Hypersocket (formerly Nervepoint) enables organizations to efficiently manage and administer end users and their access to disparate systems by empowering end users to manage their own accounts across multiple systems both on-premise and in the cloud, while allowing IT to gain control over user sprawl, cut support and gain in-depth business insight.
N/A
Microsoft Entra ID
Score 8.8 out of 10
N/A
Microsoft Entra ID (formerly Microsoft Azure Active Directory or Azure AD) is a cloud-based identity and access management (IAM) solution supporting restricted access to applications with Azure Multi-Factor Authentication (MFA) built-in, single sign-on (SSO), B2B collaboration controls, self-service password, and integration with Microsoft productivity and cloud storage (Office 365, OneDrive, etc) as well as 3rd party services.
HyperSocket is very well suited if the resources and budget are made available. There is not much a learning curve for the IT Department or for those users already familiar with two-factor authentication. There will be some education and training requirements for most end-users as the notifications and general verbiage can be confusing for some. It may also show some exploits within some end-users who are unaware of a notification but will use the email to reset an expired password without thinking twice if it may have been a phishing email or the opposite where an end-user deletes or ignores the expiration email notification expecting it to be spam/phishing.
Overall, the Microsoft Entra ID platform is best utilized by people looking to have one platform that manages all interactions between other platforms. The Microsoft Entra ID platform allows for a seemless SSO integration, and can also integrate with Intune for MDM. Additionally, and probably the most easy to understand integration, is the integration with Active Directory, and controls associated with that.
Application integration is really good for single sign-on and managing identity overall. The correlation with Active Directory on-prem is really good, so we can manage it in a single place. It's easy to manage the users and integrate other Microsoft products. It is the base of everything else.
Help-Desk functionality similar to OneIdentity Self-Service Password Manager, as it provides additional users that do not require administrative access to assist with managing end-users who may have locked themselves out of HyperSocket Access Manager by forgetting their own security questions.
Too many features which become unusable and feel like the payment plans are not flexible since it's an all-in-one product with one price. It is not necessarily a bad thing as most subscription-based pricing forces a buyer to pay more for an integral service that is only available on the highest price-plan. You really do get what you pay for, but we found many of our use-case scenarios limited the product.
This isn't necessarily against the product, just a personal opinion around Multi-Factor authentication which is always primarily driven mobile devices. Not all companies or end-users have access to a multi-factor device, (or in our case, are allowed to have access to a cell phone while servicing members/clients). This creates a shortfall to allow multi-factor functionality to extend to all users unless there are hardware tokens, which can be miss placed or left out more easily as most users don't treat it the same way they would their personal smartphone.
I'm not quite sure what they could do to improve, but I guess they can make it more user-friendly. It's very directed at admin staff, and perhaps there could be some better self-service features so that the admins don't have to do everything. We can let the users do some more of the work. Perhaps that'd be a good one.
MSFT Entra ID has been essential for managing our geographically dispersed team. We're confident that it will scale with us as grow, and we'll be able to take advantage of additional security and ID management features as they become necessary. Being able to centrally manage our user access from anywhere with a small support team is such a relief.
Because there are things you can improve somewhere. Sometimes you set up something that the Microsoft Manager doesn't work with. It could be a security boundary. And then let me say the basic security boundary is not set up as we would like, though. I think it's a better approach to set it up at a different level to be highly secure, and then we can change it whenever we need it because not many people are aware of some of the functionality. A user can create a security group and create the Microsoft Entra ID. Guests can invite guests in the beginning, which is extremely hard to track later, especially if we have pre-tier and we do not send the diagnostics data anywhere else. But within the enterprise environment, it's quite okay because most companies don't go with the security defaults because we do have a premium license. So probably, I hope we are sending data somewhere else. This is why nine. Maybe information about new changes or new functionality that are coming could be better. Because when we have to go to the Microsoft admin portal to get the message information, which is extremely hard because most admins don't do that. And there are lots of notifications. So going through them and identifying the risk and overall functionality, especially the new ones, is extremely hard.
I have not needed to engage support for anything at this time. I have been able to find the answers either online or in a knowledgebase. I tried to skip the question but it would not let me, so I rated a 9 based on other interactions with Microsoft support I have had
Make sure you use a good partner. Our implementation was a bit longer and more problematic than we expected. Our partner got it done, but, in my opinion, some of their inexperience and staffing issues were evident.
Nervepoint Access Manager (NAM) has the ability to deal with multiple domains. While ServiceNow at the time we looked at the solution did not (I do not know if it does now). NAM was a more polished, mature product.
We've done stuff with Okta for Identity and Duo. Those would probably be the two big ones that I would say that people would recognize and stuff. There's some other smaller players we've talked to, but those are the two big ones that we play with. We're still using it. So, because it was integrated into everything we've already done, it just made it almost indispensable.
Microsoft Professional Services' technical knowledge is appreciable as consultants design the solution as per customer requirements. Mapping of features per user specifications and assisting Customer IT engineers to implement so they can manage and administer the services.
As with any IT Service or Solution, the investment will always be seen as a sunk cost. The only ROI would be the time and resources spent elsewhere rather than with Password Management through an IT Department or similar department. I found that the time spent on password management was about the same, as many users who are frequently forgetting a password are also forgetting their security question & answers.
There are some positives, as it was able to help manage the bulk of their non-windows passwords or passwords related to another online service. The centralized password manager doesn't feel like a true single sign-on but for most users, it replaces a hand-written copy they have taped to a monitor.
It can help with automating some of the active directory workflows with its own user provisioning functionality. Took more time to set up than it was to manage on its own.
So I would say all of that, especially when we look at deploying our Federation, or I would say our SSO stuff now, helps out tremendously with that. When we deploy applications to specific users, we can control that. That's a great option as well. So I would say we got a good ROI on that.