The trend that’s continuing to surge for workforce employees is mobile, on-the-go work and work from home despite some pull back from large organizations, like Yahoo! In the last six years telework grew a staggering 73 percent . In addition, one of four U.S. employees works remotely at least some of the time. These statistics don’t include all of the people who travel regularly and work remotely because of this.
Though working remotely has many benefits or organization and their employees, the cloud and mobility can bring about issues for both the organization’s IT department and the end user. Richard Branson, founder of Virgin Group, was recently quoted making the bold statement that “one day offices will be a thing of the past.” Until then, though, some of the issues with working remotely need to be ironed out.
Managing Accounts for Remote Employees
Correctly provisioning accounts for hundreds or thousands of users who are not physically working within the walls of an organization can be a major headache, and also can be an issue for the end user as employees need access to their accounts quickly and correctly provisioned so that they can begin their work and have access to the systems and applications that they need. In addition, ensuring that employees who are no longer with the company are correctly de-provisioned also needs to be done properly. A disgruntled employee who has access to the organization’s network can cause a great deal of havoc to its data.
Losing Track of Who Has Access to What
Amidst all of the account provisioning, granting access and revoking access to the many cloud applications, organizational IT leaders can easily lose track of exactly who has access to what. This can become not only a security issue, but also a problem for licensing costs since the organizations does not know exactly how many licenses they need to be buying. In addition, this can be a problem when needing to audit systems since it is difficult for the organization to show and document who has access to secure data.
Dealing with Password Issues
Like employees working onsite, those working remotely tend to have difficultly remembering their credentials for the many different cloud applications they need to access. This is especially true for employees who are on the go, and contacting the IT department can be a major hassle. Needing to contact the helpdesk to have a password reset while working remotely is not only a huge annoyance for the end user, but also for the IT department since it tends to receive copious amounts of these types of calls.
So how can all of this be solved? Several leading organizations have chosen to use identity and access management solutions for resolving most of these issues. An automated account management solution can allow the IT department at any organization to easily complete a form, check the boxes for which systems accounts need to be created in and accounts are automatically provisioned. This task can even be delegated to less technical staff if needed, such as help desk employees.
When employee accounts need to be disabled, help desk employees can easily de-provision users without manually going into each system and application. Additionally, the accounts also can be placed into a different category, where they have limited access to systems, but can still utilize other aspects of the accounts.
To keep track of exactly who has access to what, a centralized dashboard can be used to provide an overview of which users are deployed in each cloud application. This allows the organization to know exactly who has access to what, and how many licenses they need for each cloud application.
To help with password issues, single sign-on solutions work well with cloud applications. This allows users to login in once with a single set of credentials and thereafter gain access to all other applications they are authorized for. If a password does need to be reset, a self-service password reset software is another type of solution that can be helpful to remote employees. This type of solution allows end users to reset their own passwords without having to contact the help desk. Employees and students can answer security questions that they have previously provided answers to, and quickly reset their passwords.
With all or some of these solutions, organizations are able to provide a better experience to their users who are working remotely, and allow them to work more efficiently wherever they are.
For more information, please visit our website - www.tools4ever.com.
Friday, February 6, 2015
Thursday, October 2, 2014
Management of Complex Passwords Causing Headaches for Enterprise IT Leaders
Complex passwords: Their intention is to ensure organizational security, but they often cause more of a headache than they are worth, and the issues that usually arise from having to manage them can prove more problematic than beneficial. Security, of course, is the name of the game here, and organizations that put such a strategy in place are usually better off for doing so. However, given the complexities of such protocols – the rules associated with complex passwords, such as changing them monthly, for example -- often cause many headaches for end users, the helpdesk, IT departments and the organization overall.
The issues involved in employing a complex password strategy are many. The following are just some of the issues enterprise IT leaders often experience because of them:
Extended Log In Times
When employees need to log in to each system or application separately, and enter a different set of usernames and passwords, the process becomes time consuming and cumbersome. This can be especially annoying for those who utilize multiple computers and workstations. Each time they need access their systems, they are likely required to log in into a different computer and each application again, separately. This can be a major drag on efficiency and productivity.
