{"id":6911,"date":"2023-11-21T15:20:25","date_gmt":"2023-11-21T19:20:25","guid":{"rendered":"https:\/\/solutionsreview.com\/identity-management\/?p=6911"},"modified":"2023-11-29T16:20:00","modified_gmt":"2023-11-29T20:20:00","slug":"overcoming-the-challenges-of-adding-passwordless-to-legacy-apps","status":"publish","type":"post","link":"https:\/\/solutionsreview.com\/identity-management\/overcoming-the-challenges-of-adding-passwordless-to-legacy-apps\/","title":{"rendered":"Overcoming the Challenges of Adding Passwordless to Legacy Apps"},"content":{"rendered":"<p><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-6912\" src=\"https:\/\/solutionsreview.com\/identity-management\/files\/2023\/11\/4-3.jpg\" alt=\"passwordless\" width=\"800\" height=\"400\" srcset=\"https:\/\/solutionsreview.com\/identity-management\/files\/2023\/11\/4-3.jpg 800w, https:\/\/solutionsreview.com\/identity-management\/files\/2023\/11\/4-3-300x150.jpg 300w, https:\/\/solutionsreview.com\/identity-management\/files\/2023\/11\/4-3-768x384.jpg 768w\" sizes=\"(max-width: 800px) 100vw, 800px\" \/><\/p>\n<p><em><strong>Solutions Review\u2019s\u00a0<a class=\"fui-Link ___1idfs5o f3rmtva f1ewtqcl fyind8e f1k6fduh f1w7gpdv fk6fouc fjoy568 figsok6 f1hu3pq6 f11qmguv f19f4twv f1tyq0we f1g0x7ka fhxju0i f1qch9an f1cnd47f fqv5qza f1vmzxwi f1o700av f13mvf36 f1cmlufx f9n3di6 f1ids18y f1tx3yz7 f1deo86v f1eh06m1 f1iescvh ftqa4ok f2hkw1w fhgqx19 f1olyrje f1p93eir f1h8hb77 f1x7u7e9 f10aw75t fsle3fq f17ae5zn\" title=\"https:\/\/solutionsreview.com\/solutions-review-contributor-guidelines\/\" href=\"https:\/\/solutionsreview.com\/solutions-review-contributor-guidelines\/\" target=\"_blank\" rel=\"noreferrer noopener\" aria-label=\"Link Contributed Content Series\"><u>Contributed Content Series<\/u><\/a> is a collection of contributed articles written by thought leaders in enterprise software categories. Steve Lay of <a href=\"https:\/\/www.strata.io\/\" target=\"_blank\" rel=\"noopener\">Strata Identity<\/a> bridges the gap between legacy apps and modern protocols for a true passwordless authentication experience.<\/strong><\/em><\/p>\n<p>Passwords have been a fact of life for 60 years now, ever since MIT came up with the idea of letting multiple people share a computer by verifying a user\u2019s identity first. But as the password nears retirement age, organizations are struggling to make passwordless authentication a reality.<\/p>\n<p>Eliminating passwords is being driven by the need to reduce friction, but more importantly, to implement stronger security controls such as biometrics like fingerprints, facial recognition, and passkeys that are linked to a user\u2019s device. However, one of the challenges standing in the way of the migration away from passwords is supporting these new authentication methods on both legacy and modern platforms. In fact, almost half the IT decision-makers in a recent poll said their organizations have yet to adopt passwordless authentication because their applications are not designed to support it.<\/p>\n<h2><strong>Passwordless: Overcoming the Challenges of Legacy Apps<\/strong><\/h2>\n<hr \/>\n<h3><strong>Legacy Apps; Modern Protocols<\/strong><\/h3>\n<p>So why can&#8217;t legacy apps support passwordless authentication? The short answer is: Because they cannot understand modern authentication protocols. Most legacy apps were created before OpenID Connect (OIDC) and Fast Identity Online (FIDO), standards that are required to integrate with passwordless technology directly.<\/p>\n<p>These protocols are vital for passwordless systems in two ways. First, they mediate the exchange of information between identity systems and the passwordless authentication provider. Second, they are required to manage the user experience, in this case prompting the user to scan their face or thumbprint, or another factor used to replace those combinations of pet\u2019s names and kids\u2019 birthdays that have proved less effective as authentication.<\/p>\n<p>When legacy apps can\u2019t integrate with these protocols, enabling a passwordless user experience requires development work to modify the code of each application so that it can integrate with the identity system and\/or the passwordless provider\u2019s system.<\/p>\n<p>This leaves enterprises with the following choices:<\/p>\n<ul>\n<li><em>Do nothing and accept the risk (we\u2019re all familiar with the Verizon annual survey\u2019s dismal news on credential theft and abuse).<\/em><\/li>\n<li><em>Rely on an identity provider\u2019s passwordless authentication, which layers multifactor authentication (MFA) over legacy apps. This is not an ideal choice because MFA is not truly passwordless\u2014it still requires a password upfront.