Frontegg Features
Authentication Options (8)
-
Authentication User experience
Process of providing credentials and logging into multiple systems is easy and intuitive for users
-
Supports Required Authentication systems
Supports required 3rd party Authentication Technologies. Example systems: bioMetric, passwords, key cards, token based systems, etc.
-
Multi-Factor Authentication
Provides support for Multi-Factor authentication, so users are required to provide multiple factors to authenticate. For example, something they know, Something they have or something they are.
-
Supports Required Authentication Methods/Protocols
Support SSO via Web agents, proxy agents, agent-less, SAML or oAuth and WS-Federation authentication and authorization Web services depending upon the application and business use case
-
Federation/SAML support (idp)
Can serve as the identity provider to external service providers so that when the user logs into a service, instead of providing credentials to the service provider, the service provider trusts the identity provider to validate the credentials.
-
Federation/SAML support (sp)
Can serve as the Service provider from an external service so that when the user logs in externally they have seamless SSO to internal applications from a service provider.
Two-Factor Authentication
Extra layer of security that requires not only a password and username but also something specific to that user
Authentication
Verify the identity of users/devices to enable secure access
Access Control Types (5)
-
Endpoint access
Provides ability to control access to PC's, Mobile devices, and other endpoint devices.
-
Local Access
Controls access to legacy applications, web based applications, network resources and servers while employees are on the companies local area network.
-
Remote Access
Controls access to legacy applications, web based applications, networks resources while employees are outside the local area network.
-
Partner Access
Controls access to users that are not company employees that are either within the companies local area network or outside the network
-
Supports BYOD users
Enables users to use their own device to access company applications.
Administration (11)
-
Ease of installation on server
Installation process is easy and flexible.
-
Password Policy Enforcement
Options for resetting and enforcing password policies
-
Administration Console
Provides Administration tools/console that are easy to use and learn for routine maintenance tasks
-
Ease of connecting applications
Easily provisions new systems, platforms or applications using configuration and not customization.
-
Self Service Password Administration
Users can set, change passwords without interaction from IT staff
Single Sign On
Allow users to access multiple services after entering their login credentials once
-
Password synchronization
Syncronizes passwords across company systems.
-
Centralized management
Provides a tool for IT administrators to manage the software.
-
Group policy complexity controls
Configure specific policies for users or groups using group policy objects.
-
Multiple policies
Supports multiple password policies.
-
Multi-lingual
Supports multiple languages.
Platform (7)
-
Multiple Operating system support
Supports Endpoint access control to multiple operating systems
-
Multi-Domain Support
Allows user authentication to be honored by all the hosts in two or more domains
-
Cross Browser support
Support access to browser based applications across required browser types
-
Fail over protection
Provides required failover mechanisms to ensure if one server, network, etc fails users are still able able to authenticate
-
Reporting
Contains pre-built and custom reporting tools to required to manage business
-
Auditing
Provides mechanism for auditing authentication for trouble shooting purposes.
-
Third Party Web Services support
Can call and pass credentials to third party web services.
Authentication type (10)
-
SMS-Based
Sends a one-time passcode (OTP) via SMS.
-
Email-Based
Sends a one-time passcode (OTP) via email.
-
Hardware Token-Based
Supports hardware tokens, which are often USB-sized, fob-like devices that store codes.
-
Software Token
Offers software tokens, which are applications installed on a mobile phone, wearable devices, or desktops and generate time-based one-time passcodes (TOTP) that a user can easily copy. Software tokens work both online and offline.
-
Biometric Factor
Allows biometric factors such as fingerprints, faceprints, voiceprints, or other biometric information to be used as an authentication factor.
-
Mobile-Push
Offers mobile push authentication, which is a user-friendly method that does not require a user to copy a code, but rather accept or deny an authentication using a mobile application. Mobile push authentication only works when a user is connected to the internet.
-
Risk-Based Authentication
Analyzes users' IP addresses, devices, behaviors and identities to authenticate a user.
Knowledge-Based Authentication
Two-Factor Authentication
Extra layer of security that requires not only a password and username but also something specific to that user
Mobile Authentication
Verify user identity through mobile devices
Functionality (21)
-
Multi-Device Sync
Allows the use of tokens on multiple devices. This feature can also be turned off if the user does not want this.
-
Backup
Offers encrypted backup recovery stored by the vendor.
-
Active Directory integration
Intetgrates with Active Directory.
-
LDAP integration
Integrates with Lightweight Directory Access Protocol (LDAP)-based directory services.
-
Hacker dictionary
Utilizes existing known hacking dictionaries to disallow users to select passwords that have been compromized.
