Tested as a potential addition to a suite of products offered to Government and Commercial customers
What do you like best?
Its implementation is relatively simple. Made easy by Silverfort's custom scripting to integrate to a customer landscape. Dashboards are clean and concise.
Syslog shipping makes it easy to collect LDAP and KRBGT events across an enterprise for later investigation and/or real time monitoring with a SIEM.
Silverfort's turnaround time from new idea to feature is rather impressive.
Testing against "Pass the Hash" attacks was thwarted every time. And most man-in-the-middle attacks as well. Two attacks other 2FA solutions fall short on more times than not.
What do you dislike?
If this were to be used on a SOC floor, of some sort, there is a limitation on defining granular permission per Silverfort User. This feature is more geared towards case management and segregation of visibility and to their credit Silverfort never advertised it. Its more of my personal "...like to have...". RADIUS capability is also another nice to have.
Recommendations to others considering the product:
Understand why you or your company are looking for a 2FA solution. Meaning know what type attack your attempting to mitigate. There are many 2FA solutions but, sadly, many that can be circumvented.
What problems are you solving with the product? What benefits have you realized?
Providing 2FA solutions for customers when it comes to: Client-to-Site VPN connections, ESXi management access, Administrator level sign-on, and SOC analyst sign-on.