<\/em><\/li>\n<\/ul>\n<p>For example, if an organization uses a cloud identity provider, the legacy application hands off the login to the Cloud IDP, which uses OIDC to authenticate the user and call back to the app. However, that first handoff to the authentication provider still requires a traditional username and password, which is not true passwordless authentication. The other alternative is to use providers that require deep integration at the Active Directory domain controller.<\/p>\n<h3><strong>Abstraction is the Key to Passwordless Adoption<\/strong><\/h3>\n<p>Any application that\u2019s a candidate for passwordless authentication is so for a reason: it performs a sensitive function worthy of protection. Access is usually controlled by some legacy web access management platform, not left open to all comers. So how do we overcome the challenge of adding passwordless access to these apps?<\/p>\n<p>The most useful practice is to separate identity authentication from the individual applications and logins by creating an enforcement layer that decouples identity validation and access policy enforcement. This can be accomplished using an abstraction layer (i.e., identity orchestration) that can translate modern identity protocols and operate with on-premises or cloud-based apps.<\/p>\n<p>The key concept in this architecture is that by decoupling applications from the passwordless provider, the app itself never has to be integrated with anything other than that abstraction layer\u2014 not even the passwordless provider itself. This also enables administrators to manage access policies within that abstraction layer. The application doesn&#8217;t know the difference, and neither do end-users.<\/p>\n<p>One huge benefit of this approach is that developers never have to touch a line of code in the application. The work to integrate with the application itself becomes very lightweight and typically will only require discovery. This architecture essentially creates a walled garden around the application with only one gate. It is straightforward to configure and enforce\u2014and results in a true passwordless experience for legacy apps.<\/p>\n<h3><strong>Final Thoughts<\/strong><\/h3>\n<p>Consider this example: An organization running on-premises applications that use Microsoft Active Directory that wants to transition to cloud-based Azure for identity management and passwordless access. Using an orchestration layer to decouple both identity and passwordless systems from the applications, simple configuration changes in the orchestrator can enforce new user flows and access policies across every single application without modifying any code in the applications themselves.<\/p>\n<p>The use of identity orchestration makes it possible to completely avoid the kind of development work that turns passwordless authentication into a time-consuming, costly effort, and is blocking its adoption at so many organizations. It can bridge the gap between modern identity protocols, legacy applications, and the passwordless future.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Solutions Review\u2019s\u00a0Contributed Content Series is a collection of contributed articles written by thought leaders in enterprise software categories. Steve Lay of Strata Identity bridges the gap between legacy apps and modern protocols for a true passwordless authentication experience. Passwords have been a fact of life for 60 years now, ever since MIT came up with [&hellip;]<\/p>\n","protected":false},"author":979,"featured_media":6912,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"inline_featured_image":false,"footnotes":""},"categories":[5,1],"tags":[],"acf":[],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v23.5 - https:\/\/yoast.com\/wordpress\/plugins\/seo\/ -->\n<title>Overcoming the Challenges of Adding Passwordless to Legacy Apps<\/title>\n<meta name=\"description\" content=\"Steve Lay of Strata Identity bridges the gap between legacy apps and modern protocols for a true passwordless authentication experience.