Start from a neutral baseline and add what matters to you. Criteria are labeled by source — the platform baseline is architecture-neutral; buyer-contributed criteria are shown separately.
Build your evaluation
no account needed
Match on your requirements
no account needed
This evaluation is stored in your browser only. We cannot see it, and it is not tied to any account. Save it to a link or create an account to keep it across devices — you can export it at any time either way.
1. Weight what matters
28 criteria
baselineDoes the vendor solution support the uses of SSO/MFA?
baselineWhich passwordless authentication methods are supported natively (FIDO2/WebAuthn passkeys, platform biometrics, magic links, push notification with number matching), and which require a third-party integration?
baselineDescribe phishing-resistance specifically — does the platform support FIDO2/WebAuthn as a first-class, default-recommended factor, and what percentage of your customer base has migrated off phishable factors (SMS OTP, push-without-number-matching) using this product, per a customer reference?
baselineHow does step-up/adaptive authentication work — what signals (device posture, network/IP reputation, impossible-travel, behavioral biometrics) trigger a higher assurance factor, and can policies be configured per application/risk tier?
baselineWhat is the account-recovery and factor-reset flow when a user loses their only registered device, and what safeguards prevent that flow from becoming the weakest link (i.e., a social-engineering bypass of strong MFA)?
baselineDetail integration breadth — native support for the major IdPs (Okta, Entra ID/Azure AD, Ping) as well as legacy/on-prem apps (RADIUS, LDAP, Windows login) — and which integrations require additional agents or connectors.
baselineDoes the platform support passkey synchronization across a user's devices (e.g., via a platform ecosystem) versus device-bound-only passkeys, and what are the security tradeoffs the vendor discloses between the two?
baselineExplain enrollment and rollout support for a large, distributed workforce — self-service enrollment flows, bulk provisioning, and measured time-to-full-deployment with a customer reference of comparable size.
baselineHow does the product handle shared/kiosk workstations and service accounts where per-user passwordless factors don't map cleanly (e.g., shift workers, call centers)?
baselineWhat is the pricing model per user/per month, and does cost differ meaningfully between a basic MFA tier and a full passwordless/adaptive-auth tier — provide a concrete cost comparison for a defined workforce size.
baselineDetail hardware security key support (YubiKey and similar) — procurement/distribution assistance, lifecycle management (lost-key revocation, bulk re-enrollment), and whether hardware keys are treated as first-class alongside software passkeys.
baselineHow does authentication work in offline or air-gapped environments (e.g., a technician in a facility with no network connectivity) where real-time verification against a cloud IdP isn't possible?
baselineWhat is the support SLA specifically for authentication lockouts (a locked-out user is often fully blocked from work) — 24/7 support availability, average time-to-resolution, and whether resolution requires IT-admin intervention or has a self-service path.
baselineDoes the platform hold relevant compliance certifications (FIPS 140-2/140-3 for cryptographic modules, FedRAMP, SOC 2) required for regulated or government customers, and at what certification level?
baselineExplain support for high-volume consumer/B2C authentication (millions of external users) versus workforce-only authentication — does the same product scale to that volume, or is it a fundamentally different product line?
baselineWhat is the incident response process if a bypass or vulnerability in the MFA mechanism itself is discovered (by the vendor, a researcher, or an active attacker) — how are customers notified, and what is the historical track record of disclosed MFA-bypass vulnerabilities for this product?
baselineHow does the platform support machine-to-machine or API authentication (service accounts, workload identity) as a complement to human MFA, or is that entirely out of scope requiring a separate secrets/workload-identity product?
baselineProvide MFA options including push-based authenticator app approval, authenticator app OTP, text message, voice call, passkey, Yubikey, Windows Hello for Business/biometrics, and OATH tokens (the organization currently uses DeepNet SafeID hard tokens).
baselineProvide remediation recommendations from the password assessment (e.g., password policy changes, MFA enforcement, privileged account hardening).
baselineRequire Contract Staff to use Multifactor Authentication and maintain strict control of access credentials, immediately removing access for persons no longer authorized.
baselineIntegrate with the organization's OKTA Identity and Access Management/MFA software for user authentication and provisioning, and provide MFA capabilities.
baselineSecondary Red Team objectives: establish persistent access and maintain stealth, lateral movement across network segments/geographic boundaries, privilege escalation to critical administrative roles, exfiltration of sensitive data without detection, and bypassing of security controls (EDR, SIEM, DLP, MFA).
baselineProvide Access Management: SSO (SAML/CAS/Oauth), MFA integration with DUO Security, modern self-service password reset, access auditing and attestation/recertification, and federated identity including native support for InCommon federation.
