Auth0 is an identity management platform for developers and application teams. It gives users a platform to authenticate and authorize, providing secure access to applications, devices, and users. Auth0 aims to provide the simplicity, extensibility, and expertise to scale and protect any application, for any audience. Integrate Auth0 into any app, written in any language, and any framework.
$23
per month
Cisco Duo
Score 9.5 out of 10
N/A
Cisco Duo is a two-factor authentication system (2FA), acquired by Cisco in October 2018. It provides single sign-on (SSO) and endpoint visibility, as well as access controls and policy controlled adaptive authentication.
$3
per month per user
Pricing
Auth0
Cisco Duo
Editions & Modules
1,000 External Active Users
$23
per month
2,000 External Active Users
$57
per month
5,000 External Active Users
$114
per month
500 External Active Machines
$130
per month
10,000 External Active Users
$228
per month
20,000 External Active Users
$455
per month
50,000 External Active Users
1,138
per month
Over 50,000 External Active Users
Contact for quote
Enterprise
Contact for quote
Duo Essentials
$3
per month per user
Duo Advantage
$6
per month per user
Duo Premier
$9
per month per user
Offerings
Pricing Offerings
Auth0
Cisco Duo
Free Trial
Yes
Yes
Free/Freemium Version
Yes
No
Premium Consulting/Integration Services
No
No
Entry-level Setup Fee
Optional
No setup fee
Additional Details
—
—
More Pricing Information
Community Pulse
Auth0
Cisco Duo
Features
Auth0
Cisco Duo
Identity Management
Comparison of Identity Management features of Product A and Product B
Auth0 is very well suited for situations where a JSON web token can be used for authorizing APIs, websites, and mobile devices. It's especially useful if the JWT validation can happen at a gateway layer. It's especially useful if you only need to verify the user's email address or mobile number as the passwordless login is easy to implement.
Cisco Duois is well suited in all kinds of scenarios where you need to ensure proper security measurements, I think. We can't just rely on our passwords only, as they can be easily stolen through phishing or data breaches thus keeping multi factor authentication is quite essential. I always prefer MFA or at least 2FA for any critical system.
Auth0 can be somewhat limiting if you want a lot of control over the design of your authentication flow. Custom branding can be done, but it may be limited depending on how you plan to integrate.
The Auth0 API documentation has proven confusing at times; a single API endpoint's behaviour will change based on inputs and configured settings (e.g. offline_access). Consequently fields that are advertised as being returned in a response might not be there or have different values if you miss a key detail and it can be difficult to debug when this happens. All information required is available in the documentation but requires some digging.
The toggle to switch tenants feels a bit odd, it works, but I've had a few instances where I didn't realize I was on a staging tenant looking for something that was on the production tenant. Not a big deal, just something to watch out for.
Documentation is oftentimes missing key information for proper implementation. This is circumvented by reading third-party guides or contacting support for additional details.
They do not push Fail-Closed as much as I think they should. Fail-Open is fairly trivial to bypass and it should be made known to the customer during setup how much this will affect overall security.
More vendor integration is something that is always craved by administrators. There are so many third-parties to integrate with.
There are a lot of competing solutions on the market; however, Duo "just works", and there is little to no learning curve for the new members to be acclimated to it. As long as that continues I see it as the preferred option moving forward
- integration and ease of implementation - great over all product support specially for passkey biometric authentication -Auth0 is very reliable to use their API integration for security verification. It provides best API to integrate our website and application with Single Sign In option and two step verification option. Sales and technical teams are always there to provide support
La interfaz es intuitiva y fácil de navegar, lo que permite a los usuarios administrar sus dispositivos y acceder a las políticas sin problemas. La integración con las aplicaciones SSO y SaaS facilita aún más el proceso de acceso, mejorando la experiencia del usuario.
In the last 5+ years we've been using Duo, there may have been 1 outage that impacted us. We do receive periodic notifications of issues but, for the most part, they impact carriers or functionality that we either don't use, or do not care about.
There isn't a clear method to get a hold of support when trouble arises if you're on their standard plan. You can file a support ticket and they generally are responsive. I've often been able to find similar questions to the questions I've had when it comes to support in their ticket history, however, some have been closed without a satisfactory conclusion for the original poster.
Since it’s a reputable company, I have received technical support when needed and I trust that if anything else happens I can contact them with any issues. I haven’t experienced bad customer service and I totally feel supported while using this authentication method. No complains so far and the high rating!
Implementation was straight forward and you can isolate different scenarios in order to test new application setup or add to an existing setup. Gui interface is pretty easy to understand and follow. I had no experience with Duo and still manage to easily set up new policies and rules.
Auth0 is non-evasive and does not require software download. It is user friendly, seamless, and doesn't require additional actions on the part of the user. IBM Trusteer is none of these things and is based on a technology stack that cannot scale in the same way as Auth0. We believe Auth0 provides a superior solution and is well suited for our own technology stack.
Ultimately we ended up going with Cisco Duo because we are a Cisco shop. All of our networking infrastructure, our phones, our wireless environment is Cisco based. It made logical sense to stay with a product that we already have a line of support with. With a smaller support / tech group we depend on outside Cisco support. That support is already here for us, so we stayed with a Cisco product.
Development time has been allocated to the more core parts of our business.
We are confident in the security of our user's accounts and their data.
Auth0's login flows are customizable which means that we don't have to worry about users being confused when logging in/changing their passwords, and we didn't event have to spend that much time configuring this. (Full in-house development for login could take weeks to get right.)
It's one of those things that only costs money in the sense of you have to convince a leadership team to spend money to save money, right? Like a compromise is far more expensive than duo paying for duo. So specifically it's really just about trying to prevent problems. And so while it costs money and we don't have a direct return on investment that we can point out immediately, I would still always advocate for it just because it keeps security. Paying for security is cheaper than getting compromised essentially.