HID DigitalPersona (formerly Crossmatch) provides a comprehensive multi-factor authentication solution. The vendor’s value proposition is that their solution frees users from cumbersome login activities while making it easy for an IT Team to secure access to their networks, data and applications.
$3.75
per user per month
Yubico YubiKeys
Score 9.4 out of 10
N/A
Yubico YubiKeys make the internet safer with phishing-resistant multi-factor authentication (MFA) by providing simple and secure access to computers, mobile devices, servers, and internet accounts. The Yubico YubiKey stops account takeovers at scale by mitigating phishing and ransomware attacks, and delivers users authentication with a simple touch or tap.
I know its not a direct competitor but HID is better in all the sense its amazing because of its integration with Microsoft Azure AD. It has overall better functionality as it doesnt work on cloud premises it can also be used on premises. The best part is one can use mfa …
We've been using HID DigitalPersona for so long that I honestly can't recall what other products we did investigated. We have been satisfied with the app for a very long time, therefore we don't see the need to explore other options.
It has a greater advantage than Okta because it gives a variety of verification options and allows biometrics logging in, which is something the other software does not, in my suggestion.
HID DigitalPersona is selected against them as it has a reliable and a great secured software which has a versatile access to other platforms as well which saves a lot software to be taken and HID DigitalPersona is a one stop solution to all problems it has everything a …
Our use of HID DigitalPersona has been for long that I really can't remember what other products we looked at. We have happy with app for a very long time thus I don't see the need to look at other possibilities.
Not proper usage with AWS but HID has been really versatile it just works as we need to login to system has become really easy and fast because of it. The multi factor authorization gives you the freedom to chose from a variety of authentication methods such as biometric login, …
In comaprison to okta its better suited as it has array of authentication methods and it also offers login via biometric which according to me is not present in the other software.
They both are great and offer great features such as single sign on and top, but HID DigitalPersona is ahead of Ping identity because it offers Biometrics as well and it can also work in offline setting as well.
Strong authentication, multifactor authentication, biometrics, and integration set HID DigitalPersona apart, making it an excellent option for a range of authentication requirements.
I don't have excessive experience with One login, but it wasn't as feature rich as HID DigitalPersona. The best part about HID DigitalPersona is that it can be used in offline settings as well.
HID serves all our purposes and is not that expensive its integration with microsoft active directory makes it super helpful. It is loaded with features that are not just for show off but actually works its a great software and we dont think any other software can match its …
HID DigitalPersona is a great software from others as it provides a great security and trusted 2 factor authentication which helps in creating a system integrator with trust and ease of use it has been proved to be a great software by it's easy and accessible user interface …
HID provides better integration option more authentication options and its easier to use. The integration which helps HID the most is Azure's active directory it makes HID better in all regards. It acts as a centralized system to protect all the resources and data of your …
Okta Workflows (previously Azuqua) focuses on application integration and workflow automation while HID DigitalPersona stresses authentication security and compliance.
The benefit of HID DigitalPersona is it uses a biometric method for authentication. It can be integrated with Azure which means it is more features reach and offers multiple factor authorization and SSO.
A number of factors, including HID DigitalPersona's extensive range of authentication methods, easy integration with Microsoft Active Directory, support for a variety of use cases, robust compliance and security features, and affordable pricing or licensing models, may make it …
We have used HID DigitalPersona for over 8 years and have been so satisfied with the product that we just haven't even looked because we like the product that much.
We went the other direction. DigitalPersona was our initial implementation, but we have moved away from DigitalPersona and moved to a product called TecMFA. Our organization has implemented Okta as our application and Azure as our multifactor authentication platform, and …
We used to use something from Okta that has I think a passwordless authentication or readily get a notification that's an alternative, but it's software, not hardware. That's the other thing I would say. We have tried nothing else on the hardware side. Its hardware token, ease …
Yubico YubiKeys has been a leader in the security key market, and I think they have a new product we just read about two days back and they can store up to a hundred private keys now. So I think this is what it distinguishes them from the market, apart from this, whatever …
If you compare it to authenticator apps, I'd say it's much more easy to set this up for the individual user. Well, it's Swedish. It's also very well documented. There are a lot of guides on how to use them and I have a lot of faith in the security posture of Yubico and how the …
I've never really used any other physical keys, I mean I've used multifactor authentication from Google Authenticator or Duo, but never another physical key, so this is my first experience with that.
I have used the tokens that display a little six-digit code that rotates, but I feel that's just like my phone does that, so why would I have a separate device for that? This at least provides a physical thing I have to either insert or tap to use. I think they're not …
I have tested the Google Titan Keys. I found Yubico YubiKeys to be a bit more durable and last longer. I've already had a few Google Titan Keys that have just gone out. They just stopped working. So the Yubico YubiKeys are a bit more lightweight and easier to fit on a key ring. …
I prefer Yubico YubiKeys because sometimes logging in with pass keys on an iPhone you have to do kind of two handshakes. One is the QR code and then doing a face ID. So that's an extra step versus the Yubico YubiKeys, which I can just put in and scan with my finger.
