TACACS+ Server Evaluation: 12 Criteria to Compare Before You Choose
Choosing a TACACS+ server rarely comes down to a feature-count contest. In this Alepo blog, Vishal Mathur argues that three criteria decide most evaluations: how granular command authorization is, whether the server works across every device platform in your estate, and whether there is a supported migration path from whatever you run today. Before comparing vendors, the article asks operators to settle three questions: how many devices need authentication and how many sit outside the primary region; how many distinct administrative roles the organisation really has (usually four to eight); and what legacy system is being replaced and what it contains. The checklist itself covers twelve criteria, each with a weight and a way to verify it: standards conformance and a dated RFC 9887 (TACACS+ over TLS 1.3) roadmap; command authorization granularity; identity store and MFA integration; multi-realm and tenant isolation; device interoperability; accounting depth, retention and qu...