Community Bank and Trust of Florida is an example of an organization facing these issues. The bank uses hundreds of different systems and applications to assist its customers, and because of this, employees frequently had to remember credentials for many of them. This proved difficult since most of the organization’s passwords were complex and expired often, which led employees to frequently forget their passwords. With a focus on quality customer service, the password issues caused a major issue with efficiently assisting customers.
Customer Service Issues
Not only is logging into each system and application separately an annoyance for the employee, it also can be a huge service obstacle for customers when an employee must load and re-load their access rights for the various systems they need to access when addressing client-facing service requests. Add to this any problems, such as getting locked out, and the issue is only exacerbated. If customers are affected by such issues, it’s a negative. If customers must wait longer than they need to because of poor IT protocols, they may leave and never return.
Needham Bank in Massachusetts faced this challenge. Employees at the bank were frustrated by the number of credentials they were required to remember and by the amount of time it took to reset their passwords. It also frustrated employees when they had to halt what they were doing and contact the help desk to reset their password when locked out.
Decreased Security
People tend to take the easiest action to complete tasks in the timeliest manner. With passwords, this means they usually write them down. Obviously, this is a self-defeating action when security is the ultimate goal. Simply put, doing so leaves the organization’s network at risk for hack or attack.
Waiting in Queue for a Password Reset
Help desk, help desk, help desk: Calls to the help desk because of users forgetting their complex passwords is an issue no one should face and yet currently takes most of the help desk’s time to manage. In fact, it’s estimated that password resets are one of the most common reasons for calls to the help desk, and that 40 to 50 percent of all calls to the department are because they need passwords reset.
When users need to reset their passwords because of forgetting one of the many they need to remember, they’ll likely need to go through the process of contacting the help desk. While this process isn’t very difficult, it is non-productive for employees to sit on the phone waiting in the queue when they have a list of things needing to be completed for the day. This leads to the next issue.
Large Number of Calls to the Help Desk
For even the smallest organizations, voluminous calls to the help desk is a major problem since the department has to then deal with the issue.
Certain password solutions can be helpful with these issues. More organizations are beginning to realize the benefits of single sign-on and self-service password reset solutions, allowing them to solve these issues while still ensuring security.
SSO allows users to log in with one set of credentials and thereafter automatically gain access to all other applications and systems for which they are authorized. This helps improve log in times since users only need to enter credentials one time, instead of for each application. The solutions also drastically reduce the chances that users will write down their credentials since they do not have several to remember.
Also, two-factor authentication can be added ensure additional security of information and systems. Instead of entering a username and password, two-factor authentication requires users to log in by presenting a smart card to a reader and entering a PIN code. Combining a smart card and a PIN ensures strong authentication since it is based on two forms of identification.
Finally, self-service password reset solutions allow users the ability to reset their passwords themselves after correctly answering security questions that they previously provided answers to. This allows users to proactively solve their own password issues without having to contact the help desk. In turn, this drastically reduces password reset calls, and allows employees to be more productive.
Password solutions such as these allow organizations to ensure security while also allowing their employees to be more productive, can improve customer service and can drastically reduce the calls to often overwhelmed help desks.
For more information, please visit our website: www.tools4ever.com
The issues involved in employing a complex password strategy are many. The following are just some of the issues enterprise IT leaders often experience because of them:
Extended Log In Times
When employees need to log in to each system or application separately, and enter a different set of usernames and passwords, the process becomes time consuming and cumbersome. This can be especially annoying for those who utilize multiple computers and workstations. Each time they need access their systems, they are likely required to log in into a different computer and each application again, separately. This can be a major drag on efficiency and productivity.
