In light of the recent integration of ForgeRock into Ping Identity, The Cyber Hut has received numerous inquiry calls regarding potential integrations, feature overlap, next steps and existing deployment advice with respect to the merger.

It is a topic we have covered in several episodes of The Week in Identity podcast over recent months:

Episode 37Community feedback and discussion; customer advice
Episode 36Public announcement of deal complete – what is means for the market
Episode 13Thoma Bravo announce intention to acquire – first thoughts

To that end, we’re making available a basic feature comparison matrix that highlights the basic capabilities each vendor has in each of the main identity areas of B2E and B2C. This matrix was compiled using publicly available references with peer review by those who have implemented ForgeRock or Ping technologies in the last 3 years.

Note this is not a comment on the strength of said features, but more to highlight existing go to market strategies.

B2E Workforce:

Identity TypeCapabilityForgeRockPing Identity
B2E WorkforceIdentity Life Cycle ManagementIDM. Homegrown solution focused on data connectivity.
B2E WorkforceIdentity StorageForgeRock Directory Services. Based on the OpenDS project from Sun. Ping Directory and Directory Proxy.
B2E WorkforceIdentity Governance and AdministrationAI lead aspect for permissions analysis. known as Autonomous Identity. Based on technology developed by Accenture. Access request/review component known as ForgeRock IGA.Partner with likes of Sailpoint or You Attest.
B2E WorkforceAuthenticationFalls under ForgeRock Access Management. Previously OpenAM (OpenSSO) from Sun Microsystems. Broad array of modular optionsPing Authentication Authority. Out of the box modules and policies that powers SSO
B2E WorkforceMulti Factor AuthenticationFalls under ForgeRock Access Management. Previously OpenAM (OpenSSO) from Sun Microsystems. Push notifications, HOTP, OTP and numerous strong auth partners via Trust NetworkNumerous OOTB integrations for Ping MFA (OTP, Push, FIDO2). Also partner with likes of Yubico.
B2E WorkforcePasswordlessFalls under ForgeRock Access Management. Previously OpenAM (OpenSSO) from Sun Microsystems. Push notifications, HOTP, OTP, WebAuth native support. Plus partnersPing Zero marketing. Leverage FIDO2, device and risk analysis.
B2E WorkforceBiometric AuthenticationFalls under ForgeRock Access Management. Previously OpenAM (OpenSSO) from Sun Microsystems. Mobile lead capabilities. Specialist biometry via Trust Network partnersNumerous OOTB integrations for Ping MFA (OTP, Push, FIDO2). Also partner with likes of Yubico.
B2E WorkforceAuthorizationFalls under ForgeRock Access Management. Policy based access with agent and API lead enforcement.Ping Dynamic Authorization Powered by acquisition of Symphonic software in 2020
B2E WorkforceAuthorization EnforcementPolicy agents, Identity Gateway and native APIsIntegration with third party gateways.
B2E WorkforceFederation SAMLFalls under ForgeRock Access Management. SAML provider/relying partner supportPing Federate historic product. Multi-function
B2E WorkforceFederation OAuth2/OIDCFalls under ForgeRock Access Management. OAuth2 provider/relying party support. Many profiles/extensions.Via Ping Federate as OAuth2 provider
B2E WorkforceGatewayLightweight reverse proxy called ForgeRock Identity GatewayIntegration with third party gateways. Also have API Security Enforcer. AI based analysis (based on Elastic Beam acquisition in 2018?)
B2E WorkforceConnectorsIdentity Connector Framework. Small yet powerful collection
B2E WorkforceSDKiOS, Android and JavaScript. Primarily for authentication integration.API Toolkit Ping One (cloud) mobile native SDKs.
B2E WorkforceMobile AppBasic app for Android (100k downloads) and IoSBasic app for Android (5M downloads) and iOS
B2E WorkforceSingle Sign OnFalls under ForgeRock Access ManagementPing SSO with range of SAML/OAuth2 capabilitites and session management

B2C Customer:

Identity TypeCapabilityForgeRockPing Identity
B2C CustomerIdentity ProofingPartner networkNative via Ping Verification service.
B2C CustomerFraud / ATOForgeRock Autonomous Access. Organic development of AI/ML activity analysisPing Protect
B2C CustomerRegistration / Progressive ProfilingVia ForgeRock IDM integrated with Intelligent AccessModular components (see fraud, verification and DaVinci orchestration). Dedicated microsite.
B2C CustomerMulti Factor AuthenticationFalls under ForgeRock Access Management. Previously OpenAM (OpenSSO) from Sun Microsystems. Push notifications, HOTP, OTP and numerous strong auth partners via Trust NetworkModular components (see fraud, verification and DaVinci orchestration). Dedicated microsite.
B2C CustomerPasswordlessFalls under ForgeRock Access Management. Previously OpenAM (OpenSSO) from Sun Microsystems. Push notifications, HOTP, OTP, WebAuth native support. Plus partnersModular components (see fraud, verification and DaVinci orchestration). Dedicated microsite.
B2C CustomerBiometricsFalls under ForgeRock Access Management. Previously OpenAM (OpenSSO) from Sun Microsystems. Mobile lead capabilities. Specialist biometry via Trust Network partnersModular components (see fraud, verification and DaVinci orchestration). Dedicated microsite.
B2C CustomerBYOIVia ForgeRock IDM integrated with Intelligent AccessModular components (see fraud, verification and DaVinci orchestration). Dedicated microsite.
B2C CustomerPrivacy PreservationPartner for vaulting and encryption. Support for UMA for consent and data sharing. Soverienty via directory.Privacy microsite. Modular cpaabilties. Storage via Unbound acquisition. OAuth2 sharing. Consent capture
B2C CustomerIoT IntegrationOAuth2 Device Flow support. Some edge SDK capabilities.

Other:

Identity TypeCapabilityForgeRockPing Identity
GeneralOrchestrationHistorically known as Authentication Trees, Intelligent Access, Orchestration Trees.Ping DaVinci (via acquisition of Singular Key in 2021)
GeneralDeploymentOn-prem and more recently cloud. Cloud is same on-prem components, containerized and hosted by ForgeRock.Ping One is cloud model for B2E and B2C
GeneralScaleKnown for large multi-million storage of identities. Transactions per second for authZ/authN 1000+SEC Filings refer to mid-market focus with more repeatable project focus.
GeneralOtherIoT. Open Banking / PSD27 acquistions since 2016

Please contact us for any corrections of comments.

Categories:

Tags:

Signup for New Content Updates