Frequently Asked Questions About Keytos Shield All-In-One Passwordless Identity Management
What is Keytos Shield?
What is Keytos Shield and How Does It Help Me Go Passwordless?
Keytos Shield is a all-in-one solution for helping you go passwordless across all your workplace or school devices, applications, and networks. From issuing you ultra-secure certificates to getting you connected to your Wi-Fi using that password, Keytos Shield automates the manual processes and duct-tape that usually prevents or slows down typical passwordless rollouts.
What Is a Passwordless Identity?
Passwords are cumbersome, insecure, and outdated. For both users and devices, passwords (and connection strings) are a dated technology that lead to nearly all credential-related breaches and phishing attacks. It’s time for a change.
A passwordless identity is one that doesn’t require you to remember, copy, and rotate text-based passwords (what you know). Instead, you can use a variety of different factors that prove your identity without remembering something, such as a certificate within a smart card or YubiKey (what you have) or your fingerprint/face scan (who you are). You’ve probably used a passwordless identity if you’ve used FaceID on your phone or Windows Hello on your PC, or if you’ve ever used a Passkey on a website.
How Does Keytos Shield Manage Passwordless Identities?
Shield is a Software-as-a-Service (SaaS) solution that gives you a single pane of glass where you can configure, manage, and monitor your entire passwordless identity real-estate. From issued & revoked SCEP certificates to real-time network authentication monitoring, Shield gives you a single experience that usually requires multiple pieces of software and brittle integration points.
With Keytos Shield, you’re just a few clicks away from:
- A complete PKI environment with Root + SCEP Certificate Authorities
- A Cloud RADIUS service for Wi-Fi and network authentication
- Seamless integration with Microsoft Entra ID and Microsoft Intune to issue unique certificates to all your users and devices
- Deep MDM ecosystem support for Mobile Device Management platforms like Jamf, NinjaOne, and more
- BYOD Support for personal phones, laptops, tablets, and more with Keytos Connect.
- Only pay for the users who connect with no minimum costs or requirements
Does Keytos Shield Replace EZCA and EZRADIUS?
No. Keytos Shield is a SaaS solution that builds on top of the existing EZCA Cloud PKI and EZRADIUS Cloud RADIUS platforms that customers have trusted for years. Instead of needing to manually build your PKI environment in EZCA and connect it to an EZRADIUS policy, Keytos Shield sits on top and acts as an all-in-one platform with just a single experience. New and existing customers looking for platform-level PaaS capabilities can continue to use EZCA and EZRADIUS directly, or they can move to Keytos Shield at any time. Since it’s all the same services powering each solution, customers can get all the best features and support while choosing the model that best fits their needs.
Do I Need an EZCA or EZRADIUS Subscription to Use Keytos Shield?
No. Keytos Shield is a standalone SaaS solution and does not require an existing EZCA or EZRADIUS subscription to function. All necessary PKI and RADIUS capabilities are included within Keytos Shield itself.
Can I Migrate My Existing EZCA and EZRADIUS Subscriptions Into a Keytos Shield Subscription?
Not yet. Moving to Keytos Shield currently requires manually setting up your environment within Shield and reconfiguring your users, devices, and network. We are actively working on a streamlined migration process for future releases.
Does Keytos Shield Support Government Workloads?
Yes, Keytos Shield has full support for Azure Government Community Cloud (GCC High) which allows US federal, state, and local government to go passwordless in their existing GCC tenant.
Does Keytos Shield Have Soverign Regions For Data Residency?
Yes! Keytos Shield is available around with the world with dedicated EU and AU regions for full data residency.
How Does Keytos Shield Billing Work?
What is Keytos Shield’s Billing Model?
With Keytos Shield you pay for each user as part of a monthly or yearly subscription fee. There are no other subscription costs or minimums involved. Once a user is added to Keytos Shield, they can issue unlimited certificates and connect as much as they’d like to your network without any additional costs.
How Much Does It Cost To Sign Up For Keytos Shield?
There is no cost to sign up for Keytos Shield or minimum amount of seats/users. A Keytos Shield subscription is completely free and you only pay for the users that you add to your subscription. The underlying PKI environment which includes both Root and Issuing CAs are included in your subscription at no cost.
Can I Add or Remove Users To/From My Keytos Shield Subscription After Signing Up?
Yes, it’s easy to add or remove users from your Keytos Shield subscription as your business changes. Within Keytos Shield you can choose to either license all users in your tenant or you can configure groups of licensed users. You’re in control of who is licensed to use Keytos Shield.