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/solutionsreview.com\/identity-management\/overcoming-the-challenges-of-adding-passwordless-to-legacy-apps\/\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Steve Lay\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"4 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\/\/schema.org\",\"@graph\":[{\"@type\":\"WebPage\",\"@id\":\"https:\/\/solutionsreview.com\/identity-management\/overcoming-the-challenges-of-adding-passwordless-to-legacy-apps\/\",\"url\":\"https:\/\/solutionsreview.com\/identity-management\/overcoming-the-challenges-of-adding-passwordless-to-legacy-apps\/\",\"name\":\"Overcoming the Challenges of Adding Passwordless to Legacy Apps\",\"isPartOf\":{\"@id\":\"https:\/\/solutionsreview.com\/identity-management\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\/\/solutionsreview.com\/identity-management\/overcoming-the-challenges-of-adding-passwordless-to-legacy-apps\/#primaryimage\"},\"image\":{\"@id\":\"https:\/\/solutionsreview.com\/identity-management\/overcoming-the-challenges-of-adding-passwordless-to-legacy-apps\/#primaryimage\"},\"thumbnailUrl\":\"https:\/\/solutionsreview.com\/identity-management\/files\/2023\/11\/4-3.jpg\",\"datePublished\":\"2023-11-21T19:20:25+00:00\",\"dateModified\":\"2023-11-29T20:20:00+00:00\",\"author\":{\"@id\":\"https:\/\/solutionsreview.com\/identity-management\/#\/schema\/person\/299667468a9fe60e677ad52f3f3b5809\"},\"description\":\"Steve Lay of Strata Identity bridges the gap between legacy apps and modern protocols for a true passwordless authentication experience.\",\"breadcrumb\":{\"@id\":\"https:\/\/solutionsreview.com\/identity-management\/overcoming-the-challenges-of-adding-passwordless-to-legacy-apps\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\/\/solutionsreview.com\/identity-management\/overcoming-the-challenges-of-adding-passwordless-to-legacy-apps\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/solutionsreview.com\/identity-management\/overcoming-the-challenges-of-adding-passwordless-to-legacy-apps\/#primaryimage\",\"url\":\"https:\/\/solutionsreview.com\/identity-management\/files\/2023\/11\/4-3.jpg\",\"contentUrl\":\"https:\/\/solutionsreview.com\/identity-management\/files\/2023\/11\/4-3.jpg\",\"width\":800,\"height\":400,\"caption\":\"passwordless\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\/\/solutionsreview.com\/identity-management\/overcoming-the-challenges-of-adding-passwordless-to-legacy-apps\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\/\/solutionsreview.com\/identity-management\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Overcoming the Challenges of Adding Passwordless to Legacy Apps\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\/\/solutionsreview.com\/identity-management\/#website\",\"url\":\"https:\/\/solutionsreview.com\/identity-management\/\",\"name\":\"Identity and Access Management Solutions | Solutions Review\",\"description\":\"Evaluating Enterprise IAM Software, Identity Governance &amp; Access Control Tools.\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\/\/solutionsreview.com\/identity-management\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Person\",\"@id\":\"https:\/\/solutionsreview.com\/identity-management\/#\/schema\/person\/299667468a9fe60e677ad52f3f3b5809\",\"name\":\"Steve Lay\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/solutionsreview.com\/identity-management\/#\/schema\/person\/image\/\",\"url\":\"https:\/\/secure.gravatar.com\/avatar\/ef743d3f8a07e9f6ccb8e81bc4578c1c?s=96&d=mm&r=g\",\"contentUrl\":\"https:\/\/secure.gravatar.com\/avatar\/ef743d3f8a07e9f6ccb8e81bc4578c1c?s=96&d=mm&r=g\",\"caption\":\"Steve Lay\"},\"description\":\"Steve Lay is the Senior Sales Engineer at Strata Identity. He has more than 20 years of customer-facing experience in identity governance, access management, Single Sign-On, privileged access management, SIEM \/ security analytics, and data access governance platforms. He has held senior technical roles at SailPoint, Sirius Computer Solutions, and IBM. At SailPoint, he led technical sales engagements for Fortune 100 customers. With Sirius Computer Solutions, Steve led technical presales efforts across North America for SIEM, IAM, and data security. At IBM, he was a technical security specialist.\",\"url\":\"https:\/\/solutionsreview.com\/identity-management\/author\/slay\/\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Overcoming the Challenges of Adding Passwordless to Legacy Apps","description":"Steve Lay of Strata Identity bridges the gap between legacy apps and modern protocols for a true passwordless authentication experience.