Beyond Identity unveiled a new sub-category of its zero-trust technology — Zero Trust Authentication. The vendor claims the service addresses the limitations of passwords and legacy multi-factor authentication (MFA) and integrates security signals from industry leaders including Palo Alto Networks and CrowdStrike.
The Zero Trust Authentication approach offers continuous risk-based MFA experience and includes components such as Beyond Identity's risk scoring and continuous authentication capabilities, the vendor says.
Beyond Identity worked with third-party advisors, customers, and zero-trust experts to identify seven Zero Trust Authentication requirements that help organizations measure their current identity practices and differentiate the approach from other authentication solutions in seven ways:
- Passwordless – No use of passwords or other shared secrets, as these can easily be obtained from users, captured on networks, or hacked from databases.
- Phishing-resistant – No opportunity to obtain codes, magic links, or other authentication factors through phishing, adversary-in-the-middle, or other attacks.
- Capable of validating user devices – Able to ensure that requesting devices are bound to a user and authorized to access information assets and applications.
- Capable of assessing device security posture – Able to determine whether devices comply with security policies by checking that appropriate security settings are enabled, and security software is actively running.
- Capable of analyzing many types of risk signals – Able to ingest and analyze data from endpoints and security and IT management tools.
- Continuous risk assessment – Able to evaluate risk throughout a session rather than relying on one-time authentication.
- Integrated with the security infrastructure – Integrating with a variety of tools in the security infrastructure to improve risk detection, accelerate responses to suspicious behaviors, and improve audit and compliance reporting.
Beyond Identity VP Chris Cummings says he expects more vendors to offer services under this Zero Trust Authentication category but they have to meet all the requirements above.
“You're gonna need to meet these, otherwise you fail,” he said. “I don't think that we're necessarily in a category unto ourselves forever, because certainly, we can't be the only ones listening to what customers want, right?”
Beyond Identity Partners With Leaders in Zero-Trust EcosystemThe vendor noted security giants Palo Alto Networks and CrowdStrike, identity vendors Ping Identity and Beyond Trust, and industry associations the Cloud Security Alliance and the FIDO Alliance are among the organizations that support Zero Trust Authentication.
And Beyond Identity the security singles from some of those vendors to expand customers’ existing security stack.
“For our advanced customers and our enterprise customers, we can actually help them get more out of their existing security investment and make even better decisions at the time of access by providing these integrations with partners like EDR [endpoint detection response] vendors like CrowdStrike like MDM [mobile device management] vendors like AirWatch from VMWare, and VPN vendors like Palo Alto Networks,” Beyond Identity CTO Jasson Casey told SDxCentral.
“In order for us to do authentication the right way, we need to be in a position to use as many signals as possible that are already resident from within the security infrastructure that is deployed on site,” Cummings echoed.
“That's what we do with our partners and we do that processing in real -time. So we can give a very accurate picture of the user, how authentic is that user? And also look at the devices that that user is using,” he said.
Comments