How Can I Pay for Keytos Shield?
Keytos Shield supports a wide variety of flexible payment options including:
- Month-by-month via credit card. Simply create a subscription with us, add your credit card, and we’ll only charge you for your licensed users.
- Azure Marketplace. Directly bill your Keytos Shield subscription to your existing Azure subscription, with MACC eligibility so you can use your pre-committed Azure credits.
- Prepaid Invoice & Purchase Order. Pre-pay for your Keytos Shield usage with purchase order and invoice payments. Add additional users at any time when needed.
Can I Try Out Keytos Shield With a Free Trial?
Yes. Keytos Shield has a free 30-day, fully featured free trial, with no credit card required to sign up. Once you’re ready to move into a paid subscription you can seamlessly move into a paid subscription.
What Is The Minimum Time Commitment For a Keytos Shield Subscription
None! Keytos Shield subscriptions are fully month-to-month so you can cancel at any time. We don’t have any minimum time commitments, license requirements, or other ways to lock you in. We hope that Keytos Shield is a great option for your passwordless needs, but if it falls short you can cancel at any time.
Does Keytos Shield Offer Any Volume Discounts?
Not at this time. We strive to make Keytos Shield the most affordable and easy to use solution possible, and to do that we believe a low, monthly cost for everyone is the best way to offer that. We don’t offer any discounts for volume or time commitments to pressure you into buying today. We think our product should speak for itself and offer you the best possible value.
Does Keytos Shield Offer Education Discounts?
Not at this time. We strive to make Keytos Shield the most affordable and easy to use solution possible, and to do that we believe a low, monthly cost for everyone is the best way to offer that.
How Does Keytos Shield Cloud PKI Work?
What Certificate Authorities Are Created As Part of a Keytos Shield Subscription?
When you create a new Keytos Shield subscription two CAs are created for you:
- A Root CA for your organization which other issuing CAs chain up to.
- A SCEP CA for issuing user and device certificates.
Additional CAs may be added as part of future updates as we add additional features to Keytos Shield. Stay tuned for updates.
If you opt-into a hybrid CA environment at set up time, your PKI environment may be different that the default Root + SCEP configuration.
Can I Issue SSL Certificates As Part of Keytos Shield?
Keytos Shield does not support SSL Certificate and Domain management at this time. Please continue to use EZCA for your SSL certificate needs alongside Keytos Shield.
How Many Certificates Can I Issue in Keytos Shield?
There are no limits to the number of certificates you issue via Keytos Shield, within your subscription’s defined rate limits. Every Keytos Shield subscription can issue as many certificates as your environment requires, with no additional cost.
Does Keytos Shield Integrate With Microsoft Intune for Certificate Issuance?
Yes, Keytos Shield integrates directly with Microsoft Intune via Intune SCEP to issue certificates for your managed devices and users.
Does Keytos Shield Support SCEP Certificate Issuance?
Yes, in addition to direct Microsoft Intune support, Keytos Shield supports static and dynamic SCEP for integration with popular Mobile Device Management (MDM) solutions such as Jamf Pro, Jamf Now, NinjaOne, Iru, SimpleMDM, and more.
Does Keytos Shield Support Device ACME Support?
Yes, in addition to SCEP issuance, Keytos Shield supports device certificate issuance via device ACME. Many popular MDM platforms such as Jamf Pro support this as an alternative to static SCEP.
Note that this uses the device ACME attestation and challenge and is not the same as HTTP or DNS ACME for server SSL certificates, which Keytos Shield does not support at this time.
Can I Use Keytos Shield With Microsoft Cloud PKI?
Yes, although we have some different recommendations based on how you plan to use Microsoft Cloud PKI.
If you want to use the Keytos Shield provided PKI alongside your existing Microsoft Cloud PKI, where Intune devices get Cloud PKI certificates and Jamf/other devices get Keytos Shield certificates, we offer a way to run both PKIs side by side for Cloud RADIUS. Note that some features such as Keytos Connect BYOD support are not compatible with Microsoft Cloud PKI so you’ll need to use the built-in Keytos Shield PKI for those features.
If you plan to fully rely on Microsoft Cloud PKI, we recommend using EZRADIUS directly with Keytos Shield if you don’t plan to use the Keytos Shield provided cloud PKI. It will save you a bit on your bill and we have lots of great guides on how to integrate Microsoft Cloud PKI with EZRADIUS Cloud RADIUS.
