Amazon Cognito is a mobile identity product that allows users to add user sign-up and sign-in to mobile and web apps, and authenticate users through social identity providers.
$0.01
Per MAU
Forefront Identity Manager (Discontinued)
Score 8.5 out of 10
N/A
Forefront Identity Manager is a Microsoft's legacy identity management solution. In 2016 Microsoft released Microsoft Identity Manager, an updated IAM solution. Support for Forefront Identity Manager ended October 2017.
I think that MIM is great for compliance since it reduces the number of logins that are required by users. Most offices have post-it notes with logins floating around because there are so many to remember or there are "shared" logins. This reduces the number of logins to 1 and you can easily revoke access in one fell swoop. This prevents gaps and holes with terminations and updates to select groups are super simple.
Amazon Cognito has a bit of a learning curve. You need to learn its concepts and terminology. The documentation does not describe some topics comprehensively.
Some Console screens would benefit from improved search and filtering options.
When another AWS product (e.g., SageMaker) configures Cognito on your behalf, it is not clear what you're getting. For example, the expiration of a temporary password was configured but never communicated.
For Windows Server 2008 R2 Servers is a great tool to set a codeless provisioning over new objects.
Can easily integrate with Active Directory and Exchange Servers, improving the identity sync between the final user and the lifecycle management.
Improvements in the areas of performance, simplified deployment easing the troubleshooting tasks, better documentation knowledge base, and more language support.
The codeless provisioning provided in FIM can sustain a variety from high demand to mid-size scenarios for account lifecycle management.
Amazon Cognito is easy to use and implement if you don't need to implement custom policies. But if your security team requires something outside the box, then implementation becomes complicated and you risk wasting time. There is no option for customizable regex for passwords, which is a major deficiency. The standard password policy, allow to choose the length of the password, if it should contains at least one number, one special character, one uppercase letter and one lowercase letter.
Community support is excellent, many times even better and quicker then the offical AWS support. I really cannot recommend community support enough! Apart from that the service is relativily easy to use and does not have a huge learning curve. Examples are easy to follow and will help you start using the service.
They are ideal tools to create a secure and unique login experience for our applications. Thanks to its API authorization, Amazon Cognito ensures connections to applications that are secure.It is easy to use and provides easy access to files and applications that you need to complete your goal.