
In my previous article, I focused on service accounts as a component of the IT environment that is often neglected from a security perspective, due to the lack of human interaction during the login process. We can speak of comprehensive protection for all identities—whether human or NHI (non-human identities)—when a solution enables multi-factor authentication across an organization’s entire environment—from the cloud to on-premises resourcesthat have so far remained outside the scope of traditional MFA: the aforementioned service accounts, access to PowerShell, legacy applications, and RDP and SSH protocols. The key is Runtime Access Protection technology, which integrates directly with the Active Directory authentication flow without installing agents on machines or deploying proxies on the network. This allows MFA verification to be enforced on any protocol without abandoning the access methods already in use and proven by IT administrators.
Modern MFA: Tools You're Already Familiar With
Silverfort doesn’t limit you to a single authentication method. On the contrary—it extends the tools you already use to cover a full range of resources and activates them according to predefined policies. This maintains a Zero Trust policy without the hassle of constantly having to verify your identity. Of course, ITDR also runs in the background, analyzing deviations from the norm and responding to potential threats, such as logging in from two different locations within a short period of time. So, aside from Microsoft, what other authentication methods does Silverfort support?
Biometrics (Keyless). Keyless is the only biometric solution in Silverfort’s portfolio—a privacy-preserving facial authentication solution that works on both mobile devices and desktops. Silverfort extends this phishing-resistant biometric authentication to on-premises and SaaS resources, providing users with a consistent, familiar login experience for every system.
Hardware keys (Yubico). The FIDO2-compliant YubiKey hardware security token is one of the most effective, phishing-resistant MFA methods. Thanks to native integration, you can extend YubiKey protection to resources that previously could not be secured—legacy applications, command-line tools (PowerShell, PsExec), administrative access, and databases.
Push notifications (Duo). When Silverfort determines that access requires confirmation, it forwards the request to Duo, and the user approves it with a single tap in the app. The response is sent back to Silverfort, which then instructs the identity provider whether to grant access.
Passwordless Authentication (HYPR). HYPR eliminates passwords entirely—MFA is handled through the HYPR mobile app. Silverfort triggers MFA when accessing any resource, including those where traffic is based on Kerberos or NTLM protocols, such as logging into servers via the command line.
Of course, that’s not all—Silverfort also integrates natively with solutions such as Okta, Ping, and RSA, among others. Regardless of the method chosen, the logic remains the same: every access request undergoes real-time risk analysis, and MFA is applied exactly when it’s needed—all within a single, unified management interface for the entire environment.
Talk to an ISCG expert:
https://outlook.office.com/book/KonsultacjaSilverfort@ISCG.onmicrosoft.com/?ismsaljsauthenabled