Community Bank and Trust of Florida is an example of an organization facing these issues. The bank uses hundreds of different systems and applications to assist its customers, and because of this, employees frequently had to remember credentials for many of them. This proved difficult since most of the organization’s passwords were complex and expired often, which led employees to frequently forget their passwords. With a focus on quality customer service, the password issues caused a major issue with efficiently assisting customers.
Customer Service Issues
Not only is logging into each system and application separately an annoyance for the employee, it also can be a huge service obstacle for customers when an employee must load and re-load their access rights for the various systems they need to access when addressing client-facing service requests. Add to this any problems, such as getting locked out, and the issue is only exacerbated. If customers are affected by such issues, it’s a negative. If customers must wait longer than they need to because of poor IT protocols, they may leave and never return.
Needham Bank in Massachusetts faced this challenge. Employees at the bank were frustrated by the number of credentials they were required to remember and by the amount of time it took to reset their passwords. It also frustrated employees when they had to halt what they were doing and contact the help desk to reset their password when locked out.
Decreased Security
People tend to take the easiest action to complete tasks in the timeliest manner. With passwords, this means they usually write them down. Obviously, this is a self-defeating action when security is the ultimate goal. Simply put, doing so leaves the organization’s network at risk for hack or attack.
Waiting in Queue for a Password Reset
Help desk, help desk, help desk: Calls to the help desk because of users forgetting their complex passwords is an issue no one should face and yet currently takes most of the help desk’s time to manage. In fact, it’s estimated that password resets are one of the most common reasons for calls to the help desk, and that 40 to 50 percent of all calls to the department are because they need passwords reset.
When users need to reset their passwords because of forgetting one of the many they need to remember, they’ll likely need to go through the process of contacting the help desk. While this process isn’t very difficult, it is non-productive for employees to sit on the phone waiting in the queue when they have a list of things needing to be completed for the day. This leads to the next issue.
Large Number of Calls to the Help Desk
For even the smallest organizations, voluminous calls to the help desk is a major problem since the department has to then deal with the issue.
Certain password solutions can be helpful with these issues. More organizations are beginning to realize the benefits of single sign-on and self-service password reset solutions, allowing them to solve these issues while still ensuring security.
SSO allows users to log in with one set of credentials and thereafter automatically gain access to all other applications and systems for which they are authorized. This helps improve log in times since users only need to enter credentials one time, instead of for each application. The solutions also drastically reduce the chances that users will write down their credentials since they do not have several to remember.
Also, two-factor authentication can be added ensure additional security of information and systems. Instead of entering a username and password, two-factor authentication requires users to log in by presenting a smart card to a reader and entering a PIN code. Combining a smart card and a PIN ensures strong authentication since it is based on two forms of identification.
Finally, self-service password reset solutions allow users the ability to reset their passwords themselves after correctly answering security questions that they previously provided answers to. This allows users to proactively solve their own password issues without having to contact the help desk. In turn, this drastically reduces password reset calls, and allows employees to be more productive.
Password solutions such as these allow organizations to ensure security while also allowing their employees to be more productive, can improve customer service and can drastically reduce the calls to often overwhelmed help desks.
For more information, please visit our website: www.tools4ever.com
Friday, September 12, 2014
Core Registration: The Umbrella Over All Health Systems and Data
Healthcare organizations use a variety of systems containing personal data and collected information. As the quantity of this data continues to increase over time, and as the organizations continue to expand and develop, merge and downsize, not to mention constant employee turnover, there are a great many changes and countless systems managing this information, making it difficult to implement changes across the network in a convenient way. Moreover, if the wrong authorizations are assigned, it is not possible to ensure proper information security.
The ability to quickly anticipate the inflow, transfer and outflow of staff requires a transparent and uniform overview of all the personal data in a single source system. This is called core registration. In many organizations, core registration is absent or incomplete. In such a case, the security officer must ask the various systems administrators for information to find out exactly who an employee is, what they are authorized to do and to which resources they are able to access. After all, the required information is fragmented across various systems, such as the facility management system, Active Directory, the electronic health record and other systems involving complex authorizations, such as planning and scheduling applications.