-
Custom blacklist dictionary
Allows administrators to create a custom blacklist to disallow employees from using specific words in their passwords.
-
Self-registration and self-service
Enables a seamless customer experience with self-registration and self-service functions, including account creation and preference management.
-
Authentication
Verifies user identity with authentication, which may include multiple multi-factor authentication methods.
-
Scalability
Scales to support growing a customer base.
-
Consent and preference management
Captures and manages a customer's consent and preferences to comply with data privacy laws such as GDPR and CCPA.
-
Social login
Offers users the option to sign in with social media accounts.
-
Customer data linking
Integrates with directories or other data stores that house customer data to create a complete view of a customer.
Access Management
Control and manage access to company resources
Two-Factor Authentication
Extra layer of security that requires not only a password and username but also something specific to that user
-
User provisioning
Simplifies or automates user provisioning, deprovisioning, and other user role changes.
-
Password manager
Offers password management tools to end users.
-
Single Sign-on
Offers single sign-on functionalities to end users, allowing them to authenticate once and be given access to all of their company accounts.
-
Enforces policies
Enforces user-access policies based on individual, role type, group membership or other factors to prevent unauthorized access to company systems and data.
-
Authentication
Authenticates users prior to granting access to company systems.
-
Multi-factor authentication
Offers multi-factor authentication methods to verify a user's identity.
Two-Factor Authentication
Extra layer of security that requires not only a password and username but also something specific to that user
Compliance (3)
-
NIST-compliant
Complies with the National Institute of Standards and Technology password best practice recommendations.
-
NCSC-compliant
Complies with the National Cyber Security Centre (NCSC) password best practice recommendations.
-
Section 508-compliant
Compliant with Section 508 to enable employees with disabilities to use this software.
Type (2)
-
On-premises solution
Provides an IAM solution for on-prem systems.
-
Cloud-solution
Provides an IAM solution for cloud-based systems.
Reporting (7)
-
Activity Tracking
Track and document all activities across devices, networks, and other systems
-
Reporting
Provides reporting functionality.
Access & Permission Change Reporting
Log and report all modifications to user roles and access rights.
Compliance & Audit Trail Export
Provide standardized reports for regulatory compliance and audits.
Ad hoc Reporting
Generate one-off reports that meet information requirements
Role-Based Permissions
Set & manage permission levels based on user roles and restrict access to only authorized individuals
Real-Time Reporting
Active reporting of data and metrics
Implementation (3)
-
Easy Setup
Offers an easy to understand user interface to make setup smooth.
-
Mobile SDK
Offers a mobile software development kit (SDK) for iOS, Blackberry, and Android.
-
Web SDK
Offers a software development kit (SDK) for web-based applications.
Authentication & Authorization - Identity and Access Management (IAM) (1)
Adaptive & Contextual Access Control
Grant access based on user attributes, location, device posture or risk.
Administration & Governance - Identity and Access Management (IAM) (5)
Identity Lifecycle Management
Automate onboarding, offboarding, and access reviews throughout user lifecycles.
Self‑Service Account Management
Enable users to reset passwords and update profiles without admin support.
Member Accounts
Accounts held by members of an organization
User Management
Manage user accounts, profiles, roles, permissions, and other details across applications, devices or networks
Multiple User Accounts
Allow multiple users with individual logins and varying permissions to use the same account, software, portal, or service
Generative AI - Identity and Access Management (IAM) (3)
AI‑Driven Access Anomaly Detection
Identify unusual access patterns using machine learning models.
Automated Policy Tuning
Dynamically adjust access policies based on risk and AI-generated insights.
Predictive Role Recommendations
Suggest appropriate user roles based on usage patterns and peer behavior.
AI Authentication Risk Management - Customer Identity and Access Management (CIAM) (5)
Adaptive MFA
Possesses AI-driven triggers to determine when to require MFA or stronger authentication rather than always requiring it.
Anomaly Detection
Builds profiles of known devices/environments per user and flags deviations such as new devices, new networks, and/or suspicious locations as higher risk.
Fraudulent Login Detection
Spot fraudulent behavior, such as account takeover attempts, credential stuffing, bots, and brute force attacks through the use of AI.
Adaptive Authentication Policies
Uses machine learning to analyze past authentication events and suggest optimizations to security policies (e.g. thresholds, triggers) or to adjust rules over time.
Risk-Based Authentication
Leverages AI to assign a risk score to a login attempt based on context, device, IP, historical patterns to dynamically decide whether to prompt for MFA, additional challenges, or allow seamless login.
