Optimal Authentication Service™

Authentication as a ServiceThe Optimal IdM authentication-as-a-service (AaaS) offering, called The Optimal Authentication Service (OAS), is a hosted RESTful web service that provides customers with the ability to perform various types and levels of authentications including single authentication and multi-factor authentication (MFA).

OAS may be deployed in any data center and is offered in a multi-tenant environment as well as in an isolated/dedicated environment. OAS can easily integrate into your applications using the RESTful call or by using the Optimal IdM .NET SDK or jQuery plugin.

The Optimal Authentication Service permits the addition of Multi-Factor authentication

Because OAS is available via industry standard REST calls, both web and non-web applications may easily add MFA capabilities, including passwordless authentication options. As a MFA service, OAS helps prevent phishing and man-in-the-middle attacks by delivering push notifications to a user’s registered mobile device which optionally works with fingerprint enabled systems. OAS includes other MFA options like Time-based One-Time Password (TOTP) and traditional One-Time Passcodes (OTP) that can be sent via Short Message Service (SMS), Email or voice calls.

Each can be used as a stand-alone option or in conjunction with a complete Identity Access and Management (IAM) program.  When integrating with an existing system, you can leverage OTPs via SMS, Email or voice without storing any information about the user in the cloud service.  When using TOTP or push notifications, only device information is stored, which reduces the amount of personal identifiable information that is needed.  The service can also be used to access applications in a passwordless authentication method by sending a push notifications to a mobile device for logins.

Optimal IdM Offers the First ever Virtual Directory with advanced MFA built-in

MFA For Windows Servers

Accessing Windows servers, whether in a local data-center or cloud-based, should always require multi-factor authentication (MFA).  Until now, it has been a difficult task to setup MFA for server access whether directly through the console or via remote-desktop (RDP).  The Optimal GINA™ Plugin (pGina) together with OAS, offers a flexible and secure solution for accessing Windows servers providing state-of-the-art MFA technology leveraging the user’s mobile device and PUSH notification technology.  Accounts are easily managed in The OptimalCloud™.   pGina also provides the ability to map cloud groups to local server/domain groups when logging in.  In fact, users that are configured to login to a given server via The OptimalCoud can automatically have an account created locally and even optionally deleted when they log out.

The Optimal Authentication Service includes:

  • Passwordless Access method
  • Basic Authentication (username & password)
  • Strong-Authentication via E-Mail (MFA)
  • Strong-Authentication via SMS/Text Message (MFA)
  • Strong-Authentication via VOICE (where a call is placed to a number) (MFA)
  • Strong-Authentication via TOTP (MFA)
  • Strong-Authentication via PUSH (alert to a mobile device)(MFA)
  • Basic Authentication + Strong-Authentication via PUSH (alert to a mobile device)(Fingerprint authentication to iOS and Android)(MFA)


For more information about authentication-as-a-service or MFA, contact Optimal IdM today.

google play logo    app store logo