Active Directory as a source system
Active Directory is often used as a source system for assigning authorizations, as well as keeping track of additional personal or organizational information. Authorizations may find expression, for instance, in Active Directory groups, with information such as the room number, title and department being added to user accounts. However, organizations that do so run into a number of limitations. First of all, Active Directory does not offer a location for arranging physical access. Neither is it very suitable for mapping out persons with multiple employment contracts that are active in various different departments.
In addition, probably the most important limitation for using Active Directory as a source system is authorizations, as a too limited overview of a person is obtained. Active Directory groups are often used to manage access to applications. However, with certain healthcare applications, authorizations are often not handled via Active Directory as it does not “dig deep enough” for this purpose. Users can only see whether someone has access to the application and not what somebody is allowed to do inside the application.
Human resources management system as a source
Some organizations use their human resources management (HRM) system as the source for implementing changes across the network. When an employee is added to the HRM system, a user account is created immediately. However, the HRM system is not exhaustive; freelancers, medical specialists from partnerships and other third parties are often not or only partially included in the system. Furthermore, although the HRM system contains a host of data, it does not contain all the information that is important for IT.
A HRM system only answers the question of “Who is this person and which role does he or she fulfil in the organization?” However, it does not contain information on the permissions people have (which user rights does an employee have in a certain system, for example) or the resources (phone, access pass, laptop) they have at their disposal.
This type of information must be derived from other systems. When somebody leaves the organization, the corresponding Active Directory account will be disabled automatically. Unfortunately, it is not easy to perform other required measures, such as blocking the access pass, collecting the mobile phone and removing the phone number from the phone systems. Disabling user accounts in cloud-based systems usually is an even more complex affair.
There are organizations that use role-based access control (RBAC) alongside the HRM system to set up authorization management. In this approach, authorizations are not assigned on an individual basis, but are based on pre-determined roles. These roles in turn comprise information on the department, title, location and cost center of an employee.
However, RBAC is not all encompassing when it comes to staff transfers. RBAC provides an overview of the authorizations an employee should receive for their new role and what their authorizations are in their current role. The current situation may indicate that an employee has received manual authorizations since they were initially provisioned, and they should be re-validated during their transfer to determine if these rights need to persist.
Identity Vault
Rather than using Active Directory or the HRM system as a source, a better solution would be to deliver these and other data in a single, uniform pane of glass: the core registration.
The objective of core registration is to have a single, leading registration for all identities across the organization. With core registration, personal data are retrieved from all sorts of sources (e.g. the HRM, scheduling, flex pool management, Active Directory and facility management system). These may include name, address and town details, information on the employment contract, the room number, title, manager of the employee, as well as used resources, such as the phone and access pass. All data are compiled in the core registration. This set of data is also known as an identity vault.
The core registration is leading for the assignment of physical and logical access. All authorizations across the network are loaded and stored in the core registration and made searchable. The core registration provides a 360-degree overview of people’s identity, what they are allowed to do and which resources they have at their disposal. If employees are not listed in the core registration, they will not have access to the network and no physical access to (parts of) the building.
Every change in the source system will result in a modification in the core registration. Since the data is searchable, the security officer can look up a person and directly see in which systems the person is present, under which identities and what the person in question is allowed to do. The security officer can also see for each department and team which rights are used by whom, so that any anomalies can be quickly identified.
License management and more
In addition to the benefits of setting up more efficient processes for the inflow, transfer and outflow of employees and proactively identifying and responding to security incidents, core registration can be used for audits. Because of the availability of a centralized dashboard for keeping track of who has access to which applications, it will be easier to pass software license audits. In this scenario, the dashboard will work as a business intelligence tool for authorizations.
Core registration can also be used to control the license costs. Using the technique role mining, insight can be provided into which applications are available on average for each organizational role. This matching may result in the conclusion that 90 percent of employees in a particular organizational role (e.g. nurse at the cardiology department) use a particular application, like the scheduling system. When it has been identified which applications are required for a particular organisation role, it will be easy to pinpoint employees in the same role who use different applications. In such cases, an additional check can be performed. After all, it is more than likely that the employee in question is unnecessarily incurring license costs.