Can I Chain Up To My Existing PKI and Certificate Authorities Instead of the Keytos Shield Provided Root?
Yes, as part of onboarding we’ll ask you about your existing PKI environment with steps for chaining up to your on-premises and existing PKI.
How Does Keytos Shield Cloud RADIUS Work?
What Regions Is Keytos Shield Cloud RADIUS Available In?
Keytos Shield runs in the exact same regions and countries that EZRADIUS operates in, including regions across the United States, Europe, Australia, Latin America, South Africa, US Government, and more. When creating a Keytos Shield subscription you can select the regions closest to you.
What Protocols Does Keytos Shield Cloud RADIUS Support?
Keytos Shield provides the same protocol support as EZRADIUS, including Classic RADIUS and RadSec for the transport protocols and EAP-TLS, EAP-TTLS, PEAP, MSCHAPv2, MAB, and PAP for the authentication protocols. This allows you to easily connect your managed and BYOD devices with certificates, legacy devices with local user accounts or MAC address bypass, or Entra ID username and passwords for devices without certificates. Your Keytos Shield network policies define what devices are allowed to connect.
Can I Run A Local Cloud RADIUS Server or Proxy?
Yes, the EZRADIUS local proxy is fully compatible with Keytos Shield which will allow you to run a RADIUS proxy from within your network for lower latency and redundancy. The local proxy does not depend on the cloud server and can operate on its own either during incidents in the cloud service or full internet disconnections using the onboard identity & certificate cache.
What Support and Availability Options Does Keytos Shield Offer?
How Can I Get Support For Keytos Shield?
Every Keytos Shield subscriptions comes with email, live chat, and ticket-based support included. Our team of engineers will get back to you as soon as we can within your subscription’s support SLA.
We recommend trying our live chat first, as it has a great AI assistant that’s trained on our documentation. But if you need to talk to a human at any time just say so and we’ll get you connected to a member of our engineering team as soon as we can.
Can I Get Deployment Assistance From The Keytos Team For My Deployment?
We recommend getting started using our documentation and video guides. We strive to make them the best possible solution for getting up and running in just a few minutes.
But if you need support along the way, you can always check out one of our support options for questions or issues with Keytos Shield.
For integration support where a Keytos Engineer can work one-on-one with you to integrate Shield into your environment and consult on your PKI and network authentication strategy, we also have Professional Services options available to schedule and purchase.
What SLAs Does Keytos Shield Provide?
Keytos Shield provides up to 99.95% availability for its cloud PKI and cloud RADIUS services. You can also achieve higher SLAs with local proxies running within your own network for High Availability scenarios.
How Do Keytos Shield Permissions Work?
How Does Keytos Shield Access My Entra ID Tenant?
Keytos Shield uses native Entra ID authentication to access your tenant via the Microsoft Graph APIs. When you sign up for Keytos Shield, you consent our Entra ID application to access your tenant with a least-privileged set of permissions necessary to provide the Keytos Shield services.
What Permissions Does Keytos Shield Require?
Keytos Shield requires only the minimum set of permissions necessary to perform its functions. These typically include permissions to read user and group information, manage authentication methods, and access directory data through the Microsoft Graph APIs.
When you consent the Keytos Shield application, there are actually 5 different application registrations that are created in your Entra ID tenant, each with its own set of permissions required to perform specific functions within Keytos Shield. Here is a summary of the key permissions for each registration:
Keytos Shield Client
The Keytos Shield Client application (Application ID 2963e596-88f5-43a1-ab17-68b8026c6468) is the frontend (client) of Keytos Shield, which users sign into when accessing the Keytos Shield services. It handles user authentication and interacts with the backend services to provide the necessary functionality.
| Description | Name | Type | Why is this needed? |
|---|---|---|---|
| Sign in and read user profile | User.Read |
Delegated | This permission allows Shield to read your basic profile information such as your name and email address to create your account in our system. |
| Read basic profile information | profile |
Delegated | This permission allows Shield to read your basic profile information such as your name and email address. |
| Read directory data | Directory.Read.All |
Delegated | This permission allows Shield to read information about your organization’s directory, such as users and groups, which is necessary for managing access to your domains and certificates. |
| Interact with EZCA | API.Access |
Delegated | This permission allows Shield to interact with the EZCA service for managing PKI. |
| Interact with Keytos (EZCA) | API.Access |
Delegated | This permission allows Shield to interact with the EZRADIUS service for configuring RADIUS policies. |
| Interact with Keytos Intune App | API.Access |
Delegated | This permission allows Shield to interact with the Keytos Intune App for managing Intune certificates and configuration |
Keytos Shield
The Keytos Shield application (Application ID 04ba5b42-89b9-441e-b6d6-4d04a4638418) is the backend (server) of Keytos Shield, which handles the core functionality, business logic, and interactions with various services such as EZRADIUS, EZCA, and the Keytos Intune App. It ensures secure communication between the client and the services, manages user data, and enforces security policies.
