Wednesday, October 5, 2011

Identity Management Metrics

A recent article in PC WORLD, identified ten important metrics that are critical to success if any IDM project. I would like to take a look at a few of these items and expound upon how Tools4ever can provide software and services to provide a clear and concise implementation that will lead to a quick ROI.

Monthly Password Reset Volume – The article points to this as an indicator of password policy effectiveness. Too few resets requests might mean users are using simple passwords or writing them down on sticky notes. Too many requests could indicate the complexity standards are very stringent and users are having difficulty remembering their passwords

    Solution – Self Service Reset Password Manager (SSRPM) – allows companies to enforce complex passwords without inundating the help desk with user reset or unlock requests. The product can be deployed in an average organization in less than one day and the ROI is typically a few months.

Number of Credentials per User – A recent Tools4ever survey uncovered the average user has 10-12 separate, distinct sets of credentials and the article reiterated this fact. Once again, the large number of credential can lead to a large number of calls to the help desk and sticky notes with user name and passwords on the monitor.
    Solution – Enterprise Single Sign On Manager (E-SSOM) from Tools4ever provides a cost efficient method to reduce he number of credentials to one – the AD username and password. This product is easily deployed by Tools4ever consultants in a few hours to a few days – depending on the number of applications. Two factor or strong authentication via biometrics or smart cards eliminated the normal security concerns with SSO implementations.


Average time to provision or de-provision a User - No one wants a new employee to sit idly for days waiting on network and email access. Even worse, a terminated employee should not have access to anything once they have left the building. Too often the information flow from HR to IT is slow or non-existent in both of these scenarios leading to a loss of productivity or a potential security breach.
    Solution – User Management Resource Administrator (UMRA) allows companies to implement a closed loop process that encompasses creation, modification and deletion of user accounts. A common scenario is to synchronize Active Directory with the authoritative data source, typically the HR system, to insure the correct account status and security rights are always present. We forms are easily deployed to handle non-employees such as consultants, volunteers and contractors.


The article has many other great discussion topics and is a quick, informative read.

To learn more about Toosl4ever solutions for Identity and Password Management, please visit our website.

Wednesday, September 21, 2011

Getting Started with IDM

One of the questions often encountered when an organization decides to start an Identify Management project is “where do we start?” Undoubtedly, when looked at as a whole, the task can be daunting if not completely overwhelming. What is the source of data, how do we define roles, dozens of applications to interface with and the list goes on.

The approach we recommend is to start small – replace the manual, paper intensive process that is currently in place with a more automated, web based solution. Most organizations have a new hire form that has basic information – department, location, title, etc. and this is frequently coupled with another form that outlines what the new employee will need – network account, email, computer, phone, access to certain applications and group memberships to name a few.

A portal, such as the one in UMRA, can easily replace the paper request forms with web forms. The HR department or hiring manager completes the form online in lieu of the paper. Workflow processes automatically take over and distribute the information to the appropriate parties for approval or action. Active Directory and email accounts can quickly and securely be created while emails can be delivered to the system owners to insure provisioning occurs and hardware requirements are fulfilled. As items are completed, the owners indicate such in the portal allowing for ease of tracking.

A similar process can easily be set up for termination. Instead of HR sending the help desk an email, a quick entry into a web form can kick off the entire account disable and delete process. This allows for a much better level of security and reduces the risk a terminated employee will continue to have access to systems for days, weeks or even longer!

Once the “electronic” forms are in place, more time can be spent defining further requirements such as Role Based Access Control, electronic interfaces to other systems and even employee self-service. The net result, however, is a quick win for the entire organization – reduced paper work, better accuracy, timely account creation and, just as important, account deletion.

For more information, please visit our website to learn more about our phased approach Tools4ever.com.

Monday, August 15, 2011

Combining migration with implementation?

Many companies are apprehensive about implementing UMRA when they are in the middle of a migration process to an Active Directory (AD) environment. This may be due to the misconception that the migration must first be completed before UMRA will work properly, or starting another project while they are in the process of migration might overcomplicate the project, thus delaying the project deadline. The fact is that UMRA assists with migration both pre and post project and streamlines the process. Tools4ever expertise in this area provides a valuable project management asset and speeds up the migration process.

There are two common migration scenarios. The first of which is domain consolidation, multiple AD domains are being collapsed into a single domain. In this scenario UMRA is able to recreate the user account and, more often than not, retain the username in the new domain. Organizations also have the choice to implement new naming conventions. This occurs in circumstances where the migration results in several duplications of names. UMRA will then create a new user name and alerts end users, via email, what their new username will be along with the date that name will be made effective.

Not only is the user migration process streamlined, but the resources of those users as well. This includes items like group memberships and home directory data. As users are migrated UMRA will retain their group memberships, and if one of groups in question doesn’t reside in the new domain UMRA creates it automatically. Home directory data can either be copied to a new server in the new domain or re-permissioned on the existing server with the SID of the newly migrated account.

UMRA also assists and eases the migration process by:

Eliminating Pollution-Most migration tools will copy 1:1 which will includes erroneous and/or stale accounts. UMRA migrates users by reconciling them against a HR/SIS system so that pollution is not included. Activity reports on which groups are not being used are generated so that unused objects are not migrated.

Fill Attributes-When migration takes place there might be some missing information such as “title” or “Department”. UMRA automatically populates this information as needed.


To learn more about UMRA please visit our website.

Monday, August 8, 2011

What’s in a Password?