Finally, any events triggered by the core registration will result in a network action. By linking the core registration to a provisioning system, these network actions can be implemented automatically. When an employee leaves the organization, the provisioning system will set in motion the procedure for shutting down the user account.
For more information, please visit our website.
The ability to quickly anticipate the inflow, transfer and outflow of staff requires a transparent and uniform overview of all the personal data in a single source system. This is called core registration. In many organizations, core registration is absent or incomplete. In such a case, the security officer must ask the various systems administrators for information to find out exactly who an employee is, what they are authorized to do and to which resources they are able to access. After all, the required information is fragmented across various systems, such as the facility management system, Active Directory, the electronic health record and other systems involving complex authorizations, such as planning and scheduling applications.
Active Directory as a source system
Active Directory is often used as a source system for assigning authorizations, as well as keeping track of additional personal or organizational information. Authorizations may find expression, for instance, in Active Directory groups, with information such as the room number, title and department being added to user accounts. However, organizations that do so run into a number of limitations. First of all, Active Directory does not offer a location for arranging physical access. Neither is it very suitable for mapping out persons with multiple employment contracts that are active in various different departments.
In addition, probably the most important limitation for using Active Directory as a source system is authorizations, as a too limited overview of a person is obtained. Active Directory groups are often used to manage access to applications. However, with certain healthcare applications, authorizations are often not handled via Active Directory as it does not “dig deep enough” for this purpose. Users can only see whether someone has access to the application and not what somebody is allowed to do inside the application.
Human resources management system as a source
Some organizations use their human resources management (HRM) system as the source for implementing changes across the network. When an employee is added to the HRM system, a user account is created immediately. However, the HRM system is not exhaustive; freelancers, medical specialists from partnerships and other third parties are often not or only partially included in the system. Furthermore, although the HRM system contains a host of data, it does not contain all the information that is important for IT.
A HRM system only answers the question of “Who is this person and which role does he or she fulfil in the organization?” However, it does not contain information on the permissions people have (which user rights does an employee have in a certain system, for example) or the resources (phone, access pass, laptop) they have at their disposal.
This type of information must be derived from other systems. When somebody leaves the organization, the corresponding Active Directory account will be disabled automatically. Unfortunately, it is not easy to perform other required measures, such as blocking the access pass, collecting the mobile phone and removing the phone number from the phone systems. Disabling user accounts in cloud-based systems usually is an even more complex affair.
There are organizations that use role-based access control (RBAC) alongside the HRM system to set up authorization management. In this approach, authorizations are not assigned on an individual basis, but are based on pre-determined roles. These roles in turn comprise information on the department, title, location and cost center of an employee.
However, RBAC is not all encompassing when it comes to staff transfers. RBAC provides an overview of the authorizations an employee should receive for their new role and what their authorizations are in their current role. The current situation may indicate that an employee has received manual authorizations since they were initially provisioned, and they should be re-validated during their transfer to determine if these rights need to persist.
Identity Vault
Rather than using Active Directory or the HRM system as a source, a better solution would be to deliver these and other data in a single, uniform pane of glass: the core registration.
The objective of core registration is to have a single, leading registration for all identities across the organization. With core registration, personal data are retrieved from all sorts of sources (e.g. the HRM, scheduling, flex pool management, Active Directory and facility management system). These may include name, address and town details, information on the employment contract, the room number, title, manager of the employee, as well as used resources, such as the phone and access pass. All data are compiled in the core registration. This set of data is also known as an identity vault.
The core registration is leading for the assignment of physical and logical access. All authorizations across the network are loaded and stored in the core registration and made searchable. The core registration provides a 360-degree overview of people’s identity, what they are allowed to do and which resources they have at their disposal. If employees are not listed in the core registration, they will not have access to the network and no physical access to (parts of) the building.
