HID DigitalPersona (formerly Crossmatch) provides a comprehensive multi-factor authentication solution. The vendor’s value proposition is that their solution frees users from cumbersome login activities while making it easy for an IT Team to secure access to their networks, data and applications.
$3.75
per user per month
WatchGuard AuthPoint
Score 9.1 out of 10
N/A
AuthPoint Total Identity Security provides businesses with a solution to protect user accounts and credentials. With
multi-factor authentication and dark web credential
monitoring, AuthPoint mitigates the risks associated with workforce credential
attacks. AuthPoint adds an extra layer of security by monitoring for
potential credential exposure in the dark web for both personal and corporate
accounts.
I know its not a direct competitor but HID is better in all the sense its amazing because of its integration with Microsoft Azure AD. It has overall better functionality as it doesnt work on cloud premises it can also be used on premises. The best part is one can use mfa …
We've been using HID DigitalPersona for so long that I honestly can't recall what other products we did investigated. We have been satisfied with the app for a very long time, therefore we don't see the need to explore other options.
It has a greater advantage than Okta because it gives a variety of verification options and allows biometrics logging in, which is something the other software does not, in my suggestion.
HID DigitalPersona is selected against them as it has a reliable and a great secured software which has a versatile access to other platforms as well which saves a lot software to be taken and HID DigitalPersona is a one stop solution to all problems it has everything a …
Our use of HID DigitalPersona has been for long that I really can't remember what other products we looked at. We have happy with app for a very long time thus I don't see the need to look at other possibilities.
Not proper usage with AWS but HID has been really versatile it just works as we need to login to system has become really easy and fast because of it. The multi factor authorization gives you the freedom to chose from a variety of authentication methods such as biometric login, …
In comaprison to okta its better suited as it has array of authentication methods and it also offers login via biometric which according to me is not present in the other software.
They both are great and offer great features such as single sign on and top, but HID DigitalPersona is ahead of Ping identity because it offers Biometrics as well and it can also work in offline setting as well.
Strong authentication, multifactor authentication, biometrics, and integration set HID DigitalPersona apart, making it an excellent option for a range of authentication requirements.
I don't have excessive experience with One login, but it wasn't as feature rich as HID DigitalPersona. The best part about HID DigitalPersona is that it can be used in offline settings as well.
HID serves all our purposes and is not that expensive its integration with microsoft active directory makes it super helpful. It is loaded with features that are not just for show off but actually works its a great software and we dont think any other software can match its …
HID DigitalPersona is a great software from others as it provides a great security and trusted 2 factor authentication which helps in creating a system integrator with trust and ease of use it has been proved to be a great software by it's easy and accessible user interface …
HID provides better integration option more authentication options and its easier to use. The integration which helps HID the most is Azure's active directory it makes HID better in all regards. It acts as a centralized system to protect all the resources and data of your …
Okta Workflows (previously Azuqua) focuses on application integration and workflow automation while HID DigitalPersona stresses authentication security and compliance.
The benefit of HID DigitalPersona is it uses a biometric method for authentication. It can be integrated with Azure which means it is more features reach and offers multiple factor authorization and SSO.
A number of factors, including HID DigitalPersona's extensive range of authentication methods, easy integration with Microsoft Active Directory, support for a variety of use cases, robust compliance and security features, and affordable pricing or licensing models, may make it …
We have used HID DigitalPersona for over 8 years and have been so satisfied with the product that we just haven't even looked because we like the product that much.
We went the other direction. DigitalPersona was our initial implementation, but we have moved away from DigitalPersona and moved to a product called TecMFA. Our organization has implemented Okta as our application and Azure as our multifactor authentication platform, and …
We use different 2FA providers to secure different things. We are actively using Duo now, as well as WatchGuard AuthPoint. Each provider has different strengths, and you must test the applicability of a service in your own environment.
Started looking at Yubikeys and RSA, but WatchGuard AuthPoint had complete package instead of piecemealing tokens with one vendor and then using softkeys from Microsoft or another vendor.
The biggest reason we selected Watchguard was support. We already use Watchguard firewall products and have received excellent support from our third-party vendor, Watchguard.
If you already have WatchGuard firewall, this just integrates a lot better than any other product. We tried Microsoft Authenticator but not nearly as seemless for the experience as it is with WatchGuard AuthPoint. It is all built into the same portal as the firewall and can be …
WatchGuard AuthPoint is less expensive than most competitors, easier to manage through WatchGuard Cloud, and the MFA solutions is rock solid and secure. We do not worry about vulnerabilities with WatchGuard AuthPoint.
We reviewed and tested Duo, but having already WatchGuard products, and WatchGuard AuthPoint also having more capabilities, we ended up with them. One less vendor to deal with and also knowing them for a long time and having a great relationship was the key factor to move …
We have chosen WatchGuard AuthPoint because we are gold partner and we know very well all their products. In the past we have used Safenet but we think that with Watchguard we can get a better solution to protect devices and network. End users don't need to learn difficult …
AuthPoint integrates with our WatchGuard driven security stack, and is therefor the obvious choice. Competitive pricing. One vendor means streamlined implementation and management, streamlined support.
Watchguard integrates easily into active directory which makes it very versatile. There are a lot more options inside of watchguard Authpoint versus DUO mobile authentication. It also works a lot better on end user devices in my opinion. The reliability of both products are top …
We investigated Fortinet IAM but found it costly and complex. Atuthpoint was less expensive, the mobile client was preferred by staff. The cloud console was also easier to use.
