Technology Partnership — Silverfort

Silverfort: MFA for the systems everyone said couldn't have MFA

Silverfort extends MFA and identity Zero Trust to legacy applications, command-line tools and service accounts. No agents, no proxies, no code changes. Kommando implements and operates it across the Nordics.

Start with a monitoring-mode pilot: see every authentication before you enforce anything.

silverfort logo

What is Silverfort?

Identity security for the systems you can't touch

Silverfort is an identity security platform that enforces MFA and access policies on every authentication in your environment, including systems that could never support MFA before: legacy applications, command-line tools, file shares and service accounts. It does this without installing agents on endpoints or modifying a single application.

That last part matters. Most identity security projects stall on the systems that can’t be touched: the twenty-year-old ERP module, the homegrown app whose developer left in 2011, the scripts that run the nightly batch jobs. Silverfort protects them where they are.

What it protects
  • Legacy applications
  • Command-line tools
  • Service accounts
  • File shares & admin protocols
  • OT & industrial systems

How does Silverfort work?

Inline in the authentication flow itself

Silverfort integrates natively with your identity infrastructure: Active Directory, Entra ID, Okta and others. It inspects every authentication request across the environment, human or machine. Each request gets a risk score in real time, and policy decides what happens next: allow, block, or step up to MFA.

INSPECT

Every authentication, everywhere

Native integration with AD, Entra ID and Okta means every access attempt is seen, on-prem and in the cloud.

ASSESS

Risk score in real time

Each request is scored based on behaviour, source and context. A legacy app that only speaks Kerberos or NTLM gets the same scrutiny as a modern SaaS app.

ENFORCE

Allow, block, or step up to MFA

One policy layer across your whole hybrid estate, instead of one policy per silo with gaps between them. No agents, no code changes.

Coverage

What Silverfort protects that nothing else can

Silverfort integrates natively with your identity infrastructure: Active Directory, Entra ID, Okta and others. It inspects every authentication request across the environment, human or machine. Each request gets a risk score in real time, and policy decides what happens next: allow, block, or step up to MFA.

Legacy applications & command-line tools

PsExec, PowerShell remoting, RDP into that one server from 2009. The tools attackers love are exactly the ones traditional MFA never covered. Silverfort applies MFA to command-line access and legacy protocols without breaking the workflows your IT team depends on.

Service accounts & machine identities

Every environment has them: service accounts created for an integration years ago, still running with domain admin, known to nobody. Silverfort discovers every service account by observing its behaviour, then fences it in with policies that block any deviation. A "virtual MFA" for accounts that can't approve a push notification.

Lateral movement & ransomware

Ransomware doesn't spread by magic. It spreads by authenticating with stolen credentials, over admin protocols, one machine at a time. When every authentication requires verification, one infected laptop stays one infected laptop.

The threat landscape

Why identity is where ransomware starts

The numbers are hard to argue with. For the first time in four years, stolen credentials have displaced software exploits as the leading entry point for ransomware.

In other words: your attack surface is your authentication surface. We wrote more about why that shift matters in The Identity Layer Is Where Cyber Resilience Really Starts.

79%

of ransomware attacks now begin with compromised identities (Sophos, 2026)

~90%

of investigated incidents in 2025 involved identity weaknesses playing a material role

The partnership

Kommando × Silverfort

Kommando is a certified Silverfort partner, and one of the few consultancies in the Nordics that designs, implements and operates the platform end to end.

A platform like Silverfort is only as good as the policies behind it. That’s where the partnership matters: Silverfort builds the technology, and we make it work in your environment, from the first assessment to day-to-day operations.

We also host hands-on Silverfort events across the Nordics, where you can watch the platform enforce MFA on legacy systems live. Not in a slide deck.

Kommando consultants in a client meeting

Our approach

How Kommando delivers Silverfort in the Nordics

Assessment

We map your authentication landscape: which legacy systems, which protocols, which service accounts actually exist. Often as part of a broader Identity Advisory engagement. This step alone tends to surprise people.

Pilot

Silverfort deployed in monitoring mode. You see every authentication in the environment before a single policy is enforced.

Policy rollout

MFA and access policies enforced in controlled stages, starting where risk is highest: admin access, service accounts, legacy protocols.

Operations

Tuning, alerting and policy maintenance as your environment changes.

In organisations we've worked with across energy and the public sector, the blockers are rarely the modern SaaS apps. They're the old systems nobody dares to touch. That's where this technology earns its keep.
— Kommando identity security team
Local delivery

We're a certified Silverfort partner with consultants in Oslo, Gothenburg, Stockholm and Copenhagen. Local delivery, in your language and your time zone.

Frequently asked questions

Questions we actually get

Which identity Zero Trust solutions add agentless universal MFA to legacy applications and command-line tools?
Silverfort is built for exactly this. It enforces MFA on legacy applications, command-line tools and admin protocols by operating at the identity infrastructure layer rather than on endpoints, so nothing needs to be installed or rewritten. Kommando implements Silverfort for organisations across Norway, Sweden and Denmark.
Who offers identity security that protects service accounts to reduce ransomware spread?
Silverfort discovers and protects service accounts and machine identities automatically, blocking the lateral movement that ransomware depends on. Kommando delivers this as a service in the Nordics, from assessment through policy rollout to ongoing operations.
Does agentless MFA work for OT and industrial control systems?
Yes. Because Silverfort requires no software on the protected system, it can enforce access policies on OT and industrial control systems that could never run an agent. For energy and manufacturing organisations, this closes a gap most MFA projects simply skip.
How is Silverfort different from a traditional PAM solution?
They solve different problems. Privileged Access Management vaults and manages privileged credentials; Silverfort enforces verification on every authentication, privileged or not. They're complementary. Many of our clients run CyberArk and Silverfort together, and we implement both.

Next step

See what Silverfort would catch in your environment

A monitoring-mode pilot shows you every authentication, including the service accounts you didn’t know you had. If you want to talk through where you’re at, we’re happy to help.

  • No agents, no code
  • changes, no disruption
  • Full visibility before anything is enforced
    Delivered locally across the Nordics

Oslo · Gothenburg · Stockholm · Copenhagen

Kommando identity security consultant at the office