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/solutionsreview.com\/identity-management\/overcoming-the-challenges-of-adding-passwordless-to-legacy-apps\/","twitter_misc":{"Written by":"Steve Lay","Est. reading time":"4 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"WebPage","@id":"https:\/\/solutionsreview.com\/identity-management\/overcoming-the-challenges-of-adding-passwordless-to-legacy-apps\/","url":"https:\/\/solutionsreview.com\/identity-management\/overcoming-the-challenges-of-adding-passwordless-to-legacy-apps\/","name":"Overcoming the Challenges of Adding Passwordless to Legacy Apps","isPartOf":{"@id":"https:\/\/solutionsreview.com\/identity-management\/#website"},"primaryImageOfPage":{"@id":"https:\/\/solutionsreview.com\/identity-management\/overcoming-the-challenges-of-adding-passwordless-to-legacy-apps\/#primaryimage"},"image":{"@id":"https:\/\/solutionsreview.com\/identity-management\/overcoming-the-challenges-of-adding-passwordless-to-legacy-apps\/#primaryimage"},"thumbnailUrl":"https:\/\/solutionsreview.com\/identity-management\/files\/2023\/11\/4-3.jpg","datePublished":"2023-11-21T19:20:25+00:00","dateModified":"2023-11-29T20:20:00+00:00","author":{"@id":"https:\/\/solutionsreview.com\/identity-management\/#\/schema\/person\/299667468a9fe60e677ad52f3f3b5809"},"description":"Steve Lay of Strata Identity bridges the gap between legacy apps and modern protocols for a true passwordless authentication experience.","breadcrumb":{"@id":"https:\/\/solutionsreview.com\/identity-management\/overcoming-the-challenges-of-adding-passwordless-to-legacy-apps\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/solutionsreview.com\/identity-management\/overcoming-the-challenges-of-adding-passwordless-to-legacy-apps\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/solutionsreview.com\/identity-management\/overcoming-the-challenges-of-adding-passwordless-to-legacy-apps\/#primaryimage","url":"https:\/\/solutionsreview.com\/identity-management\/files\/2023\/11\/4-3.jpg","contentUrl":"https:\/\/solutionsreview.com\/identity-management\/files\/2023\/11\/4-3.jpg","width":800,"height":400,"caption":"passwordless"},{"@type":"BreadcrumbList","@id":"https:\/\/solutionsreview.com\/identity-management\/overcoming-the-challenges-of-adding-passwordless-to-legacy-apps\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/solutionsreview.com\/identity-management\/"},{"@type":"ListItem","position":2,"name":"Overcoming the Challenges of Adding Passwordless to Legacy Apps"}]},{"@type":"WebSite","@id":"https:\/\/solutionsreview.com\/identity-management\/#website","url":"https:\/\/solutionsreview.com\/identity-management\/","name":"Identity and Access Management Solutions | Solutions Review","description":"Evaluating Enterprise IAM Software, Identity Governance &amp; Access Control Tools.","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/solutionsreview.com\/identity-management\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Person","@id":"https:\/\/solutionsreview.com\/identity-management\/#\/schema\/person\/299667468a9fe60e677ad52f3f3b5809","name":"Steve Lay","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/solutionsreview.com\/identity-management\/#\/schema\/person\/image\/","url":"https:\/\/secure.gravatar.com\/avatar\/ef743d3f8a07e9f6ccb8e81bc4578c1c?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/ef743d3f8a07e9f6ccb8e81bc4578c1c?s=96&d=mm&r=g","caption":"Steve Lay"},"description":"Steve Lay is the Senior Sales Engineer at Strata Identity. He has more than 20 years of customer-facing experience in identity governance, access management, Single Sign-On, privileged access management, SIEM \/ security analytics, and data access governance platforms. He has held senior technical roles at SailPoint, Sirius Computer Solutions, and IBM. At SailPoint, he led technical sales engagements for Fortune 100 customers. With Sirius Computer Solutions, Steve led technical presales efforts across North America for SIEM, IAM, and data security. At IBM, he was a technical security specialist.","url":"https:\/\/solutionsreview.com\/identity-management\/author\/slay\/"}]}},"_links":{"self":[{"href":"https:\/\/solutionsreview.com\/identity-management\/wp-json\/wp\/v2\/posts\/6911"}],"collection":[{"href":"https:\/\/solutionsreview.com\/identity-management\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/solutionsreview.com\/identity-management\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/solutionsreview.com\/identity-management\/wp-json\/wp\/v2\/users\/979"}],"replies":[{"embeddable":true,"href":"https:\/\/solutionsreview.com\/identity-management\/wp-json\/wp\/v2\/comments?post=6911"}],"version-history":[{"count":0,"href":"https:\/\/solutionsreview.com\/identity-management\/wp-json\/wp\/v2\/posts\/6911\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/solutionsreview.com\/identity-management\/wp-json\/wp\/v2\/media\/6912"}],"wp:attachment":[{"href":"https:\/\/solutionsreview.com\/identity-management\/wp-json\/wp\/v2\/media?parent=6911"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/solutionsreview.com\/identity-management\/wp-json\/wp\/v2\/categories?post=6911"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/solutionsreview.com\/identity-management\/wp-json\/wp\/v2\/tags?post=6911"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}