Technology Partnership — Silverfort
Silverfort: MFA for the systems everyone said couldn't have MFA
Silverfort extends MFA and identity Zero Trust to legacy applications, command-line tools and service accounts. No agents, no proxies, no code changes. Kommando implements and operates it across the Nordics.
Start with a monitoring-mode pilot: see every authentication before you enforce anything.
What is Silverfort?
Identity security for the systems you can't touch
Silverfort is an identity security platform that enforces MFA and access policies on every authentication in your environment, including systems that could never support MFA before: legacy applications, command-line tools, file shares and service accounts. It does this without installing agents on endpoints or modifying a single application.
That last part matters. Most identity security projects stall on the systems that can’t be touched: the twenty-year-old ERP module, the homegrown app whose developer left in 2011, the scripts that run the nightly batch jobs. Silverfort protects them where they are.
- Legacy applications
- Command-line tools
- Service accounts
- File shares & admin protocols
- OT & industrial systems
How does Silverfort work?
Inline in the authentication flow itself
Silverfort integrates natively with your identity infrastructure: Active Directory, Entra ID, Okta and others. It inspects every authentication request across the environment, human or machine. Each request gets a risk score in real time, and policy decides what happens next: allow, block, or step up to MFA.
Every authentication, everywhere
Native integration with AD, Entra ID and Okta means every access attempt is seen, on-prem and in the cloud.
Risk score in real time
Each request is scored based on behaviour, source and context. A legacy app that only speaks Kerberos or NTLM gets the same scrutiny as a modern SaaS app.
Allow, block, or step up to MFA
One policy layer across your whole hybrid estate, instead of one policy per silo with gaps between them. No agents, no code changes.
Coverage
What Silverfort protects that nothing else can
Silverfort integrates natively with your identity infrastructure: Active Directory, Entra ID, Okta and others. It inspects every authentication request across the environment, human or machine. Each request gets a risk score in real time, and policy decides what happens next: allow, block, or step up to MFA.
Legacy applications & command-line tools
PsExec, PowerShell remoting, RDP into that one server from 2009. The tools attackers love are exactly the ones traditional MFA never covered. Silverfort applies MFA to command-line access and legacy protocols without breaking the workflows your IT team depends on.
Service accounts & machine identities
Every environment has them: service accounts created for an integration years ago, still running with domain admin, known to nobody. Silverfort discovers every service account by observing its behaviour, then fences it in with policies that block any deviation. A "virtual MFA" for accounts that can't approve a push notification.
Lateral movement & ransomware
Ransomware doesn't spread by magic. It spreads by authenticating with stolen credentials, over admin protocols, one machine at a time. When every authentication requires verification, one infected laptop stays one infected laptop.
The threat landscape
Why identity is where ransomware starts
The numbers are hard to argue with. For the first time in four years, stolen credentials have displaced software exploits as the leading entry point for ransomware.
In other words: your attack surface is your authentication surface. We wrote more about why that shift matters in The Identity Layer Is Where Cyber Resilience Really Starts.
of ransomware attacks now begin with compromised identities (Sophos, 2026)
of investigated incidents in 2025 involved identity weaknesses playing a material role
The partnership
Kommando × Silverfort
Kommando is a certified Silverfort partner, and one of the few consultancies in the Nordics that designs, implements and operates the platform end to end.
A platform like Silverfort is only as good as the policies behind it. That’s where the partnership matters: Silverfort builds the technology, and we make it work in your environment, from the first assessment to day-to-day operations.
We also host hands-on Silverfort events across the Nordics, where you can watch the platform enforce MFA on legacy systems live. Not in a slide deck.
Our approach
How Kommando delivers Silverfort in the Nordics
Assessment
We map your authentication landscape: which legacy systems, which protocols, which service accounts actually exist. Often as part of a broader Identity Advisory engagement. This step alone tends to surprise people.
Pilot
Silverfort deployed in monitoring mode. You see every authentication in the environment before a single policy is enforced.
Policy rollout
MFA and access policies enforced in controlled stages, starting where risk is highest: admin access, service accounts, legacy protocols.
Operations
Tuning, alerting and policy maintenance as your environment changes.
In organisations we've worked with across energy and the public sector, the blockers are rarely the modern SaaS apps. They're the old systems nobody dares to touch. That's where this technology earns its keep.
We're a certified Silverfort partner with consultants in Oslo, Gothenburg, Stockholm and Copenhagen. Local delivery, in your language and your time zone.
Frequently asked questions
Questions we actually get
Which identity Zero Trust solutions add agentless universal MFA to legacy applications and command-line tools?
Who offers identity security that protects service accounts to reduce ransomware spread?
Does agentless MFA work for OT and industrial control systems?
How is Silverfort different from a traditional PAM solution?
Next step
See what Silverfort would catch in your environment
A monitoring-mode pilot shows you every authentication, including the service accounts you didn’t know you had. If you want to talk through where you’re at, we’re happy to help.
- No agents, no code
- changes, no disruption
- Full visibility before anything is enforced
Delivered locally across the Nordics
Oslo · Gothenburg · Stockholm · Copenhagen