{"id":101798,"date":"2023-12-01T11:30:00","date_gmt":"2023-12-01T16:30:00","guid":{"rendered":"https:\/\/jumpcloud.com\/?p=101798"},"modified":"2024-01-08T13:16:03","modified_gmt":"2024-01-08T18:16:03","slug":"okta-fastpass-vs-jumpcloud-go","status":"publish","type":"post","link":"https:\/\/jumpcloud.com\/blog\/okta-fastpass-vs-jumpcloud-go","title":{"rendered":"Okta FastPass vs. JumpCloud Go\u2122"},"content":{"rendered":"\n

Credential phishing has many undesirable outcomes from lost business and data to reputational and legal harm. Small and medium-sized enterprises (SMEs) have responded by deploying the security controls that are readily available on their platforms like multi-factor authentication<\/a> (MFA). Unfortunately, adversaries\u2019 tactics and capabilities have shifted to where traditional MFA isn’t always enough. \u2026And let’s face it, many people simply dislike using some MFAs.<\/p>\n\n\n\n

NIST recognized this issue in its  February 2022 paper<\/a> and cautioned, \u201cAll MFA processes using shared secrets are vulnerable to phishing attacks.\u201d The solution is modern authentication, or passwordless authentication<\/a>, which is stronger and more convenient<\/a> for users. Use cases can range from securing privileged assets and identities<\/a>, or simply making it easier for everybody to get work done by eliminating the source of their frustrations with MFA.<\/p>\n\n\n\n

JumpCloud and Okta both provide modern authentication via JumpCloud Go<\/a>\u2122 and Okta FastPass<\/a>\u2122. They serve a similar purpose, but the implementations are very different. This has real-world impacts on the ease of deployments and determines what\u2019s possible with each platform. JumpCloud also has integrated cross-OS device management while Okta doesn\u2019t. This article draws a comparison between these technologies that SMEs can use as a reference.<\/p>\n\n\n\n

What Is Okta FastPass?<\/h2>\n\n\n\n

Okta FastPass is a passwordless authentication system that works with Okta\u2019s single sign-on<\/a> (SSO) and MFA products to access web apps. It requires Okta Verify, a mobile app, in order to function, and is available to Okta Identity Engine (OIE) subscribers. Existing customers must upgrade from the Classic Engine to the OIE authentication pipeline in order to use FastPass. <\/p>\n\n\n\n

How Does Okta FastPass Work?<\/h2>\n\n\n\n

FastPass leverages public key infrastructure (PKI) to bind a set of keys to a device. It stores the private keys on a secure crypto-processor such as a Trusted Platform Module (TPM) or Apple\u2019s Secure Enclave. A software keystore is used if a device doesn\u2019t have the requisite hardware. Access requests are redirected from a service provider<\/a> (SP) to Okta for authentication, and the challenge flows to the Okta Verify app for verification. The app collects various signals from the device and generates digitally signed output using the keystore(s). Okta servers check that payload against policies and the signature to make authentication decisions. The assertions are passed onto the SP if access is granted, or a designated policy action will be taken in response.<\/p>\n\n\n\n

<\/p><\/div>

Note:<\/strong> \n

Okta\u2019s FastPass Technical Whitepaper<\/a> outlines all authentication flows.<\/p>\n <\/div><\/div><\/div><\/div>\n\n\n\n

Benefits and Challenges of Okta FastPass<\/h2>\n\n\n\n

Benefits<\/strong><\/p>\n\n\n\n