The table below shows the differences for a service between the two authentication options. Note that both options can be used by an institution protecting it's services. For each service the most appropriate integration option can be chosen.

FeatureStandard authenticationSFO authenticaton
Authentication of first factorAlwaysNever, should be done by the service itself
Authentication of second factorYes, based on policy between IdP and SPAlways
User registrationUsing the SURFsecureID selfservice registration and optional vetting process
Standard SURFconext featuresAttributes, Authorization, persistent identifiersNone