Two-factor authentication that does not get in the way

A password on its own has not been enough for years. But a second factor that is too much hassle gets worked around — with a sticky note, a shared account, or an exception nobody ever reverses. We roll out 2FA and MFA in a way that holds up.

Sign-in screen asking for a code from an authenticator app, alongside the systems the two-factor setup connects to

The technology is the smallest part

Switching on a second factor is an afternoon of work. The real work starts with the exceptions: the colleague without a work phone, the external party who also needs access, the service accounts with no human behind them, and the Friday afternoon when somebody leaves their phone on the train.

Fail to settle those cases up front and within a month you have exceptions that hollow out the protection again. We have run this often enough to know which questions belong first.

Get in touch →

From choosing to running it

You can bring us in for the whole route, or only for the part you are stuck on.

Advice and choice

Which form suits which group? An authenticator app for the office, a hardware token for people who cannot bring a phone in, a certificate for machines. Usually it is a combination.

Connecting to your environment

Hooking into Active Directory, RADIUS and LDAP, so the same second factor covers the VPN, the RDP session and your web applications — rather than being arranged separately per system.

Rollout and enrolment

Enrolling users at a pace the service desk can absorb, with clear instructions and a fallback for anyone who gets stuck.

Certificates and PKI

Issuing and managing certificates for secured communication between systems and parties, including keeping an eye on expiry dates.

Key management

For heavier requirements: key management through a key management service or an HSM, plus advice on what is proportionate in your situation.

Running it afterwards

Lost tokens, people joining and leaving, recovery procedures that actually work. This is where rollouts come apart in the long run.

Ten years on the build side of authentication

Ten years on the build side of authentication

We spent ten years leading development and support at a vendor of authentication solutions: design on Windows and Linux servers, integration with Active Directory, RADIUS and LDAP, and implementations at national and international organisations. Since then we have done that work as consultants.

On top of that, we have managed and issued PKI certificates for secured communication at a regulator, connected a key management service to a back-end system, and assessed whether an HSM as a service was worth taking on.

Security is not a standalone product

Two-factor authentication stands or falls with the rest: who looks after the servers, how is the backup arranged, and what happens if somebody gets in anyway? We do that work too, so we can look at it as a whole rather than bolting one measure on top.

See all our services →

Introducing or improving two-factor authentication?

Tell us briefly what your environment looks like and we will set out what is involved.