Centrify edges Okta and OneLogin in seven-vendor shootout.
Since we last looked at single sign-on products in 2012, the field has gotten more crowded and more capable. A number of new vendors have come to ply their wares, and a number of old vendors have been acquired or altered their products.
For this round of evaluations, we looked at seven SSO services: Centrify’s Identity Service, Microsoft’s Azure AD Premium, Okta’s Identity and Mobility Management, OneLogin, Ping Identity’s Ping One, Secure Auth’s IdP, and SmartSignin. In addition to these products, we also looked briefly at AVG’s Business SSO.
Several vendors declined to participate, including NetIQ, WSO2, Covisint, CA, Janrain, RSA, Radiant Logic, SalesForce and Sailpoint. We also did not focus on open-source identity management tools or consumer-grade products, like LogMeIn.
Here are our overall conclusions:
— First, products have expanded their support for additional authentication factors. Three years ago, one additional factor was about what you could expect beyond user name/password. Now, all of the products have solid multifactor authentication (MFA) protection. Okta and Centrify have even created their own one-time password mobile apps. SecureAuth, Okta, Ping and Centrify can specify MFA for particular applications as part of a risk-based authentication approach. This makes using SSO a powerful protective tool and can make logins much more secure than relying on individual users to choose passwords individually.
— Second, as Gartner analysts recently pointed out, the vendors are moving towards integrating mobile device management (MDM) as part of their identity service offerings. Gartner sees a bright future when the two types of products are better integrated, and we agree. While not yet as capable as a true MDM tool, SSO tools such as Okta, Ping and Centrify have a better mobile focus and could be a good choice if you want to protect your mobile endpoints with more than just their login passwords, but don’t want to purchase a separate MDM solution.
— Third, when we looked at these products in 2012, most were just moving into the cloud. Now, all but SecureAuth are focused on their cloud-based solutions. Vendors typically supply two URLs: one for users for a common login to their apps, and another one for IT administrators for management tasks. This means these products have only a small footprint for their on-premises software, mostly for handling Active Directory synchronization and browser extensions.
— Next, these products have deepened their support for multiple identity management providers. Vendors have also gotten more serious about publishing their own identity APIs and SDKs. That along with the ability to reach into the Active Directory schema means that it is now easier to automatically provision hundreds of users at once with very little operator intervention. This makes SSO tools especially useful if you have to onboard a lot of staff quickly.
— Finally, almost all of the products now support thousands of applications for their automated sign-on routines and some come with catalogs that you can browse to find your particular apps. Overall the products are getting easier to install and integrate into your existing collection of apps and servers.
Our Clear Choice test winner is Centrify, but not by much. It slightly outperforms the others in terms of features and reports. Both Okta and OneLogin (our winners from 2012) aren’t far behind. The others fall somewhat below these in terms of features, documentation, or usability.
Here are the individual reviews:
NET RESULTS
| Vendor |
Features and Flexibility |
Documentation and Reports |
App Support |
Total |
|
Centrify Identity Service | 4.5 | 4.5 | 4.5 | 4.5 |
|
Microsoft Azure AD Premium |
3 | 2.5 | 3.5 |
3 |
|
Okta Identity and Mobility Management |
4 | 4.5 | 4.5 | 4.3 |
|
OneLogin | 3.5 | 4.5 | 4.5 | 4.2 |
|
Ping Identity Ping One |
4 | 2.5 | 4.5 | 3.7 |
|
Secure Auth IdP | 4.5 |
3 | 3.5 | 3.7 |
|
SmartSignin |
3 |
3 |
4 | 3.3 |
Centrify Identity Service
Centrify has put together a solid SSO tool that also has some terrific mobile device management (MDM) features. If you are in the market for both kinds of products, this should be on your short list. It outscored the other tools, although not by much in some cases.
