Does Microsoft multi-factor authentication provide the features that your business requires?
Free, bundled IAM solutions are all well and good, but if you need granular security controls – have not yet fully adopted cloud – or need complete MFA coverage across your network – SecurEnvoy can help.
SecurEnvoy provides flexible, easy to administer Identity & Access Management and MFA, that can help you secure identities across your whole environment, which can be deployed:
Securing the MFA logon process for Windows and Windows Hello is not always straightforward, for example, Windows Hello for Business also requires an internet connection for logon, restricting certain offline situations.
SecurEnvoy Windows Logon agent provides MFA access to Windows directly, remotely or offline, covering:
In addition, for environments, which include MacOS, SecurEnvoy MacOS Logon Agent can be deployed to protect these endpoints giving the same full MFA functionality. The risk of unauthorised access can be reduced across your whole organisation.
Many companies still have on-premise environments that are protected by a VPN or other remote access, which are supported by the RADIUS protocol.
Microsoft Azure MFA does support RADIUS, but requires other components, such as Network Policy Server (NPS), which increases complexity. In addition, the RADIUS capability is limited and does not always work well with all vendor VPNs.
SecurEnvoy offers a fully featured RADIUS capability enabling:
Microsoft Azure AD MFA has limitations in the granularity options it provides, which lead to challenges striking a balance between security and user experience. Most organisations need a broad range of authentication methods to address their specific business needs and based on group and user profiles.
SecurEnvoy is able to offer a range of authentication methods, a single view of user authentication, user self-service and location-based authentication.
Authentication ranging from biometrically protected smartphone apps through to hardware tokens and simple SMS OTP.
SecurEnvoy Universal Directory, at the core of SecurEnvoy IAM, can simplify multiple directory environments and consolidation projects. The Universal Directory acts as the Identity Provider (IdP), creating a single digital user identity, and providing visibility of all identities along with the applications and resources they have access to.
SecurEnvoy Universal Directory synchronises bi-directionally across multiple directories, so that if a user is disabled in any directory, all access will be disabled, in real-time, from all other directories. Universal Directory supports a wide range of directory types, including Microsoft AD, Azure AD, Google Workspace, and more.
SecurEnvoy’s dedicated Customer Experience Team is available to help, with all calls directed to experienced second and third line technical service engineers, who have first-hand knowledge of our customers’ environments. Our support staff work closely alongside our development team to offer a consultative service and unique solutions to specific business issues.