We have thought about just trying another competitor for due diligence but have not explored that option yet. We went with Yubico YubiKey due to hearing about it at a conference and decided to start experimenting with the solution. We are pretty decided on what we are going …
They offer ways to store passwords or MFA support, but most need a root password. In addition, LastPass and 1Password do not have much support for MFA. This results in a lack of MFA support. For Okta, although it offers MFA and SSO, the OTP can be very annoying to have as I do …
During the onboarding process, remote workers can enroll their fingerprints or create secure PINs. This eliminates the need for complicated passwords and enables them to safely access company resources and critical apps from remote locations. HID DigitalPersona's robust authentication techniques and access control features can assist you in adhering to data security laws.
When I used it as an engineer for a software company a few years ago, I would be able to continue doing work on the train ride into and out of the office. So that was an extra hour, two hours a day that I was able to access our systems and still be able to continue to work. So that was a lot of fun. Well, I don't know if stay fun, but it was nice to be able to have the access, not have to be connected directly to the corporate network.
I think the best thing is it has a lot of capacity and it's very, very secure. It can store a lot of private keys versus all the other products. We have reviewed a few other products, but Yubico YubiKeys gives a lot more capabilities than some of the other security key brands.
Multiple domains - DigitalPersona struggles with multiple domains. Since the solution is licensed per domain, migrating users between domains can be troublesome to keep licensed. Additionally, migrating to a new domain removes the AD leaf objects that store all digital persona information, essentially wiping out and credentials or other stored information.
Password change - DigitalPersona can be confusing to update when a stored password for a website is updated. The password is entered, and then the user is redirected to the websites password change page. Users must then authenticate with a Digital persona credential again before being prompted by Digital Persona to update the password. If the user is allowed to change the password manually through the websites page, this will lead to what is stored in Digital Persona being out of sync with the new password, and eventually account lockouts.
Terminal Server - DigitalPersona has performance issues when utilized on a high-traffic terminal server. Often it causes big CPU spikes as well as hanging sessions upon disconnect.
It can be about access control because either right now it's just you have access or you don't have access. I think there can be a use case where you are allowed a particular set of servers and not a particular set of servers. I think maybe it's there or we don't use it, but I haven't seen that. I think I've used Yubico YubiKeys at two companies and I haven't seen that. Maybe that's something that can be added.
It is wonderful for multifactor authentication and gives us many options for what we use to authenticate. All of our users use it and it is engrained into our group policies and people would be very disappointed if it went away.
As for implementing YubiKey its simple so I don't see us using anything else as we have experienced no issues so fare. Adding these to our environment is still new for us currently but in the transition phase I only see us buying YubiKey. It is highly rated and well known and cost is reasonable so no need to find another solution.
I think there are still fundamental enhancements needed to be added to the management consoles and I think there ought to be a Centralized, Windows Based "Thick" Management Application instead of individual utilities which vary from MMCs, Scripts, Wizards, etc.
I give slightly better than average rating because of the complexity in using a Yubikey. It is not as easy as native push notifications for 2FA products, however, it provides much better strength. Rating this higher or lower would be a disservice to people reading this review. If you are in the market for a hardware 2FA tool, Yubikey will be a great asset in your toolbox.
We have not experienced any issues with availability which is very important when you are dealing with a company that holds the keys to the gate. We have had more issues with availability from our SaaS providers before with authentication but that was on their end. YubiKey has worked every time for us over the course of the last 6 or so months we began testing phase.
We have not seen any lag in loading pages and getting into systems or sites. In comparison to other 2FA and MFA options it is actually faster most of the time to authenticate due to not having to type in. We require users to have long passwords and when there is an option given for password less they jump on it with excitement. As we explore going password less on their PC's the YubiKey is going to make their lives a lot easier to access the resources they need.
Extremely poor; I've never encountered such. Professional Services completely dropped us for months. Crossmatch tech support seems like it has 3 techs tops! No response to emails, calls, the absolute worst! I will never recommend DP to anyone.
Could use tools to audit license usage at a more granular level as to allow an administrator to free up licenses from users whom seldom use their biometrics to login.
I figured it all out on my own with the excellent product documentation provided by Yubico. I even managed to produce a backup YubiKey in case I lost my frequently used one. This was crucial when I temporarily lost the original.
We evaluated Cisco DUO but ultimately chose HID because of their support for biometrics. With DUO every user would have to have the authentication app on their personal phone and pull it out each time they had to log in. We definitely did not want this for our frontline staff as it would slow the process way down
We used to use something from Okta that has I think a passwordless authentication or readily get a notification that's an alternative, but it's software, not hardware. That's the other thing I would say. We have tried nothing else on the hardware side. Its hardware token, ease of use, easy integration, more reliance on an external device like a phone or something. If your phone gets lost, then you are worried about your multifactor, no problems with this device.
For us I feel like the ease of deployment has made this product very appealing, overall this will make the scalability very easy for us to push out once we roll out to our users and the management tools that we have looked at will make the admins like me happy as it is clear and easy to use. The rollout process looks to be very straight forward from the demos that we have looked at regarding the enterprise tools.
Provides a quick one finger authentication\log-on.
Logging onto a machine that is used by several other users, such as in retail is no problem because the DigitalPersona software does a switch user function instead of logging out the other user.
One negative that was apparent immediately after installing the DigitalPersona software was that users very easily forgot their Windows passwords because of the one finger log-on.
I think it's the flexibility in being able to let users pick the type of authentications that they want to use. Some are comfortable with the touch device on the physical Yubico YubiKeys. Others prefer the mobile app. So it provides flexibility for our users to choose how they want to authenticate without running a file of our security requirements.