As a side note, Centrify sells a version of its SSO software to several vendors, including Samsung and AVG. (See sidebar on AVG.)
| AVG Business SSO AVG purchased their SSO code from Centrify and has slightly repackaged it as its Business SSO service that the company launched earlier this year. Mostly it follows the same menu structures and configurations. They have added a few features to address their target market, which is the SMB and MSP space. This is handled via a separate Customers tab in the admin interface, where you can set up separate identity providers for each of your customers. Each customer gets his own instance of the SSO tool and the overall MSP or reseller is the only one who can see the individual accounts. Otherwise, the AVG product is identical to the Centrify one, and charges $3 per user per month for large installations. AVG’s SSO tool is one element of a collection of other tools that are designed for MSPs under its Business Managed Workplace line. This also includes backup and disaster recovery, and an outsourced help desk service. |
The admin user interface is well thought-out with tabs clearly labeled for apps, policies, and devices, among others. Set up was quickly accomplished within a few minutes. The hardest parts were getting the MFA features and Active Directory integration, neither of which was difficult once we understood what the product wanted from us.
Centrify has been around the Active Directory space for several years and its integration is fairly seamless. Once you download the connector and install it on your Windows Server, there isn’t much to do. You can set up active/active redundant support for a second Active Directory server by just installing a second or third connector: these take care of doing the load balancing of Active Directory authentication requests and automatically failover if there is some connection issue. It supports Windows Servers since the 64-bit 2003 vintage. It also supports Integrated Windows Authentications so you can sign into your local Windows desktops and apps.
In addition to Active Directory, Centrify also supports LDAP, SAML, and other identity providers. Adding a new one is very straightforward, once you find the menu options to set everything up. Browser extensions are available from a drop-down menu on the top right, and you just click on the appropriate one for your browser to download.
MFA settings are set in the policy tab for users and in the apps tab for individual apps. Both share the same set of screens: they have different features depending on the OS type. This means that there is one set for OS X, another for iOS, and so forth. This is somewhat inconvenient and means you have to enter some of the same information multiple times. The MFA choices are numerous: you can specify whether it should be deployed if a login is coming from outside the normal corporate IP address space or from a machine that has never used Centrify’s SSO before (through the absence of a browser cookie). It adds factors such as email, SMS texts and phone calls, and security questions. More importantly, you can turn off MFA for a few minutes to enable a forgetful user to login and reset their accounts, a nice touch.
Centrify will prompt new users to add one (and only one) security question. There is also support for Centrify’s OTP feature that is built into its smartphone app. Missing is support for third-party OTP tokens that some of the other tools have.
Speaking of the mobile app, it is a full MDM solution and not just an OTP generator like some of its competitors. You can remotely wipe the device, put policies in place for requiring a device PIN, and set up other things that you would expect on a traditional MDM product.
Centrify comes with dozens of canned reports that cover the waterfront, along with the ability to create your own using custom SQL queries. Its documentation is available online and presents the basics for getting started.
Centrify has a large collection of apps and admins can add new ones into its password vault by logging into the app from a browser. There are 17 different entries for various Google-related apps, including UK and Japanese versions, only one of which is SAML provisioned. Its Web app gateway can handle internal Web server links very cleverly, without the need to connect up via VPN or poke holes in your firewall.
Centrify’s pricing is very transparent (see this webpage). There are two versions of the service: App for $4 per user per month and App+ for $8. If you want support for Apple-based devices, add another $2 a month.
Microsoft Azure Active Directory Access Control
Earlier this year Microsoft added Azure Active Directory to its collection of cloud-based offerings. It is difficult to setup because you tend to get lost in the hall of mirrors that is the Azure setup process: the Active Directory services haven’t yet been integrated into the main Azure management portal, and different bits of the Azure functionality come with different menu collections that aren’t easily navigated from one place to another.
+ ALSO: Microsoft goes all-in on hybrid cloud with Azure-in-a-box +
But once you have it working you can see that it is designed mostly for supporting cloud-based apps that you have created using federated identity by exchanging various certificates. It is still very much a work in progress and mainly a developer’s toolkit rather than a polished service. But clearly Microsoft has big plans for Azure AD, as its new Windows App Store is going to rely on it for authentication.
