We all know that relying on a simple user ID and password combination is fraught with peril. One alternative is to use one of the single sign-on solutions we reviewed last year, but there are less expensive options that could also be easier to install.
That's where two-factor authentication services come into play. Years ago, vendors came out with hardware-based two-factor authentication: combining a password with a token that generates a one-time code. But toting around tokens means that they can get taken, and in a large enterprise, hard tokens are a pain to manage, provision and track.
Enter the soft token, which could mean using a smartphone app, SMS text message, or telephony to provide the extra authentication step. We reviewed eight services that support up to five kinds of soft tokens: Celestix's HOTPin, Microsoft's PhoneFactor, RSA's Authentication Manager, SafeNet Authentication Service, SecureAuth's IdP, Symantec Validation and ID Protection Service (VIP), TextPower's TextKey, and Vasco's Identikey Authentication Server.
Other vendors, such as Authentify, BehavioSec, eSet, PortalGuard, TeleSign, Trustwave, and Yubico either declined to participate or didn't quite fit into the review set. Here's a link to a more complete list of vendors.
All of the products in our review offer some form of centralized management, and the ability to integrate additional authentication step into a series of application servers, VPNs, and Windows Active Directory logins. (Watch a slideshow version of this story.)