Find out how a recent study uncovered alarming news about the security risks in employee passwords

Would you believe it if I told you that there are less than 1% of truly random passwords in use today? Well the unfortunate reality is it’s true. A recent report* shows that less than 1% of passwords used today are random in nature. In fact, the report breaks down how some people derive their passwords; for example:
• 14% of passwords are derived from a person’s name (JohnSmith)
• 8% of password are derived from a place name – most likely the place where the person lives or was born (SeattleWA)
• 14% of passwords are purely numeric and in some situations are consecutive numbers (12345)
• 25% of passwords are random dictionary words (computer)
• Another 8% or so are made up of keyboard patterns, short phrases, words within the email address, and repeating words (asdf, myblackcat, @apple, redred – respectively)
• While the remaining 31% could not be verified during the study

This information is alarming to network and security administrators in any field. While most system administrators will set password complexity rules, not all do; and those that do may still find that employees may use passwords that are easy to replicate. So to help circumvent network breaches organizations should consider adding identity management solutions to protect themselves. There are several easy solutions an organization can implement to help reduce the risk of password security breach.

One I’d like to focus a little on is implementing a solution that requires two-factor authentication. This practice requires securing the primary login using a pass-card or biometrics. Instead of entering a username and password, users can log in by presenting a pass-card/biometric to a reader and entering a PIN code. Combining a pass-card/biometrics and a PIN code ensures strong authentication. Because this two-factor authentication is based on something users own (the pass-card/biometrics) and something they know (the PIN code).


Tools4ever’s Enterprise Single Sign On Manager(E-SSOM) offers full integration with all common two-factor authentication readers, such as HID, Mifare, Biometrie, Gridtoken, proximity-based devices and RFID readers. E-SSOM offers native integration with the driver software of the (card) reader and links the pass-card ID to the user credentials (username/password) in Active Directory. No additional software is required to create this link. This feature guarantees an user friendly and secure login for all users.

Stay tuned for my next blog where I explain how implementing a self-service password reset option can also help ensure your employees are using secure and complex passwords.

*Source: The science of password selection by Troy Hunt

Wednesday, July 13, 2011

Two-Factor Authentication for Password Resets

In order to increase security of websites, applications and networks, many organizations are increasingly turning to two-factor authentication. Recently I tried to log into my online banking from a new laptop. The website returned a message that it did not recognize the computer and I would need a PIN to log in. The PIN could be delivered via email or SMS to my mobile phone. Further, the PIN could only be delivered to an email or cell number the bank already had on record – no ability to enter new information.

Tools4ever has recently made enhancements to our Self Service Reset Password Manager (SSRPM) software to take full advantage of two-factor authentication by several methodologies. The first enhancement, released earlier this year, delivered a PIN via an email account. The email adds had to be previously entered by the end user to insure no spoofing can occur. Once a user initiates the “Forgot My Password” wizard and completes the challenge questions, they are prompted for the PIN to complete the password reset.

The most recent version of SSRPM, released on June 24th, takes two-factor authentication to the next level and provides the ability to deliver an SMS message containing the PIN. The cell phone number needs to be entered during enrollment by the end user, once again to prevent spoofing when a reset is actually performed. In a similar fashion to the email functionality, once an end user initiates the reset wizard and completes the challenge questions successfully, they are prompted to enter the PIN delivered to their cell via SMS.

To learn more about two-factor authentication, this Wiki article has excellent information. To learn more about Tools4ever and SSRPM, please visit our website.

Wednesday, June 15, 2011

Complete an SSO Survey for a chance at an IPAD2!

Toosl4ever is busy finalizing the next release of its Enterprise Single Sign On Manager. The release currently slated for June 17, 2011 will incorporate many new features and enhancements to existing supported application types.

We would like to learn more about your interest and requirements for SSO. Please take a minute to complete a brief survey and we will enter you for a chance to win an iPAd 2. This survey is limited to 500 participants so don’t delay! Click HERE to take the survey and good luck!

Wednesday, June 1, 2011

Enterprise Single Sign On for Automotive Dealerships

A recent implementation on the Tools4ever Enterprise Single Sign On Manager (E-SSOM) for a group of automotive dealers in Louisiana presented a unique opportunity. This group has a total of 15 dealerships and all were running the same HR, CRM, inventory and dealer management applications, along with a number of web-based tools. They had been utilizing an SSO application from their CRM/ dealer management vendor that automatically logged personnel into the appropriate applications based on their Active Directory credentials.

The major problem occurred when the supplier made a decision to stop supporting the SSO application in a few months.

The dealership started an immediate search for a replacement product. They knew all too well that the calls to the help desk for password assistance would skyrocket once the old SSO application was removed. Tools4ever was selected as a potential vendor and after a thorough Proof of Concept, and a few tweaks to E-SSOM, we were able to demonstrate the basic functionality of our solution in the client’s production environment by automating the logon process for 8 unique applications, including the most crucial CRM and dealer management systems.

After the roll out to all current employees was completed, a decision was made to pre-enroll new users. Basically, the only credentials anyone will ever receive going forward is their AD username and password. Access to all other applications will be handled via E-SSOM and the end users will never actually know the passwords to the eight applications they need to access. The benefit is that by disabling a terminated employees AD account, or removing their E-SSOM profile, their access to every other application is automatically revoked thus eliminating a potential security concern.

To learn more about Tools4ever solutions for Identity and Password Management, please visit our website.