Azure AD supports several identity providers, including Windows Live ID, Facebook, Google, Yahoo, JSON Web Tokens, OpenID, SAML, and WS-Fed. Getting this setup will require careful study of a series of documents on MSDN. It also comes with a downloadable AD Connector that installs various pieces of software, including a local SQL Server on a local Windows AD Forest.
Like some of the other products, Azure AD has a SaaS app catalog that you can browse to add SSO, and a search for Google brings up more than a dozen references. You then add it to your portal page with a simple three-step process to enable the sign-on relationship, enable automatic provisioning and assign particular users to that app.
Administrators have three choices on how the sign-on happens: either by establishing a federation between Azure and the app service provider, by having Azure store the user’s account credentials, or by using some other existing SSO relationship. There are more than a dozen different reports, including account provision activity, irregular sign-ons, and sign-ons from multiple locations.
An additional piece to Azure AD is the Cloud App Discovery. This downloads an agent to Windows 7 and 8 PCs and allows you to inspect network traffic to determine which SaaS apps they are accessing.
Azure AD Premium has MFA and relies on the former PhoneFactor MFA server, which is a separate Windows application but has now been integrated with the overall Azure service. It is far more limited than the other vendors’ MFA tools, although it does offer a one-time bypass feature if a user is locked out of their account. The MFA feature is available for $1.40 per month per user with unlimited authentications, if you don’t have the Premium subscription. It can be deployed as an on-premises server or in the Azure cloud and it works with numerous non-Microsoft SaaS apps.
If you already are using Azure for other purposes, then it makes sense to take a closer look at what Azure AD will buy you and whether your developers can incorporate its SSO tools into your homegrown apps. If you are looking for a general purpose SSO portal that you can deploy for a wide variety of SaaS-based applications, then you should probably look elsewhere.
Azure AD has three pricing options. The free version is included with an Azure or Office 365 subscription and can provide SSO for up to 10 apps per user. There are also basic and premium subscription levels (the latter for unlimited apps that also includes the SSO for no extra charge, which is probably the preference for most enterprises) that are covered by various Microsoft corporate purchase agreements or online for $6 per user per month.
Okta Identity and Mobility Management
Okta was one of the top scored products in our 2012 review and it still is very capable. Okta had an impressive user interface back then and it remains very simple to navigate, with tabs for Apps, Directory, and Security that make sense. However, it has several weaknesses that dropped its overall score this time around.
+ ALSO: Salesforce.com Identity tackles only the ‘really easy’ stuff, Okta CEO says +
For one, it spreads its identity provider provisioning all over its interfaces: Under the directory tab you can add either Active Directory or LDAP domains, and for the former you’ll need to download and install its AD Domain Agent to your Windows Server 2003 R2 or later. It took a call to their tech support to activate this agent. Once you connect to a local Active Directory domain, you next import and assign users. The process is a bit more involved than Centrify.
Then if you want to add SAML authentication, you need to go to a separate tab and download the Okta certificate to get that working. Speaking of downloads, all the various bits of code that you can download are collected together under a single menu tab, including the mobile MFA apps and browser extensions. That is handy.
Like Centrify and some others, Okta offers a Windows desktop SSO tool that works with Integrated Windows Authentication, so once you sign in to Windows, you are already authenticated.
Okta’s main user sign-in screen has a tabbed interface, allowing corporations to segregate their apps into ones they manage and ones that are specific to individual end users.
Over the past several years, Okta has beefed up its MFA functionality. It now offers a mobile app, Okta Verify, as a one-time password generator. It also supports other MFA methods, including Google Authenticator, SMS texts, Symantec VIP, RSA SecurID and Duo Security tokens, along with choosing from a list of security Q&A. MFA credentials can be demanded every time, or periodically or for specific groups. They also can be set up to protect particular apps.
