Product Settings

You can change the following settings of ManageEngine AD360 from this tab.

  1. Connection Type
  2. Privacy Settings
  3. General
  4. Security Hardening
  5. Product File Tamper Detection

Connection Type

Privacy Settings

By default, AD360 secures your database backups with a strong, random password. If required, you can change the password for subsequent database backups by entering the new password in the Change Password for Database Backup Files field. Ensure that the new password is at least 8 characters long.

Note: If you forget the password that you have entered, the backup files created with that password cannot be restored. You will have to set a new password before taking the backups.

General

Security Hardening

This option allows you to configure and manage all product security settings in one place. A dashboard on the right side of the page displays a security score (as a percentage), which is calculated based on the importance of each configuration. Apart from this dashboard, the security settings alert will be shown under the browser and product notification centers, product License tab, and it will also be emailed to you along with product downtime and start-up mailers.

Product Settings

The security settings alert will be displayed in the notification center (which is the icon on the top-right corner) until a security score of 100% is reached. For licensed customers, the alert will also be displayed after every successful login until all the mandatory* security configurations are done. The security configurations available in AD360 are listed below.

  1. Enforce HTTPS*: This setting helps establish a secure connection between the web browsers you use to access AD360 and the AD360 server.
  2. Change Default Admin's Password*: Use this setting to change the default admin's password.
  3. Receive Alerts On Security Updates *: Configuring this setting allows you to receive email notifications regarding released security patches. This ensures that you are well-informed about any security updates for the product, enabling you to update it as soon as possible.
  4. Enable Reverse Proxy: With this setting, you can enable connection with a reverse proxy server in order to secure the identity of the AD360 server.
  5. Enable Auto Update: This setting enables the product to be updated to the recent build automatically. This ensures that you do not miss out on important patches and new features.
  6. Enforce Two-Factor Authentication*: Use this setting to add an extra layer of security while logging in to AD360. Choose from the set of authentication options available, like email verification, SMS verification, Google Authentication, Duo Security, and more.
  7. Enforce Secure TLS: While using Transport Layer Security (TLS), this setting checks if the older versions of TLS are disabled. AD360 supports TLS versions 1.0, 1.1, and 1.2.
  8. Enforce LDAP SSL: This setting enforces an SSL connection between the AD360 server and Active Directory domains configured in the product.
  9. Enable CAPTCHA: You can add a CAPTCHA to the login page using this setting. Users will be prompted to enter a CAPTCHA after a specific number of failed login attempts.
  10. Block Invalid Login Attempts: This setting allows you to block a particular user after a specific number of failed login attempts by the user.
  11. Enable Product File Tamper Detection: This setting monitors the executable files and identifies the tampered files in the AD360 installation directory.

Product Settings

*These settings are mandatory for AD360. However, it is recommended to configure all settings to ensure your Product Security Hardening score reaches 100%. To manage individual settings, click the Configure option corresponding to that security setting and make the required changes. Once configured, the setting will have a green ticked Configured icon next to it, as shown in the image above.

Product File Tamper Detection

The Product File Tamper Detection feature examines the executable files (.exe, .bat, .msi, .dll, and .rll) in the AD360 installation directory to detect the changes made to them. It validates the files using a checksum to ensure data security. If a file in the installation directory is found to be tampered with, an alert will be displayed after every successful product login.

Note:
  • PostgreSQL and JRE folders are excluded from scanning, as the external files will replace the product default files during externalization.
  • Patch folder is excluded from scanning as it contains modified files of the previous version.

The Product File Tamper Detection feature facilitates:

  1. Scanning the installation directory
  2. Classification of files
  3. Action to be performed when the file is tampered with

Product Settings

Scanning the installation directory

The files in the installation directory can be scanned in the following ways:

Classification of files

The files are listed under these categories:

Total Files: Total Files displays all the files that are found in the product installation directory, including the tampered files.

Files Monitored: Files Monitored displays the files with whitelisted extensions, where the current checksum matches the expected checksum after scanning them.

Tampered Files: Tampered Files displays the list of executable files that have been modified, i.e., the current checksum is not the same as the expected checksum.

New Files: New Files scans and shows files that are not a part of the application bundle but have the allowlisted extensions. These new files can be included in future scanning processes or can be restricted from being executed.

Product Settings

Action to be performed when the file is tampered with

Don't see what you're looking for?

  •  

    Visit our community

    Post your questions in the forum.

     
  •  

    Request additional resources

    Send us your requirements.

     
  •  

    Need implementation assistance?

    Try onboarding

     

Copyright © 2023, ZOHO Corp. All Rights Reserved.