ManageEngine ADSelfService Plus buyer's guide
You can click and start reading the chapters from below. We've also sent the
link to your inbox for future reference.
The world has quickly adopted the hybrid working model and moved on to cloud-based services, and it is great news for having a flexible work environment. However, this news also brings a host of password management hurdles and password security loopholes. These loopholes are also being exploited by threat actors, and the case isn't helped by the fact that may people still use weak and compromised passwords. Since passwords are the first line of defense against threat actors, an organization's security is only as strong as its weakest password. Thus, it is imperative for an organization to take its password security seriously.
Native password management tools are not capable of handling the demands of today's world. Today, we need more granular control, easier access to our services, and security hardening on a case by case basis. This is why organizations rely on password management and security solutions to take care of their passwords. These solutions help organizations not only harden their password security measures, but also allow for easy password management with functionalities such as remote password self-service and single sign-on for applications. These functionalities help an organization build a strong and hassle-free password framework.
ADSelfService Plus is an integrated self-service password management and single sign-on solution (SSO) for on-premises and cloud applications. It bolsters an organization's password framework with self-service password reset and account unlock, endpoint and VPN multi-factor authentication (MFA), SSO to enterprise applications, Active Directory (AD)-based multi-platform password synchronization, password expiration notification, and password policy enforcer.
Any organization that's serious about its password security should have its key processes implemented. Here's how ADSelfService Plus can help meet the demands of your organization:
You're on the lookout for: | How ADSelfService Plus can help: |
---|---|
Secure authentication |
Secure access to machine (Windows, macOS, and Linux OS), VPN, and OWA logins with MFA. Regulate enterprise application access via single sign-on (SSO) with advanced authenticators including biometrics, or RSA SecurID. |
Remote password self-service |
Enable users to perform self-service password reset (SSPR), and self-service account unlock only after they prove their identity via the enforced authenticators. Secure cached credential updates via VPN during remote password resets. |
Strong password policy enforcement |
Enforce strong user passwords by requiring special characters and blacklisting dictionary words and patterns. Prevent users from using previous passwords during password resets. |
With ADSelfService Plus, you can also implement the following five capabilities that Gartner considers as critical for an IAM framework.
ADSelfService Plus comes packed with functionalities that go beyond native capabilities. Here's a list of what the solution can do, and what you get with each functionality:
Enables users to reset their forgotten AD domain passwords and unlock their locked out accounts without admin intervention. Users can reset their password from:
MFA improves security through additional layers of identity verification along with the existing credential-based authentication. ADSelfService Plus implements additional identity verification steps for the following:
The product supports up to 18 authentication techniques including biometrics, Google Authenticator, Microsoft Authenticator, time-based one-time password (TOTP), and Security Questions and Answers.
Advanced password policy controls can be set for an organization in addition to the native domain and fine-grand password policies offered by AD. These advanced password policies can be used to set password controls that are not available in the native policies like:
ADSelfService Plus is available in three editions: Free, Standard, and Professional. Here's what you get with each edition:
Standard | Professional | Free (for up to 50 domain users) |
---|---|---|
Web-based Self-Service Password Reset and Account Unlock | Includes everything in the Standard edition, and: | Supports all functionalities in the Professional edition |
Password Expiry Notifier | Password Reset from Windows, macOS, and Linux login screens | Password Self-Service |
Password Policy Enforcer | MFA for Windows, macOS, and Linux machine logons | Directory Self-Service |
Real-time Password Synchronizer | MFA for VPN logons | Cloud Applications SSO & Password Sync |
Password Reset Using iOS and Android App as well as Mobile Browser | MFA for OWA logons | - |
Self-Service Directory Update, Employee Search, Organization Chart, and Mail Group Subscription | Cached Credentials Update for Remote Password Reset Password Policy | - |
- | Enforcement in Windows Change Password Screen and ADUC | - |
Starts at $595 for 500 domain users | Starts at $1195 for 500 domain users | - |
“Now users do not have to travel to the office to perform Active Directory Password Reset. Helpdesk calls related to password reset have been reduced by 100%.”
"Other options, were requiring a modification of the Active Directory schema, I liked that ADSelfService Plus did not. The ability to ‘brand’ the tool to our School was also important"
"The deployment is very simple, which makes it nearly fun. We didn’t find any other software which is that fast in deployment like ADSelfService Plus. The Instructions are clear and straight forward; the support is working great."
ADSelfService Plus's components There are four components that are required to run ADSelfService Plus, which are:
The server is where ADSelfService Plus is installed, and it can be a member server or a domain controller. In case you are configuring a high availability environment, you will need a primary server and a secondary server. Both servers need to have ADSelfService Plus installed.
To enable load balancing, a primary server and one or more secondary servers have to be configured. All the servers need to have ADSelfService Plus installed.
ADSelfService Plus uses a database to store information like Active Directory (AD) attribute details, audit data, product configuration data, enrollment data, etc. The product comes with a built-in PostgreSQL database. You can also use a standalone MS SQL database or PostgreSQL database.
AD forms the cornerstone of ADSelfService Plus. Scheduled synchronization of data between ADSelfService Plus and AD is necessary to allow the IT administrators to create various self-service policies and apply them to organizational units (OUs) and groups, install the login agent on domain computers, and configure various features and settings from within the product's portal. Synchronization with AD is also necessary for end users to perform the various self-service actions.
There are two kinds of ADSelfService Plus web portals:
Admin portal: The admin portal lets the IT administrator of the solution configure domain and connection settings (SSL, proxy server, etc.), create and apply various policies, deploy MFA, integrate on-premises and cloud applications with password sync and SSO, and do much more.
User portal: The user portal lets the users enroll themselves in ADSelfService Plus, perform the various self-service actions, search for employees, view the organization chart, etc.
The ADSelfService Plus mobile app lets domain users perform AD password resets and account unlocks using their mobile device. It enables users to enroll themselves for certain MFA methods. The mobile app is also used to receive push notifications for:
With the app, users can also authenticate themselves using a MFA method like time-based one-time-passcode, push notifications, fingerprint-based, and QR codes. The mobile app can be either manually installed by users or pushed to mobile devices by the IT administrator.
Resource | Description |
---|---|
Admin guide | A one-stop guide that covers everything administrators should know to set up and run ADSelfService Plus. |
User guide | A detailed explanation on getting started with ADSelfService Plus, and how to use the solution. |
Detailed architecture | An in-depth explanation of the components and deployment scenarios. |
Privileges and permissions requirement guide | An elaboration of all the necessary roles and permissions required for ADSelfService Plus. |
Email us: support@adselfserviceplus.com
Call us: +1 844 245 1108 (toll-free)
© 2021 Zoho Corporation Pvt. Ltd. All rights reserved.