- Related Products
- ADAudit Plus
- ADSelfService Plus
- EventLog Analyzer
- Exchange Reporter Plus
- AD360
- Log360
This document provides the steps to improve the security of your ADManager Plus instance for specific scenarios mentioned below.
By default, ADManager Plus will be installed in the C:\ProgramFiles\ManageEngine folder. Starting with the 7210 release, the Authenticated Users group will no longer have access to the installation directory, and only users in the SYSTEM, Administrators, Domain Admins groups, and the user account linked during installation will have default access.
For prior builds, even users without administrative privileges who were part of the Authenticated Users group were given Full Control permission to access files in the installation directory in a few cases. To remove the Authenticated Users group from the Access Control List (ACL) on ADManager Plus, follow these instructions.
There are two ways to tackle this problem. You can either manually modify the permission settings or, use the SecureDeployment.exe file which will automatically modify the settings.
The SecureDeployment.exe file in the bin directory will automatically:
The SecureDeployment.exe file will ensure that the deployment environment is secured.
a. Steps to perform if ADManager Plus is installed in a folder other than Program Files:
i. If ADManager Plus is installed in a client OS
ii. If ADManager Plus is installed in a server OS
By default, the client OS C: directory has Authenticated Users with Modify permission for subfolders. However, the C: directory in the server OS does not have Authenticated Users in the ACL.
i) If ADManager Plus is installed in a client OS
To allow users with less privileges to start or stop ADManager Plus on the client OS, follow the steps:
ii) If ADManager Plus is installed in a server OS
b. Steps to perform if ADManager Plus is installed in C:\Program Files folder
ADManager Plus' Employee Search can be used by users or employees to look up the details of fellow employees and contacts of their organization.
Description: The Employee Search is one of the popular features of ADManager Plus and is used as a Corporate Directory Search, and it is enabled by default. However, to suit the specific needs of your organization, or for security reasons, you might want to display only specific details, of users and contacts in the search result, or might even prefer not to have this option at all.
Based on the need, you can easily:
Mentioned below are the steps:
If ADManager Plus' default admin password is not changed, there are chances that anyone who is aware of the default password might use it log in to the product, and perform malicious changes in your Active Directory (AD) or view information about AD objects.
We recommend that you change the default admin password, at least before you move to the deployment phase from the evaluation phase, for security reasons. You can change the default password in the 'My Account' section found in the top right corner of the product's web-console.
Click here for steps to change the default admin password.
ADManager Plus supports smart card, two-factor authentication (TFA), CAPTCHA, etc. and also allows you to block users in case of bad passwords, to enhance the security for user logon process and prevent unauthorized users from logging in. Click the links below for steps to configure the various options to secure the logon process for your users.
ADManager Plus offers a series of security and data privacy options to improve your management and reporting experience, secure access to the product, secure data disposal, and more. To learn how to configure the security and privacy settings in ADManager Plus, click here.