Okta has its own mobile app that can provide a secure browsing session and allow you to sign in to your apps from your phone, just as you would do from your desktop. It contains some MDM functionality, although it is not as capable as a full MDM tool.
Reports have been strengthened as well, and can be accessed from both the main dashboard and its own tab. There are now 11 preset report types, including showing unused applications. That can come in handy when it is time to renegotiate your software licenses. But reports only show the last 30 days. In the right-hand panel next to report selections is a summarized system log showing the past 30 days of events in various categories.
Like some of its competitors, you browse an applications directory and can search to find them to add to your overall corporate-approved apps. This includes several VPN gateways that support either SAML or RADIUS connections. When we searched on Google-related apps we found 10 “Okta verified,” meaning they have been tested by the vendor.
Okta has added the ability to quickly change the language used on its forms into one of three different languages, with more being added later this year.
Pricing for Okta is also very transparent with this webpage. There are several different editions, beginning at $2 per user per month. The enterprise version, which includes MFA and user provisioning, costs $8 per user per month. This includes basic support: premium 24×7 support is extra. MDM features add an additional $4 per user per month.
OneLogin
OneLogin was the other co-winner of our 2012 review and while it is still strong, its user interface has become a bit unwieldy and it has fallen in terms of our overall score. There are only four top menu choices: users, apps, activity and settings, the latter where most of the tool’s actual work is accomplished.
Once you get to its policies section (Settings/Security/Policies), you can create ones for either user-based or app-based, which is where you add MFA rules and restrictions based on IP addresses and other details. This means that OneLogin makes it easy to add risk-based authentication for users and apps.
One of the reasons OneLogin was a favorite in our original review was its impressive self-registration workflow options. These are still present, although some of the other vendors, such as SecureAuth, have now exceeded its capabilities.
As a testimonial to its longevity, OneLogin also has numerous SAML toolkits in a variety of languages such as .Net, Java and Ruby to make it easier to integrate your apps into its SSO routines. If you have homegrown apps and you want to make use of this protocol, this is reason enough to consider them on your short list. Another illustration of this is that there are 42 Google-related apps, nine of which were SAML-based. It also has specific configuration screens to set up a VPN login and take you to specific apps.
OneLogin’s AD Connector requires all of the various components of Net Framework v3.5 to be installed. Once that was done, it was a simple process to install its agent and synchronize our Active Directory with its service. One nice feature is that you are prompted to install a second agent as a failover to another instance of Active Directory. Their connector also makes use of the IIS Web server to handle desktop SSO connections too.
The service has 11 canned reports and you can easily create additional custom ones using four templates. These are a bit clunky until you get used to the interface. One of these reports summarizes weak passwords, which is a nice addition. All of its browser extensions can be downloaded at this link.
OneLogin has a very transparent although somewhat complex pricing page. You can start out with a “free forever” trial account that doesn’t include MFA and other advanced features but might be useful to try it out. Impressively, this includes unlimited users and up to right protected apps. If you want to purchase a paid plan, the starter account is $2 per user per month that includes MFA for a minimum of 25 users, the enterprise account is $4 per user per month that adds some enterprise features for a minimum of 10 users, and an unlimited account for $8 per user per month that unlocks all features for a minimum of five users. The two more expensive plans include premium 24×7 phone support.
Ping Identity PingOne
Ping has been in the identity management space for many years and has some of the largest customers around the world. When they began they were mostly an on-premises solution with their PingFederate product, but recently the company has focused on the cloud and offer a series of related products including its cloud-based PingOne, its web access tool PingAccess and its OTP soft token generator PingID. Ping Identity also has a mobile app where you can access your portal page. While that is a lot of different software bits to keep track of, they can be flexible in supporting lots of different circumstances.