AI Context-Aware Security Controls - Customer Identity and Access Management (CIAM) (2)
Account Recovery Assistants
Generates dynamic prompts to guide users through account recovery workflows.
Constraint Enforcement
Implements artificial intelligence to filter, rewrite, or block prompts that attempt to access unauthorized data, escalate privileges improperly, exploit system weaknesses, or otherwise re-provision customer access permissions.
Additional Functionality (114)
Secure Data Storage
Securely stores data to prevent data loss or breaches
User Defined Attributes
Third-Party Integrations
Set up connections to third-party platforms to improve business processes
Reporting/Analytics
View and track pertinent metrics to find patterns and gain insights from data
Audit Trail
A record of all activities within the system, including user access, changes made, etc.
Automated Scheduling
Automatically create schedules based on business needs or employee availability and qualifications
Active Directory Integration
Integrates with Active Directory
Secure Login
At least a username and password is required to access the system
Real-Time Notifications
Notifications that are delivered to users as soon as an event occurs
Event Logs
A chronological record of actions or occurrences within a network, software, or process
Activity Dashboard
Dashboard to view the status of ongoing processes, identify current incidents and track past activities
Generative AI
Use AI to generate content in the form of text, images, videos, etc.
Risk Assessment
Initiate collection and analysis of known risks
Self Service Portal
Online portal through which end users can access the system, manage tasks, or obtain information
Data Verification
Process of checking different types of data for accuracy to avoid errors or inconsistencies
Customizable Templates
Pre-designed layouts that can be customized to match preferences and requirements
Biometrics
Identify or authenticate a person's identity through biological data such as fingerprints or facial patterns.
Security Auditing
Systematic evaluation of the security of a company's overall security system and situation
AI Copilot
A virtual assistant that uses AI to pursue goals and complete tasks on behalf of users
Real-Time Data
Receive data and information in real time
Reporting & Statistics
Collection, analysis, and representation of numerical data and generation of reports to understand various patterns
Monitoring
Observe and track the demand, usage, progress or quality of a system, product, or user
HIPAA Compliant
Compliant with HIPAA, which sets standards for sensitive patient data protection
Real-Time Monitoring
Active monitoring of systems, applications, or networks
Customizable Reports
Alter the layout and content of reports
Risk Analysis
Analyze potential risks across the organization
Real-Time Notifications
Notifications that are delivered to users as soon as an event occurs
Access Certification
Verify user access rights within systems to confirm each user has appropriate and authorized access to resources
Behavioral Analytics
Track and analyse user behavior within a system or network
Self Service Portal
Online portal through which end users can access the system, manage tasks, or obtain information
Generative AI
Use AI to generate content in the form of text, images, videos, etc.
Multiple Authentication Methods
Authenticate user identities through different methods such as ID cards, PINs, passwords, RFID, and biometrics
User Provisioning
Create, modify, disable, or delete user accounts and their profiles across IT infrastructures
Data Security
Protect sensitive data for digital privacy
Reporting/Analytics
View and track pertinent metrics to find patterns and gain insights from data
Single Sign On
Allow users to access multiple services after entering their login credentials once
Automatic User/Device Recognition
The system can automatically recognize a user and/or device
Unified Directory
Store, modify, and track user accounts and access in a centralized directory
Self-Service Access Request
Enable end users to request access or request changes to their account privileges
AI Copilot
A virtual assistant that uses AI to pursue goals and complete tasks on behalf of users
Credential Management
Manage usernames, account numbers, passwords, biometric data, public access keys, and other documentation
Active Directory Integration
Integrates with Active Directory
Activity Dashboard
Dashboard to view the status of ongoing processes, identify current incidents and track past activities
Remote Access/Control
Access work applications remotely, for when working away from the office and/or traveling
Compliance Management
Track and manage adherence to policies for any service, product, process, or supplier
Audit Management
Plan, schedule, and execute organization's accounts and assets to ensure compliance with policies and laws
Social Sign On
Secure Login
At least a username and password is required to access the system
Real-Time Monitoring
Active monitoring of systems, applications, or networks
API
Application programming interface that allows for integration with other systems/databases
Access Management
Control and manage access to company resources
Third-Party Integrations
Set up connections to third-party platforms to improve business processes
Event Logs
A chronological record of actions or occurrences within a network, software, or process
Role-Based Permissions
Set & manage permission levels based on user roles and restrict access to only authorized individuals
Policy Management
Create, manage, and track policies and procedures within an organization
Reporting & Statistics
Collection, analysis, and representation of numerical data and generation of reports to understand various patterns
Fraud Detection
Identify and prevent suspicious activity
Access Controls/Permissions
Define levels of authorization for access to specific files or systems
Member Accounts
Accounts held by members of an organization
Real-Time Notifications
Notifications that are delivered to users as soon as an event occurs
AI Copilot
A virtual assistant that uses AI to pursue goals and complete tasks on behalf of users
Generative AI
Use AI to generate content in the form of text, images, videos, etc.
