HID DigitalPersona (formerly Crossmatch) provides a comprehensive multi-factor authentication solution. The vendor’s value proposition is that their solution frees users from cumbersome login activities while making it easy for an IT Team to secure access to their networks, data and applications.
$3.75
per user per month
PingOne from Ping Identity
Score 5.4 out of 10
N/A
The PingOne Cloud Platform from Ping Identity in Denver, Colorado is an identity management and access solution (IAM) for enterprises. Features of the products include single sign-on, multi-factor authentication, user management with directory, provisioning and deprovisioning. The solution is presented as a comprehensive, standards-based platform that allows users and devices to securely access any service, application or API from any device. Designed for hybrid IT environments, it can be…
$20,000
per year
Pricing
HID DigitalPersona
PingOne from Ping Identity
Editions & Modules
HID DigitalPersona
$3.75
per user per month
Essential
$20,000
per year
Plus
$40,000
per year
Premium
Contact Sales
Offerings
Pricing Offerings
HID DigitalPersona
PingOne from Ping Identity
Free Trial
Yes
Yes
Free/Freemium Version
No
No
Premium Consulting/Integration Services
No
No
Entry-level Setup Fee
Required
No setup fee
Additional Details
—
Try PingOne for Customers for free. Sign up for a free 30-day trial of PingOne for customers.
During the onboarding process, remote workers can enroll their fingerprints or create secure PINs. This eliminates the need for complicated passwords and enables them to safely access company resources and critical apps from remote locations. HID DigitalPersona's robust authentication techniques and access control features can assist you in adhering to data security laws.
The products we're using work well and are reliable. We've had very few outages, and when we have, their support team has been highly responsive and addressed the issues quickly. They are very customer focused and have been great partners throughout the relationship. I'm looking to adopt more of their technologies over the coming year.
PingFederate is feature-rich, and quickly updated with the latest standards and profiles. This gives us more tools to apply identity standards to modern business challenges.
PingFederate and PingCentral were also easy to deploy within docker containers and weave into an infra-as-code deployment, keeping operational overhead low.
PingID has an array of supported authenticators for nearly every use case, and early FIDO2 support has us looking into moving to passwordless much more quickly than I had anticipated.
Multiple domains - DigitalPersona struggles with multiple domains. Since the solution is licensed per domain, migrating users between domains can be troublesome to keep licensed. Additionally, migrating to a new domain removes the AD leaf objects that store all digital persona information, essentially wiping out and credentials or other stored information.
Password change - DigitalPersona can be confusing to update when a stored password for a website is updated. The password is entered, and then the user is redirected to the websites password change page. Users must then authenticate with a Digital persona credential again before being prompted by Digital Persona to update the password. If the user is allowed to change the password manually through the websites page, this will lead to what is stored in Digital Persona being out of sync with the new password, and eventually account lockouts.
Terminal Server - DigitalPersona has performance issues when utilized on a high-traffic terminal server. Often it causes big CPU spikes as well as hanging sessions upon disconnect.
It is wonderful for multifactor authentication and gives us many options for what we use to authenticate. All of our users use it and it is engrained into our group policies and people would be very disappointed if it went away.
I think there are still fundamental enhancements needed to be added to the management consoles and I think there ought to be a Centralized, Windows Based "Thick" Management Application instead of individual utilities which vary from MMCs, Scripts, Wizards, etc.
Easy to use; all UI's are user friendly and easy to learn.[The] possibility to use API is [a] big value as well. We really like integration with CyberArk; with it we can manage privileged accounts according to company standards without breaking any rules, and we can be 100% sure that only approved persons will have administrative access.
Extremely poor; I've never encountered such. Professional Services completely dropped us for months. Crossmatch tech support seems like it has 3 techs tops! No response to emails, calls, the absolute worst! I will never recommend DP to anyone.
For our enterprise, they've assigned a customer success manager to ensure our needs are being addressed, and that person is top notch in knowing our priorities, enhancement requests, and open cases. Every time we've needed to engage support for a problem or a how-to question, they've been highly responsive and followed up with us to ensure the case was completely resolved. Their support personnel are highly skilled and trained. This is a very customer-centric company.
Could use tools to audit license usage at a more granular level as to allow an administrator to free up licenses from users whom seldom use their biometrics to login.
We evaluated Cisco DUO but ultimately chose HID because of their support for biometrics. With DUO every user would have to have the authentication app on their personal phone and pull it out each time they had to log in. We definitely did not want this for our frontline staff as it would slow the process way down
We tested PingOne but our security team was not happy with it (because of cloud exposure). We tested PingId as well but our security team was not happy with it (because of cloud exposure). We [spent] some time on PingDataGovernance but so far we don't have any use case for this product. We started exploration for PingDataSync (to synchronize two different LDAP directories), [and] so far it looks promising.
Provides a quick one finger authentication\log-on.
Logging onto a machine that is used by several other users, such as in retail is no problem because the DigitalPersona software does a switch user function instead of logging out the other user.
One negative that was apparent immediately after installing the DigitalPersona software was that users very easily forgot their Windows passwords because of the one finger log-on.