PingOne supports four identity providers: its own through either Ping Federate or PingOne, Google’s OpenID using OAuth, Active Directory through its own connector, or a third-party SAML connector. The Active Directory connector needs .Net Framework v4 to work. We had no trouble installing it, but talking to their tech support we found that most of Ping’s customers are using Ping Federate to provide the Active Directory connection for additional identity connections.
MFA support is somewhat limited in PingOne. You can use its own OTP generator, called PingID or SafeNet’s OTP tokens. You can add the additional factors to all signins or to particular applications using the Authentication Policy Editor page under the setup tab. If you want more factors, you have to purchase the on-premises Ping Federate product.
A dozen Google-related apps came up in their directory, five of which supported SAML connections. It has more than 1,600 apps in the directory. When you select a SAML-based app, you see a step-by-step series of instructions, complete with illustrated screenshots, that will take you through the process to get things working. Reports are not this product’s strong suit. The dashboard gives you an attractive summary, but there isn’t much else.
Like several products, the browser extensions are requested when you first login with a link to download the extension.
Ping would be a stronger product if they would consolidate some of their various features and focus on the cloud as a primary delivery vehicle. If that isn’t important to you, or if you have complex federation needs, then you should give them more consideration and you will probably end up with using their on-premises Ping Federate.
Pricing starts at $2 per user per month for PingOne.
SecureAuth IdP
Out of all the products we tested, SecureAuth has the most flexibility and the worst user interface, a combination that can be vexing at times. But it is in use in some very large installations.
SecureAuth is the only holdout of the products tested that has to run on a Windows Server. We tested it in an Amazon instance that the company had setup for us. At its heart are a series of authentication realms, which while adding another degree of freedom to how it can be deployed, adds another degree of complexity to setting it up.
So, about that interface, which is supposed to get a refresh later this year. It is easy to get lost in its series of cascading menus, and while it remains a very capable product, others have passed it by in terms of ease of configuration.
When you first bring up its admin interface, you will see a series of tabs across the top. Sadly, these tabs don’t bear directly on the actual tasks you will need to perform. For example, the Overview tab is where you adjust the look and feel of your portal pages and set up the languages and particular text that are displayed for your users. The Data tab is where you specify the identity providers as well as map your Active Directory schema into various properties for SecureAuth to use. As before, there is a long list of providers, including some (sadly, nowadays) obscure ones such as Novell eDirectory and Sun ONE among others. And you can also make use of your existing Facebook, LinkedIn, and other social networking accounts as a provider too, with SecureAuth stepping up the authentication to make things more secure.
The Workflow and Registration Methods tabs are both needed to configure any MFA support: the former is where you tell SecureAuth how and when to deploy them, such as for an initial login or for a particular app instance; the latter is where you tell the tool how to communicate with the user over the particular factor, such as a OTP soft token or an SMS message.
The real strength of SecureAuth always has been with its various post-authentication workflow activities. There is a large list of actions that can happen after your users authenticate themselves, and it has gotten larger since we last looked at them. For example, you can bring a user to an app store catalog or have them check a near-field communications tag, launch a mobile app or take them directly inside IBM’s Websphere. There are dozens more choices, and this is all under another tab with that name.
To make this work, you’ll also want to understand where to put the various bits of app-specific information into IdP. They have published several dozen different guides that walk you through the process. This is enormously more complicated than the other SSO tools, but is also more capable. SecureAuth can help you if you want to enable something not in their catalog.
Finally, the Logs tab is where you can find its poor substitute for actual reports. This is still another major weakness of SecureAuth.
Going back to SecureAuth’s MFA support, it has a wide selection of factors and tokens to choose from, including Symantec VIP and Yubikey tokens along with its own OTP soft token, SMS, email and as many security questions as your users can bear. Again, this is a testimonial to its flexibility, and it is tied in directly to its support for various risk-based authentication methods, such as checking for geo-location differences between logins or adding IP address restrictions. One of these factors is a specialized browser fingerprint that does more than just set a cookie, but looks at the specific browser and OS code versions that the user last used to authenticate themselves. None of these comes very easily in terms of setup, however.