Customizable Branding
Add customized logos and colors to align with company branding
Alerts/Notifications
Alerts or notifications of various types such as pop-up messages, sounds, banners, or badges
Secure Data Storage
Securely stores data to prevent data loss or breaches
Single Sign On
Allow users to access multiple services after entering their login credentials once
Real-Time Analytics
Analyze and gain insights into data in real-time
Data Verification
Process of checking different types of data for accuracy to avoid errors or inconsistencies
Biometrics
Identify or authenticate a person's identity through biological data such as fingerprints or facial patterns.
Multiple User Accounts
Allow multiple users with individual logins and varying permissions to use the same account, software, portal, or service
Workflow Management
Create, design and manage workflows for repetitive tasks
Activity Tracking
Track and document all activities across devices, networks, and other systems
User Management
Manage user accounts, profiles, roles, permissions, and other details across applications, devices or networks
Risk Alerts
Notifying as a warning or reminder of a potential or imminent hazard
Self Service Portal
Online portal through which end users can access the system, manage tasks, or obtain information
Password Management
Generate and store passwords in an encrypted database and assist in retrieving lost or forgotten passwords
Push Notifications
Trigger clickable pop-up messages
Access Control
Regulate who can view information within the system
Email Alerts
Receive and/or send email notifications for urgent updates, requests, or other information
Data Security
Protect sensitive data for digital privacy
Reporting/Analytics
View and track pertinent metrics to find patterns and gain insights from data
Knowledge Base Management
Manage a repository of information that includes articles, FAQs, or tutorials used for self-service support
Monitoring
Observe and track the demand, usage, progress or quality of a system, product, or user
Multiple Authentication Methods
Authenticate user identities through different methods such as ID cards, PINs, passwords, RFID, and biometrics
Generative AI
Use AI to generate content in the form of text, images, videos, etc.
AI Copilot
A virtual assistant that uses AI to pursue goals and complete tasks on behalf of users
Access Controls/Permissions
Define levels of authorization for access to specific files or systems
Active Directory Integration
Integrates with Active Directory
Multiple User Accounts
Allow multiple users with individual logins and varying permissions to use the same account, software, portal, or service
Data Verification
Process of checking different types of data for accuracy to avoid errors or inconsistencies
Access Management
Control and manage access to company resources
Activity Dashboard
Dashboard to view the status of ongoing processes, identify current incidents and track past activities
Secure Data Storage
Securely stores data to prevent data loss or breaches
Data Security
Protect sensitive data for digital privacy
Biometrics
Identify or authenticate a person's identity through biological data such as fingerprints or facial patterns.
HIPAA Compliant
Compliant with HIPAA, which sets standards for sensitive patient data protection
SSL Security
Security protocol that ensures secure, encrypted communication over the internet, safeguarding sensitive data from unauthorized access
Alerts/Notifications
Alerts or notifications of various types such as pop-up messages, sounds, banners, or badges
API
Application programming interface that allows for integration with other systems/databases
Data Synchronization
Synchronizing data between two or more devices/systems and automatically updating changes to maintain consistency
Secure Login
At least a username and password is required to access the system
Policy Management
Create, manage, and track policies and procedures within an organization
User Management
Manage user accounts, profiles, roles, permissions, and other details across applications, devices or networks
Real-Time Data
Receive data and information in real time
Password Management
Generate and store passwords in an encrypted database and assist in retrieving lost or forgotten passwords
Self Service Portal
Online portal through which end users can access the system, manage tasks, or obtain information
Reporting/Analytics
View and track pertinent metrics to find patterns and gain insights from data
Employee Onboarding
Process of familiarizing new employees with the company, their position, and responsibilities
Activity Tracking
Track and document all activities across devices, networks, and other systems
Audit Trail
A record of all activities within the system, including user access, changes made, etc.
Compliance Management
Track and manage adherence to policies for any service, product, process, or supplier
Credential Management
Manage usernames, account numbers, passwords, biometric data, public access keys, and other documentation
Third-Party Integrations
Set up connections to third-party platforms to improve business processes
Workflow Management
Create, design and manage workflows for repetitive tasks



