See All Locations
For both AA and Cloud MFA, many organizations need to gather additional attributes about users and their environments and evaluate the attributes in the context of risk-based policies. The goal of AA & Cloud MFA is to provide the appropriate risk-mitigating assurance levels for access to sensitive resources by requiring users to further demonstrate that they are who they say they are. This is usually implemented by “step-up” authentication or transactional authorization. Examples of step-up authenticators include phone/email/SMS One Time Passwords (OTPs), mobile apps for push notifications, mobile apps with native biometrics, FIDO U2F/UAF/2.0, SmartCards, and behavioral biometrics.
The factors just listed as examples can be used to define variable authentication policies. More advanced forms of AA and Cloud MFA use risk-scoring analytics algorithms to first baseline regular access patterns and then be able to identify anomalous behavior which triggers additional authentication challenges.
In the first part of the webinar, John Tolbert, Lead Analyst at KuppingerCole, will delve into these features in more detail, as they pertain to both on-premises and SaaS deployments. He will also describe our Leadership Compass methodology, the criteria used for analyzing products and services in these fields, and show selected results from the Leadership Compass reports.
In the second part, you will have the opportunity to ask questions about KuppingerCole’s latest Leadership Compass on this topic.