SecureAuth charges for its server and then separately for its users. A sample 100-user configuration would cost $5,940 the first year.
PerfectCloud SmartSignin
SmartSignin has been acquired by PerfectCloud and integrated into its other cloud-based security offerings, including its secure file transfer product SmartCyptor. Since we last looked at them in 2012, they now support seven identity providers (including Amazon, Netsuite and AD) with several more on the horizon and more than 7,000 app integrations.
Adding apps is similar to some of the other products, where you search for them in a catalog. When we looked for Google-related ones, we found five listed. Once you select an app, you can select users for it. When you examine the list of all your apps selected, there are a series of very small action icons associated with each application: to change the users who have access, to share credentials, to add the SSO credentials for the app (whether they would use a SAML certificate or just a stored username/password pair) and to suspend the app. This is somewhat tedious, although it looks nice on the screen. The same series of action icons is shown in the user listing screen.
The identity providers make use of SAML or other federated means, and come with extensive installation instructions to get you started. This is a little more complex than some of its competitors. They have a nine-step getting started wizard that makes onboarding very straightforward. As part of this wizard, there are also a series of video tutorials that explain the various configuration steps, and extensive context-sensitive help that can be optionally displayed on the right-hand sidebar of each screen. While all of this is helpful, they have only three reports available: a summary of users, an audit report, and an overall summary. Reports can be exported to Excel.
When it comes to MFA support, SmartSignin is the weakest of the set of products we reviewed, which is ironic because the company pioneered having a second passphrase back in 2012 and still make use of it to login to their SSO portal. There is also a knowledge-based series of questions that you can enable as an additional factor. They are working on other MFA methods, including SMS and voice, but didn’t have them at the time we tested their product. Also, MFA is just for protecting your entire user account, there is no mechanism for protecting individual apps.
Like the other products, it has both an AD connector and browser extensions to download. The AD connector requires you to open Port 9753 for it to communicate with their cloud server. If you haven’t installed the browser extension, you are automatically prompted at your first login. That is a nice touch. The product also has a series of what it calls “webhooks” that are RESTful APIs that you can call from any internal or external applications to provision identities and apps.
They have three pricing plans that you can get details online: free for individuals, a $6 per user per month business plan and an $8 per user per month for enterprise. You can sign up for any of these for free for 15 days.
A word about AD synchronization
All seven SSO tools interact with your on-premises Active Directory installation, but have various subtle differences. Since we looked at these tools in 2012, they have come a long way. While all of the products (except SecureAuth) have separate executable agents that need to be downloaded and then installed on a Windows Server, there are important differences that an enterprise IT manager should understand.
Because SecureAuth is an actual Windows application, it communicates via LDAP to the Active Directory store. You’ll need to open Port 389 so they can communicate with each other. Some of the products (such as Okta. Microsoft and Centrify) have the ability to reset Active Directory passwords from within their own user portals, which means one less IT support call when the user forgets theirs. Others (such as OneLogin) have lengthy instructions that require careful study to get their agents up and running, or make downloading the agent more difficult. Centrify and OneLogin both offer two-way synch with Active Directory while Okta has one-way imports from Active Directory.
How we tested single sign-on services
We used a similar test plan to our 2012 review, but also focused on the user experience, both from the end user and from the IT administrator perspectives. We set up each product with a few sample user accounts and tried to automate logins to a series of hosted services and on-premises servers, including Google Mail and Apps, Box.net, SharePoint, Office 365, Salesforce.com, LinkedIn, Twitter, Windows logins and an online banking site.
We tested each product to a local Windows Server 2012 running as a domain controller with its own Active Directory forest, and looked at how each product connected to the AD-based users we had already set up.
We connected via different Windows and Mac desktops, browsers, and mobile clients (if supported) to see how each would handle the various site logins and browser extensions to save user names and passwords. We also looked at what it would take to automatically provision new users, and expire old users such as for dealing with terminated employees.




