Authentication as a Service (AaaS): Creating A New Revenue Stream with AuthAnvil
SaaS, PaaS, IaaS Powered by advancements in cloud technology, the X as a Service model has become exceptionally popular among vendors looking for new sources of recurring revenue and businesses attracted by the convenience of services they don t have to host at their own locations. Here s another acronym: AaaS. It stands for Authentication as a Service. By that, we mean delivering authentication services like two-factor authentication, single sign-on and password management remotely from the cloud. Authentication as a Service allows businesses to track their password usage, enforce strict password requirements, and provide their employees with an efficient and secure way to log into their many applications and web services. Because AuthAnvil is accessed as a cloud application, businesses are not hit with the upfront cost of setting up a server and software onsite. They also don t have to manage the continual hassle of maintaining a server. This guide is for managed service providers (MSPs) that use or are considering using the AuthAnvil password management system. It explains why and how to use AuthAnvil s multi-tenancy capabilities to not only manage your business s own passwords, but to provide similar services to your IT clients all without installing separate instances of AuthAnvil or setting up additional servers. Authentication as a Service (AaaS): delivering strong authentication services through a cloud environment
Why Your Clients Want AaaS Most businesses recognize the pains associated with authentication. As companies increasingly rely on online services and password protected applications, the struggle to maintain password security without overburdening employees or risking noncompliance with data security regulations like PCI DSS or HIPAA is becoming more and more difficult. 7 reasons IT hates passwords: 1 Unless they look like 0x25CVi5(i7<9qk, they re probably not as secure as they need to be. Your clients want secure and reliable solutions for all of these problems just as you did when you installed AuthAnvil for your own business. But your clients are hesitant to invest in onsite servers and software. IT in general is moving toward the cloud, so your clients are understandably trying to avoid building out their on-premises infrastructure any more than is necessary. Paying your company to provide these services is both easier for your clients and lower risk. It s an instant-on, instant off solution. They can try it without any significant upfront costs. There are, of course, large-scale providers of cloud-based authentication services your clients might consider, but those options represent an increased risk. Besides the fact that your clients have a prior relationship with your business and trust you, large-scale authentication as a service providers are more prone to attack because of their higher profile. They are built for general users, not the specific needs (including compliance) of specific businesses. When you offer AaaS to your clients with AuthAnvil you re also offering them the assurance of knowing where their data is and who is in control of it. Why You Would Want to Offer AaaS For MSPs, the promise of AaaS is the promise of a new revenue stream offering services your competitors don t offer. Consider AaaS as an opportunity to increase your footprint and create customer stickiness, reducing the likelihood When end users get used to your clients will jump ship for another MSP. When end the remarkable simplicity users get used to the remarkable simplicity of a tool like AuthAnvil, it s hard to go back to the dark ages of of a tool like AuthAnvil, it s password security. For this reason, our partners have found hard to go back to the dark that deploying AuthAnvil for their current customer base ages of password security. not only increases their monthly recurring revenue, but increases their customer loyalty. 2 3 4 5 6 7 People will reuse the same passwords ( 123456, anyone?) across multiple businesscritical resources. Employees write them down on sticky notes. Enforcing password policies is a nightmare. People share passwords with co-workers. Employees practicing bad password security put the company at risk of falling out of compliance with regulations Most of all, it s simply not realistic to expect employees to use a unique and extraordinarily complex password for each resource they access unless you are using password management software. 3 Scorpion Software
Partner Testimonial We were looking for a easy to implement and support two factor authentication system, we searched the usual suspects and finally settled on Scorpion Software. We liked their approach and the model they run, as a small MSP ourselves it allowed us the flexibility to spend as we grow, which we believed was essential in allowing us to scale and increase our recurring revenue model. - Michael O Neill, CMI If you are prepared to make the investment in the infrastructure (usually cloud-based, as we ll discuss later in this guide), you ll find that AuthAnvil is the ideal tool for authentication as a service. It s easy to set up on a cloud service like Microsoft Azure or Amazon Web Services. It s scalable and easy to add and remove clients. When considering offering authentication as service, you do have to think about your client base. Certain verticals, for instance, are wary of the cloud due to compliance and security concerns. There are also some organizations that are subject to government legislation about where data can be stored. But you know your customers best. If you feel like they might be a good fit for authentication as a service, read on to learn how to set up AuthAnvil for AaaS. AaaS With AuthAnvil The best reason to use AuthAnvil for AaaS is its multi-tenancy capability. Multi-tenancy just means that a single AuthAnvil installation (a single site on a single server) can be subdivided, with each subdivision hosting a different client. This multi-tenant arrangement provides many significant benefits: Your customers (and your own) infrastructure are hosted on the same system but are completely walled off from each other. You have a central point for managing data a single point for upgrading, a single point for maintenance and troubleshooting. This makes it much easier, cheaper, and less time-consuming to manage than overseeing multiple applications and multiple servers. You have a centralized point of deployment. You don t have to install additional instances of AuthAnvil or set up additional servers for new customers. With AuthAnvil s multi-tenancy capability, each of your customers will have their own web address with your domain. This provides an easy way to access each of your customers sites without having to select from a drop-down list. The Authentication Capabilities of AuthAnvil If you re already using AuthAnvil, you already know this, but if you re new to AuthAnvil, here is a breakdown of the authentication services AuthAnvil will allow you to provide your customers: Multi-Factor (Two-Factor) Authentication. Multi-factor authentication both strengthens security with credentials that are virtually impossible to steal and makes life easier on employees by not requiring them to remember extremely complex passwords. AuthAnvil provides two-factor authentication with a one-time use password generated by a SoftToken on a user s smartphone, desktop, USB-based YubiKey, or hardware keyfob. 4 Scorpion Software
Password Management. AuthAnvil gives companies a central location to organize and control all the credentials all their employees work with. It gives administrators fine-grained control over who has access to credentials and what they can do with them. It also serves as a centralized source of information for reporting on how and when credentials are used. Single Sign-On. This convenient feature of AuthAnvil gives users the ability to access all the applications, websites, and cloud services they need with a single login through a customized, web-based dashboard. Combined with the security of two-factor authentication, single sign-on not only reduces the need to remember passwords, but it increases employee efficiency and allows for smoother workflows. Working with AuthAnvil Scorpion Software, the creator of AuthAnvil, operates on a partner-only model. That means we only sell our product through MSPs and IT providers like you. You will not find yourself competing with us to provide services to the same customers. At Scorpion Software, we have developed a strong partner program for IT service providers and MSPs. Here are some of the key benefits that we offer: First and foremost, we only sell through our partners. That means if a potential buyer of AuthAnvil ever finds us (and they do), our partners will have nothing to worry about. We don t market to them; we don t sell to them. Your customers are your customers. We push business your way. Any leads we receive from end users are passed on to our partners. Setting up new customers is easy when you follow our best practices for setting up AuthAnvil on your servers. You simply need to add a new segment to your server to allow for a new tenant, import current passwords for the new customer, apply role based access controls, deploy tokens, and boom: you have new revenue coming through the door.