baselineDo you currently utilize Multi-factor authentication to access Servers, website, user logins? If no, do you have plans to move to MFA?
baselinePhase 2 roadmap: solution should support Role Mining, Fine-Grained Access Control, SIEM/DLP integration, integration with the Cherwell service management tool, Multi-Factor Authentication, advanced Access Review and Certification, and Privileged User Management.
baselineProactive availability/incident monitoring is provided (if SaaS, through a publicly available service); the solution includes a mechanism for strong authentication/MFA for administrators.
baselineVendor will maintain role-based permissions for access to University Data (principle of minimization), restrictions on copying/removing data from an authorized network/system, strong password protocols, and multi-factor authentication for any remote access to Vendor's network or systems.
baselineVendor shall ensure that all access by Vendor's employees, agents, representatives, and contractors requires strong passwords/passphrases or multi-factor authentication for users, and multi-factor authentication for all remote access; privileged accounts must use dedicated accounts and Vendor must maintain an inventory of privileged accounts.
Signing up adds sharing with your team, sending this as an RFP to vendors, and private document sharing. Nothing above is taken away, and nothing here is sent anywhere until you choose to.
Platform baseline
neutral · staff-reviewed
RFIDoes the vendor solution support the uses of SSO/MFA?
RFIWhich passwordless authentication methods are supported natively (FIDO2/WebAuthn passkeys, platform biometrics, magic links, push notification with number matching), and which require a third-party integration?Answer key — what a strong answer shows
Strong answers list methods and are explicit about which are native versus dependent on a third-party integration or add-on.
RFPDescribe phishing-resistance specifically — does the platform support FIDO2/WebAuthn as a first-class, default-recommended factor, and what percentage of your customer base has migrated off phishable factors (SMS OTP, push-without-number-matching) using this product, per a customer reference?Answer key — what a strong answer shows
Look for a real migration percentage backed by a named customer; a vendor that only offers SMS OTP as its strongest factor is not phishing-resistant regardless of marketing language.
RFIHow does step-up/adaptive authentication work — what signals (device posture, network/IP reputation, impossible-travel, behavioral biometrics) trigger a higher assurance factor, and can policies be configured per application/risk tier?Answer key — what a strong answer shows
Strong answers name specific signals used and confirm per-application/per-risk-tier policy configuration, not a single global policy.
RFIWhat is the account-recovery and factor-reset flow when a user loses their only registered device, and what safeguards prevent that flow from becoming the weakest link (i.e., a social-engineering bypass of strong MFA)?Answer key — what a strong answer shows
Look for recovery flows with real identity-proofing (not just a helpdesk phone call) — this is the classic bypass vector that undermines otherwise-strong MFA.
RFPDetail integration breadth — native support for the major IdPs (Okta, Entra ID/Azure AD, Ping) as well as legacy/on-prem apps (RADIUS, LDAP, Windows login) — and which integrations require additional agents or connectors.
From other buyers
crowdsourced · anonymized
💬
No buyer-contributed criteria yet
Verified buyers can suggest criteria (anonymized before pooling).
Answer key — what a strong answer shows
Strong answers cover both modern IdP integration and legacy/on-prem protocol support; many products are strong on one and weak on the other.
RFIDoes the platform support passkey synchronization across a user's devices (e.g., via a platform ecosystem) versus device-bound-only passkeys, and what are the security tradeoffs the vendor discloses between the two?Answer key — what a strong answer shows
A vendor that discloses the real tradeoff (sync convenience versus device-bound assurance) rather than presenting one option as strictly superior is giving a more honest answer.
RFPExplain enrollment and rollout support for a large, distributed workforce — self-service enrollment flows, bulk provisioning, and measured time-to-full-deployment with a customer reference of comparable size.Answer key — what a strong answer shows
Look for a concrete deployment timeline from a customer of comparable size and scale, not a generic 'easy rollout' claim.
RFIHow does the product handle shared/kiosk workstations and service accounts where per-user passwordless factors don't map cleanly (e.g., shift workers, call centers)?Answer key — what a strong answer shows
This is a common gap — strong answers describe a specific supported pattern (e.g., shared-device passkeys, badge-based auth) rather than admitting the product assumes one user per device.
RFIWhat is the pricing model per user/per month, and does cost differ meaningfully between a basic MFA tier and a full passwordless/adaptive-auth tier — provide a concrete cost comparison for a defined workforce size.Answer key — what a strong answer shows
Strong answers give transparent, tier-differentiated per-user economics; vendors who obscure the cost delta between basic MFA and full passwordless capability make it hard to justify the upgrade.
