Growing threats from data theft, ransomware, and other cybercrime make effective authentication a critical control within identity and access management (IAM). IAM spans the full lifecycle of vetting individuals, issuing credentials, authenticating and authorizing access, and monitoring activity; among these, authentication needs particular attention because weak methods still dominate. Authentication commonly relies on “something you know,” “something you have,” and “something you are,” while mutual authentication adds confidence for users that the system itself is genuine, often leveraging PKI and X.509 certificates. As users and transactions become more mobile, single static authentication approaches—especially usernames and passwords—provide only low assurance and are easily compromised, driving demand for multi-factor and adaptive authentication that adjusts controls based on contextual risk (e.g., location, time, device).
Entrust Datacard’s IdentityGuard for Enterprise is positioned as a consolidated authentication platform spanning physical, logical, cloud, and mobile environments. It supports certificate-based authentication, smartcards and mobile smart credentials, biometrics, OTP tokens (including QR/challenge-response variants), grid cards, TAN lists, knowledge-based questions, out-of-band methods (SMS/email/voice and push with “Confirm/Deny/Concern”), and mutual authentication options such as image/message replay and EV SSL indicators. Adaptive capabilities include device and IP geo-location registration, device profiling, device reputation scoring against a repository exceeding 2 billion devices, and a risk analytics engine evaluating up to 50 risk data points with configurable weighting and behavioural profiling, plus integration with external fraud/analytics and cyber threat intelligence sources.
Strengths include broad authenticator coverage, lifecycle credential management from a single administrative point, federation/WAM integration (e.g., SAML, RADIUS, Kerberos), and SIEM export via syslog. Challenges include no built-in directory, lack of inbuilt user and entity behaviour analytics, limited out-of-the-box service request management integration, and some solutions being tailored heavily toward banking/finance. Support for FIDO authentication is planned.
See All Locations
See All Locations