The nature of OpenVPN is that the passwords are stored on the firewall and are static. With Single Sign-On, the passwords change on schedule and complexity, length and time are set by Active Directory policy
During the onboarding process, remote workers can enroll their fingerprints or create secure PINs. This eliminates the need for complicated passwords and enables them to safely access company resources and critical apps from remote locations. HID DigitalPersona's robust authentication techniques and access control features can assist you in adhering to data security laws.
While I cannot speak of the functionalities that we do not use, the 2nd factor authentication has been great. It's actually secure, I can control it all remotely, users don't mind the extra step, and management feels more at ease knowing that we have full access control. The VPN for remote connections is fast and stable, it stays connected during network oddities and has plenty of bandwidth.
Works well with the free Authpoint client and the OpenVPN clinet.
Token management is simple and hosted completely in the cloud to reduce overall complexity
Setup was simple and and staighforward
Suppports several authentication methods we have used both RADIUS and SAML effectively, but ADFS, IDP, RDWeb, and RESTful API, and other custom apps are supported.
Geofencing for RDP has been very useful as it is independant of our firewall geofencing. This is quite useful for organizations like us who do not Geofence at at the firewall level so as to provide global access to resources on the DMZ.
Multiple domains - DigitalPersona struggles with multiple domains. Since the solution is licensed per domain, migrating users between domains can be troublesome to keep licensed. Additionally, migrating to a new domain removes the AD leaf objects that store all digital persona information, essentially wiping out and credentials or other stored information.
Password change - DigitalPersona can be confusing to update when a stored password for a website is updated. The password is entered, and then the user is redirected to the websites password change page. Users must then authenticate with a Digital persona credential again before being prompted by Digital Persona to update the password. If the user is allowed to change the password manually through the websites page, this will lead to what is stored in Digital Persona being out of sync with the new password, and eventually account lockouts.
Terminal Server - DigitalPersona has performance issues when utilized on a high-traffic terminal server. Often it causes big CPU spikes as well as hanging sessions upon disconnect.
Integration with on-premise AD is not working, even after speaking with the support team, it could not get resolved. There is no better documentation on this topic as well
Integration with Azure AD is not supported without the presence of on-prem AD
Logs information is not precious, it provides a generic code in some cases, making it harder to troubleshoot.
The Watchguard AuthPoint App in AppStore has some issues, after it's activated there is no approval request being sent to the phone, and there is no way to troubleshoot this, the only way to make it work is by uninstalling the app and reinstalling it again.
It is wonderful for multifactor authentication and gives us many options for what we use to authenticate. All of our users use it and it is engrained into our group policies and people would be very disappointed if it went away.
We are very happy with Authpoint and see no reason to make any change to it. If only there was a policy to set minimum password strength requirements and to force users change their password every xx days, then it would be a 10!!!
I think there are still fundamental enhancements needed to be added to the management consoles and I think there ought to be a Centralized, Windows Based "Thick" Management Application instead of individual utilities which vary from MMCs, Scripts, Wizards, etc.
After initial setup, it practically runs itself. Onboarding new users is fast and easy as it should be. The AuthPoint mobile app is small and simple to use. The only reason I do not give it a 10 is that I frequently get complaints from end users that the AuthPoint app is "constantly downloading". In fact, it's not downloading anything and that what the users are seeing in the app is a timer for the 6-digit code that changes every minute.
Extremely poor; I've never encountered such. Professional Services completely dropped us for months. Crossmatch tech support seems like it has 3 techs tops! No response to emails, calls, the absolute worst! I will never recommend DP to anyone.
WatchGuard support is always quick and reliable. They have urgency levels that you are able to select when creating your support ticket, and they respond in accordance to the severity that you have set. I have never had an issue with getting someone on the phone in the same business day, even for very low priority issues.
It was an Onsite demo at the ditributor with the benefits of Watchguard Authpoint. Was very nice to see the abilities of the product. This Demo was a few years back, since then Authpoint changed allot. It is very nice for partners that you can get this demo without any aditional cost.
We use the online training for all our employees. There are both sales and technical trainings available and there even is a technical certification. You can use this for the Watchguard Partner Program which can give you aditional benefits. Every now and then you have a webinar that discusses multiple Watchguard products.
Could use tools to audit license usage at a more granular level as to allow an administrator to free up licenses from users whom seldom use their biometrics to login.
the first time it takes more effort. It is helpful to already understand how each authentication type works. Then it's much easier to understand the MFA solution that you implement. It is useful to check the release notes from time to time and update the key parts of the Watchguard Authpoint. Authpoint Gateway, Logon App, RDWeb... Also, it's useful to set up notifications when something goes wrong or sometimes check the statistics of how many requests are being approved/denied, etc.
We evaluated Cisco DUO but ultimately chose HID because of their support for biometrics. With DUO every user would have to have the authentication app on their personal phone and pull it out each time they had to log in. We definitely did not want this for our frontline staff as it would slow the process way down
WatchGuard AuthPoint is easier to manage on a company-wide scale than Google Authenticator. We do use AuthPoint in conjunction with the Microsoft Authenticator but for different services. WatchGuard also has other features available, like dark web monitoring and device management, should we decide to move further services over to WatchGuard, with Google Authenticator does not have
Provides a quick one finger authentication\log-on.
Logging onto a machine that is used by several other users, such as in retail is no problem because the DigitalPersona software does a switch user function instead of logging out the other user.
One negative that was apparent immediately after installing the DigitalPersona software was that users very easily forgot their Windows passwords because of the one finger log-on.
We currently have 300 users on Authpoint, and most of them use insecure passwords. Authpoint gives us peace of mind that we don't have to police individual employee passwords.
In line with the comment above, with so many people in our organization using insecure passwords, I'm sure that Authpoint has already saved us from many potential security breaches.
Security breaches can cost a lot of money. Preventing them saves the company money and helps to achieve our bottom line.