Partner Testimonial For a partnership program, Scorpion Software checked all the boxes for us. Great product with continued development, ability to manage multiple accounts from a single console and access to the Scorpion team for large deals and development ideas. - Paul Cissel, Internet and Telephone Tedious tasks are automated with PowerShell. Pretty much every single function of AuthAnvil is exposed in a web service call, which means it is available in our PowerShell module as a cmdlet. Using our PowerShell module, you can programmatically perform tasks such as importing passwords, building password vaults and role permissions en masse, and resync user tokens. All this means that your life is made easier. We utilize home realm discovery. Home realm discovery provides a seamless experience for your customers. Instead of needing to login through our website, they login through a custom subdomain: clientname.mspname.com. We offer generous margins and volume discounting. In addition, we don t publish pricing on our site, allowing you to price at whatever level you can resell AuthAnvil at. To add some icing on the cake, as you add more users, your cost-per-seat goes down. SETTING UP AUTHANVIL FOR AAAS You can host authentication services for your clients using AuthAnvil from your own location, but we recommend you set it up on a cloud server. Here s why: Deploying a cloud server environment usually has a low upfront investment, whereas buying new servers for an on-premises solution can quickly create a huge bill. The cloud will allow you to expand your services quickly without investing in additional hardware. Adding additional resources in the cloud is usually a trivial matter of paying your cloud services provider a bit more. When expanding an on-premises solution, there is often a large portion of time when your new resources are under-utilized. Since you expand a cloud server when you need it, you are often efficiently utilizing your available technology. Many cloud providers will often have built in redundancy and server configs that allow for failover. Most cloud providers, including Microsoft Azure, are automatically configured in high-availability clustering mode, which typically comes with high licensing and servers costs in an on-premises solution. Assuming you re locating your services in the cloud, here s what you ll need: A SQL cluster in the cloud. Two Windows Server instances that are load balanced. This configuration is supported by some of the most popular cloud services providers: Windows Azure, Amazon Web Services, Rackspace, and so on. 6 Scorpion Software
Once you have your server environment up in the cloud or on-premises, you should set up AuthAnvil using the following steps. 1. Take a password inventory Take a password inventory of all the passwords you utilize: from windows admin credentials to network devices. Click here for a list of 23 common types of passwords to account for and a free password inventory worksheet. 2. Classify your passwords Classify passwords based on the principle of least privilege. That means your end users shouldn t get the same password access as your admins or external vendors. This is the process of creating roles which are fundamental to employing role-based access controls. 3. Implement your password server Once you have your passwords classified and your roles created, it s now time to set that up within the server. Here s the gist of it: Organize your password into groups based on access classification and policy/complexity. Store those groupings of passwords into a vaults. For example, you may have a network resources vault which has the passwords for routers, firewalls, wireless access points, printers/scanners, etc. All of these vaults are organized into Scopes. Scopes allow you to keep users contained within their more narrow scope of vaults. So, your technicians can t see your finance and HR scopes, and your marketing team doesn t see the scopes that were created for managing your network. Likewise, each of your clients should have their own scope. When your clients are set up on their own scopes, it ensures that they are unable to see the other scopes of your other clients. These Scopes are then organized by Orgs (hey, that s you!). That means all of your client scopes are organized under your Org. Users are then assigned to the roles you created earlier, and those roles are assigned access to scopes and vaults based on their needs, which means they get access to all of those passwords stored within those vaults and scopes. Easy, right? When you set your AuthAnvil up in this way, it s super easy to add new customers. In many cases, you can often duplicate scopes for current clients since many of those user roles and vaults are the same: two different healthcare IT clients will have similar user permission needs, and most clients will need the network admin role. Using our PowerShell scripts that automate the building of the Scopes and Vaults, this process is even faster. 7 Scorpion Software
Migrating to the Cloud If you are already using AuthAnvil at your business and need help migrating to the cloud so you can provide authentication services to your clients, we can help. Scorpion Software provides migration assistance and training to its partners, as well as PowerShell scripts that can be custom-built through a professional services engagement to meet your or your end users unique needs. This includes a behind the scenes script that gives AuthAnvil the ability to add multiple sites to a single installation. NEXT STEPS Are you ready to increase your monthly revenue from your current customers, while also increasing long-term loyalty? Being an AuthAnvil partner is the solution for you. Click below to get an idea of our pricing and to indicate your interest to our team.