| Description | Name | Type | Why is this needed? |
|---|---|---|---|
| Read Entra ID directory data | Directory.Read.All |
Application | This permission allows the backend to read information about your organization’s directory, such as users and groups, for managing access and enforcing security policies. |
Keytos
The Keytos application (Application ID 68554b48-233f-42b4-9aa7-2eadca4d7727) is the back-end application that runs the EZCA services. It requires the following permissions:
| Description | Name | Type | Why is this needed? |
|---|---|---|---|
| Sign in and read user profile | Directory.Read.All |
Application | This permission allows EZCA to read information about your organization’s directory, such as users and groups. This is used to check group permissions for users when providing access to your domains and certificates. |
EZRADIUS
The EZRADIUS application (Application ID 5c0e7b30-d0aa-456a-befb-df8c75e8467b) is the back-end application that runs the EZRADIUS services. It requires the following permissions:
| Description | Name | Type | Why is this needed? |
|---|---|---|---|
| Read directory data | Directory.Read.All |
Application | This permission allows EZRADIUS to read information about your organization’s directory, such as users and groups. This is used to check group permissions for users when providing access to your RADIUS infrastructure. |
| Manage apps that this app creates or owns | Application.ReadWrite.OwnedBy |
Application | Allows EZRADIUS to rotate secrets for the EZRADIUS Entra application. Does not give access to any other applications in your tenant. |
| Read Microsoft Intune devices | DeviceManagementManagedDevices.Read.All |
Application | Allows EZRADIUS to read device information from Intune when checking device compliance or other device-based policies. |
Keytos Intune App
The Keytos Intune App application (Application ID 772a1d3b-bd96-4650-b4b8-9f05cbab50b5) is the back-end application that integrates with Microsoft Intune to manage device compliance and policies. It requires the following permissions:
| Description | Name | Type | Why is this needed? |
|---|---|---|---|
| PFX certificate management | pfx_cert_provider |
Application | Allows the Keytos Intune App to manage PFX certificates issued to Intune-managed devices. |
| SCEP challenge validation | scep_challenge_provider |
Application | Allows the Keytos Intune App to validate SCEP challenges when devices request certificates through Intune. |
| Read all applications | Application.Read.All |
Application | Allows the Keytos Intune App to read application registrations in your tenant. |
| Read and write Microsoft Intune device configuration | DeviceManagementConfiguration.ReadWrite.All |
Application | Allows the Keytos Intune App to read and write Intune device configuration profiles, such as SCEP and certificate profiles. |
| Read and write Microsoft Intune configuration | DeviceManagementServiceConfig.ReadWrite.All |
Application | Allows the Keytos Intune App to read and write Intune service configuration necessary for certificate issuance. |
| Sign in and read user profile | User.Read |
Delegated | This permission allows the Keytos Intune App to read your basic profile information such as your name and email address. |
Can I Manually Remove Permissions?
Permissions can be manually removed from your Entra ID Enterprise Application. However, doing so will break the associated functionality of the Keytos Shield services that rely on those permissions. If there are specific permissions you don’t plan to use, you can revoke permissions at your own risk. If you later need those permissions again, you will have to re-grant them to restore full functionality.
Who Runs Keytos Shield?
Who Runs Keytos Security and Keytos Shield?
Keytos Security was started by ex-Microsoft engineers who wanted to help organizations, governments, and schools go passwordless and become more secure. The team that built Keytos Shield helped write the book on passwordless identities and identity best practices at Microsoft, and ran cloud-scale PKI services. They took that mission and experience and built Keytos Security from the ground up as a 100% employee owned company that provides PKI and network security for enterprises, small businesses, universities, schools, and governments around the world.
What Companies Trust And Use Keytos Security?
We believe that every organization should have the freedom and privacy to divulge their security vendors only if they choose to do so. For that reason we don’t have any logo banners or listed customers on our website, and we don’t name any of our customers.
What we will say is that Keytos is trusted by thousands of organizations around the world and you probably use Keytos services in your daily life without even realizing it. If you ask around your network you’ll likely find someone using Keytos.