of software that has to be downloaded to any on-premises directory server. This creates a secure tunnel that encrypts the authentication requests.
Symplified calls its product an identity router and the term is apt, as there are lots of access rules and policies like you would see in your network firewall, but of course concerning identities. It supports a large collection of identity providers, which Symplified calls User Stores, including LDAP, Oracle, Salesforce, Netsuite, Google and various SQL databases.
Their app support isn’t as plentiful as it could be, but you can set up your own custom connector using the procedures and scripting features in the product. Apps have a rather convoluted workflow that isn’t as appealing as the other products and will take more time to debug and find configuration errors. This is because they separate the authentication from the authorization process. We needed some help with our configuration, but imagine that once you get the hang of it you can create what you need in a few minutes once you know how it all works. After you set up your SSO, you hit the publish button to deploy them explicitly. This adds an extra step in the debug cycle but we can understand why they have it included.
Their documentation is all online and hyperlinked to make it easy to navigate among the various pieces. Reports are more log files although some summary information can be found on the main dashboard page.
Symplified supports the following multifactor authentication products: Symantec VIP, Symantec VIP SSP, Cryptocard and GrIDsure.
Pricing has two components, a one-time setup fee ranging from $1,500 to $5,000, and a user fee. This works out for 500 users to be $21,000 for the first year and $18,000 for subsequent years, which is on the low end of the price scale. These prices include 24×7 live support.
What to look for in a single sign-on product
Each SSO service has four basic features:
1. There’s the single sign-on activity itself, the ability to automatically login to a particular SaaS-based website or on-premises server. There are several methods for accomplishing this: one is using a secure Web authentication script that sends a user name and password to the Web server to accomplish the login. This requires the SSO product to manually manage the login string: if you decide to change your password for your online banking site for example, you have to remember to change it in the SSO tool as well. A second, and more elegant method is to use one of the identity standards such as OpenID, Web Services Federation (WS-FED) or SAML. Not every SaaS site supports these standards, but more are getting on board every day as a result of the popularity of the SSO products.
Automating sign-ons is just one half of the equation. If you want all of your users at once to have enterprise Google Apps accounts, you also need to be able to initiate provisioning from the SSO product, otherwise you are going to be in for some tedious times. Not every SaaS vendor supports automated provisioning from every SSO product.
This is where a third authentication method comes into play, exchanging site certificates between the SaaS provider and the SSO vendor. While this is initially cumbersome, it can make the process go faster when you want to automate user creation and provisioning to the SSO process. Radiant Logic uses certificates exclusively as their authentication method. The others offer some combination of SAML, secure Web forms, and custom applications connectors.
Some of the products also make use of browser-based plug-in extensions to handle the login tasks.
2. Second is the ability to work with Active Directory or some other directory service or identity provider to handle user logins to local desktops and other on-premises servers. This means that you can automatically recognize the groups of user accounts, such as network administrators. Some products can do two-way synchronization of user accounts with Active Directory so that as you add or delete users from one, your actions are matched on the other side. Other products support federated identity synchronization with outside networks, such as setting up a partner portal so that individual logins from your partner organizations don’t need to be manually created on your SSO system.
Each product typically installs one or more pieces of Windows server software to handle the Active Directory synchronization tasks. We describe the details on how this is accomplished in each review. Some also limit the amount of Active Directory information that is stored or transmitted in the cloud for security reasons too.
3. Third is the ability to manage roles of each user and their respective access permissions to various apps. Each product has varying ways of accomplishing this, typically through particulars in their Web-based management consoles. Some also use the Active Directory group identities as the basis of how they configure their SSO roles and policies. McAfee has the most flexible configuration rules, and can setup individual apps with a particular identity provider and choose whether each app needs to have two-factor authentication.
4. Finally there is how each product handles reports and compliance actions. Some products have more graphical or summary reports than others. These products offer the opportunity for you to track exactly how many users are using particular applications, so if you are paying for site licenses, they could save you money if you can reduce your license counts.
How we tested single sign-on products
We set up each product with two sample user accounts and tried to automate logins to a series of hosted services and on-premises servers, including Google Mail and Apps, Box.net, Paypal, Microsoft Active Directory, SharePoint and Office 365 (for testing WS-FED), Salesforce.com, LinkedIn, Twitter, Windows login and an online banking site. Each product supported a different collection of applications for SSO activities. We also connected to a variety of cloud-based services along with a test Windows Server from Cloudshare.com. We connected via different desktops, browsers, and mobile clients (if supported) to see how each would handle the various site logins. We also looked at what it would take to automatically provision new users on a number of SaaS vendors, and how they interacted with other identity providers.
We used two desktops: a MacBook running OS 10.6.8 and a Dell running Windows 7 Professional 32-bit. In addition, we also used both an iPad and an iPhone 4 running iOS v5.1 for testing the mobile features. The tests were conducted during November 2012.
Strom is a veteran technology journalist, speaker and former IT manager. He has written two books on computing and thousands of articles. His blog can be found at Strominator.com.