RFPDetail hardware security key support (YubiKey and similar) — procurement/distribution assistance, lifecycle management (lost-key revocation, bulk re-enrollment), and whether hardware keys are treated as first-class alongside software passkeys.Answer key — what a strong answer shows
Look for a real lifecycle-management workflow (not just 'we support FIDO2 keys') and confirm hardware keys aren't a second-class, harder-to-manage option compared to software passkeys.
RFIHow does authentication work in offline or air-gapped environments (e.g., a technician in a facility with no network connectivity) where real-time verification against a cloud IdP isn't possible?Answer key — what a strong answer shows
A vendor with no offline story is a real gap for customers with field/industrial workforces; look for a specific offline-capable factor or time-limited cached-credential mechanism.
RFPWhat is the support SLA specifically for authentication lockouts (a locked-out user is often fully blocked from work) — 24/7 support availability, average time-to-resolution, and whether resolution requires IT-admin intervention or has a self-service path.Answer key — what a strong answer shows
Strong answers give a concrete lockout-resolution SLA and describe a self-service recovery path; a vendor requiring IT-ticket-and-wait for every lockout creates real workforce-productivity risk at scale.
RFIDoes the platform hold relevant compliance certifications (FIPS 140-2/140-3 for cryptographic modules, FedRAMP, SOC 2) required for regulated or government customers, and at what certification level?Answer key — what a strong answer shows
Ask for the specific certification level and scope (e.g., FIPS 140-2 Level 1 vs Level 2) — a vague 'FIPS compliant' claim without a level and validation certificate number is not sufficient for regulated buyers.
RFPExplain support for high-volume consumer/B2C authentication (millions of external users) versus workforce-only authentication — does the same product scale to that volume, or is it a fundamentally different product line?Answer key — what a strong answer shows
Workforce MFA and consumer-scale CIAM often have very different scaling and UX requirements — a vendor should be honest about which they're actually built for rather than claiming both without evidence.
RFIWhat is the incident response process if a bypass or vulnerability in the MFA mechanism itself is discovered (by the vendor, a researcher, or an active attacker) — how are customers notified, and what is the historical track record of disclosed MFA-bypass vulnerabilities for this product?Answer key — what a strong answer shows
Look for a real, named incident-disclosure process and be willing to ask directly about the vendor's CVE history — a vendor with zero disclosed vulnerabilities ever across years of operation warrants extra scrutiny, not automatic trust.
RFIHow does the platform support machine-to-machine or API authentication (service accounts, workload identity) as a complement to human MFA, or is that entirely out of scope requiring a separate secrets/workload-identity product?Answer key — what a strong answer shows
This is a genuine scope boundary — many MFA vendors are human-only; a vendor should clarify this rather than implying broader non-human coverage than they actually provide.
RFPProvide MFA options including push-based authenticator app approval, authenticator app OTP, text message, voice call, passkey, Yubikey, Windows Hello for Business/biometrics, and OATH tokens (the organization currently uses DeepNet SafeID hard tokens).
RFPProvide remediation recommendations from the password assessment (e.g., password policy changes, MFA enforcement, privileged account hardening).
RFPRequire Contract Staff to use Multifactor Authentication and maintain strict control of access credentials, immediately removing access for persons no longer authorized.
RFPIntegrate with the organization's OKTA Identity and Access Management/MFA software for user authentication and provisioning, and provide MFA capabilities.
RFPSecondary Red Team objectives: establish persistent access and maintain stealth, lateral movement across network segments/geographic boundaries, privilege escalation to critical administrative roles, exfiltration of sensitive data without detection, and bypassing of security controls (EDR, SIEM, DLP, MFA).
RFPProvide Access Management: SSO (SAML/CAS/Oauth), MFA integration with DUO Security, modern self-service password reset, access auditing and attestation/recertification, and federated identity including native support for InCommon federation.
RFPDo you currently utilize Multi-factor authentication to access Servers, website, user logins? If no, do you have plans to move to MFA?
RFPPhase 2 roadmap: solution should support Role Mining, Fine-Grained Access Control, SIEM/DLP integration, integration with the Cherwell service management tool, Multi-Factor Authentication, advanced Access Review and Certification, and Privileged User Management.
RFPProactive availability/incident monitoring is provided (if SaaS, through a publicly available service); the solution includes a mechanism for strong authentication/MFA for administrators.
RFPVendor will maintain role-based permissions for access to University Data (principle of minimization), restrictions on copying/removing data from an authorized network/system, strong password protocols, and multi-factor authentication for any remote access to Vendor's network or systems.
RFIVendor shall ensure that all access by Vendor's employees, agents, representatives, and contractors requires strong passwords/passphrases or multi-factor authentication for users, and multi-factor authentication for all remote access; privileged accounts must use dedicated accounts and Vendor must maintain an inventory of privileged accounts.