Onboard to unphishable credentials without the help desk visit
EZCMS onboards your workforce to every phishing-resistant credential Entra ID supports, in under two minutes per user, without a trip to the IT help desk.
1,200+
Global organizations
trust Keytos
0
Account takeovers with unphishable credentials
92%
Reduction in password-related support costs
4x
Faster logins than password-based sign-in
Why choose EZCMS?
Passwords are the problem: over 6 billion credentials leaked in 2021, more than 60% of breaches came from stolen credentials, and password resets account for 20 to 50% of help desk calls. EZCMS gets your workforce off them.
Built for Entra ID + AD CS environments
EZCMS combines modern FIDO2 passkeys with traditional PIV smart card authentication to give your users a single security key that can work across cloud-only and hybrid environments.
Reduce onboarding time
EZCMS allows your users to quickly and securely onboard to FIDO2 passkeys and smart cards using biometric authentication from their own machine, without a trip to the IT help desk.
Easy hardware key distribution
EZCMS handles ordering and distribution logistics so your IT team can easily distribute security keys and smart cards to your global workforce.
Full visibility and audit logs
Security audits should not take your time away from securing your infrastructure. EZCMS logs every activity in the platform and can send those events to your SIEM.
Meets your compliance requirements
Governments have turned to smartcard authentication to protect against identity breaches, and the requirement is spreading to every organization. EZCMS meets both US Executive Order 14028 and CMMC identity requirements.
Works with your infrastructure
In PKI and identity there is no one size fits all. EZCMS can be hosted fully on-premises connecting to your existing PKI, or run as a fully managed cloud SaaS offering where our team of experts manage your instance.
Go passwordless in 3 steps
Most organizations deploy two or even all three methods. EZCMS onboards users to whichever ones you choose.
Choose your methods
Pick from Certificate Based Authentication (CBA), FIDO2 Passkeys, and phone authentication. Each has its own strengths, and you do not have to pick just one.
Deploy EZCMS
Stand up EZCMS against your Entra ID tenant and enable self-onboarding, so users can request and activate their own credentials without an IT ticket.
Users onboard themselves
A user proves who they are, receives their key, and activates it. Everything is logged, and the keys ship direct to the user.
Choose the right method
Multiple passwordless methods exist because not every user has the same needs. EZCMS gets you started with any of them, and most organizations deploy more than one. Learn how each compare.
FIDO2 Passkey authentication
FIDO2 replaces password-based login credentials with a quick and secure login experience. As a FIDO Alliance member, Keytos built the first ever self-service FIDO2 onboarding system for Entra ID.
-
The most secure method from the most secure identity provider
-
First self-service FIDO2 onboarding for Entra ID, so users enroll their own keys
-
Convenient in the cloud, with no certificate infrastructure to stand up
Certificate Based Authentication (CBA) smart cards
Smartcard implementation complexity was a barrier to entry that limited adoption to federal governments and their contractors. Entra CBA and EZCMS make it available to every Azure customer.
-
The oldest phishing-resistant method, used by governments for decades, so it is the most compatible
-
Works where FIDO2 does not, including legacy systems and ADAL based libraries
-
Fully in the cloud, without the server footprint smartcard onboarding used to need
FIDO2 + CBA smart card CBA on a single key
The best way to go passwordless is to have the best of both worlds. FIDO2 gives you convenience in cloud authentication; Entra CBA gives you compatibility with legacy systems and the places FIDO2 still is not supported.
-
One key, both credentials, so a user carries a single device
-
Cloud convenience plus legacy reach, including Android and ADAL based libraries
-
Onboarded in one flow, not two separate enrollment processes
Onboard to unphishable credentials in less than 2 minutes
Built by ex-Microsoft engineers, trusted by industry leaders
Start your passwordless journey
Transitioning to passwordless authentication does not have to be complicated. Our identity experts can guide you through every step.
Transparent pricing
View pricing detailsBasic
Self-service and IT desk onboarding for smartcards and FIDO2 keys
Premium
Most popular ✦Adds identity-proofed onboarding, bring your own CA, and SIEM export
Enterprise
Isolated infrastructure, on-premises deployment, and custom UI
Frequently asked questions
All of the phishing-resistant methods Entra ID supports: FIDO2 security keys, certificate based authentication with smartcards, and both on a single key. Multiple methods exist because not every user has the same needs, and most organizations end up deploying two or all three.
Yes. EZCMS supports YubiKeys for both FIDO2 passkeys and Entra ID Certificate Based Authentication (CBA). It can issue credentials for both so you can use a single YubiKey for multiple authentication methods.
Yes. EZCMS uses industry leading face recognition and Government ID scanning to validate a user's identity, so they can use their Government ID and biometric data to gain access to the corporate network. That removes the need for temporary access passes or a trip to the IT help desk.
Yes. EZCMS enables you to meet both the US Government Executive Order 14028 and CMMC (Cybersecurity Maturity Model Certification) identity requirements while improving your onboarding experience.
EZCMS does. Distributing keys to team members around the globe is one of the biggest hurdles in hardware key authentication, so EZCMS takes care of ordering and distribution logistics and leaves your IT team free to work on security.
Yes. In PKI and identity there is no one size fits all, so EZCMS can be hosted fully on-premises connecting to your existing PKI infrastructure, or run as a fully managed cloud SaaS offering where our team manages your instance.
Yes. EZCMS logs all activities in the platform, giving your team a full view of everything that happened in the portal. Those events can also be sent to your SIEM, giving your security team a centralized view.
EZCMS starts at $1 per user per month for Basic. Premium is $1.5 per user per month and adds bring your own CA support, Government ID and Face ID verification, and SIEM export. Enterprise pricing is custom.