Every change in the source system will result in a modification in the core registration. Since the data is searchable, the security officer can look up a person and directly see in which systems the person is present, under which identities and what the person in question is allowed to do. The security officer can also see for each department and team which rights are used by whom, so that any anomalies can be quickly identified.
License management and more
In addition to the benefits of setting up more efficient processes for the inflow, transfer and outflow of employees and proactively identifying and responding to security incidents, core registration can be used for audits. Because of the availability of a centralized dashboard for keeping track of who has access to which applications, it will be easier to pass software license audits. In this scenario, the dashboard will work as a business intelligence tool for authorizations.
Core registration can also be used to control the license costs. Using the technique role mining, insight can be provided into which applications are available on average for each organizational role. This matching may result in the conclusion that 90 percent of employees in a particular organizational role (e.g. nurse at the cardiology department) use a particular application, like the scheduling system. When it has been identified which applications are required for a particular organisation role, it will be easy to pinpoint employees in the same role who use different applications. In such cases, an additional check can be performed. After all, it is more than likely that the employee in question is unnecessarily incurring license costs.
Finally, any events triggered by the core registration will result in a network action. By linking the core registration to a provisioning system, these network actions can be implemented automatically. When an employee leaves the organization, the provisioning system will set in motion the procedure for shutting down the user account.
For more information, please visit our website.
Friday, September 5, 2014
Four Simple Solutions for Introducing Complex Passwords
Passwords are a pain and you’re on the hunt to make the management of them easier and less offensive. Complex passwords were initially introduced to improve the security of your systems, but the introduction of such passwords -- which also have to be changed regularly -- leads to resistance among your employees. After all, they have to remember of multitude of password/user name combinations. This results in insecure situations where employees write down passwords on Post-Its and many password reset requests to the helpdesk.
Here are four simple solutions that you can introduce for managing complex passwords that won’t cause frustration among users.
Reduce the number of passwords with single sign-on. Reduce the number of passwords and ensure that employees only have to remember one (complex) password instead of dozens. Single sign-on (SSO) offers the ability to do this. SSO lets employees log in just once, after which access is automatically granted to all applications and systems the user might open. So the staff member doesn’t have to log in afresh for each application. And that saves an average of three to five logins with varying passwords each day.
Perhaps you want to do away with even this one remaining password? In that case, SSO can be deployed in combination with an access pass. The security card your employees use to gain access to the premises or parts of the premises, then replaces the final password/user name combination. By presenting a card to or into a reader and, if required, entering a PIN code, the user is automatically logged in. When the employee again presents the card to a reader, he or she is then logged out.
Automatic password synchronization. Wouldn’t it be ideal if the same password/username combination could be used for every application? The difficulty here is that the passwords almost always have an expiry date and need to be renewed regularly. Typically, the expiry date is not the same for every application. For some applications a new password has to be set monthly, while other software might only require it once a year. It’s virtually impossible for users to reset a newly introduced password in all the other required applications so that the password would then indeed be identical everywhere.
However you can actually automate this very well with solutions for password synchronization, which ensure that passwords are and remain synchronous in multiple systems. The newly set password is then immediately intercepted and forwarded to all other applications.
Help users to create strong passwords. Employees often find it difficult to come up with complex passwords. Some applications insist that the password must contain an uppercase letter, a punctuation mark or a figure. Or that the password must differ from the old one by X percentage.
That’s why users need some help in creating new, strong passwords. Password creation tools assist users in producing their passwords. The established complexity rules are shown when users configure a new password, and they are notified whether the relevant requirements have been met.
Let users reset their passwords themselves. As mentioned earlier, the introduction of complex passwords leads to an increase in the number of password reset requests to the helpdesk. To ease the burden on the helpdesk, it’s possible to let users reset their passwords themselves. Users identify themselves by correctly answering a number of personal questions (e.g. “What’s your mother’s maiden name?”) and can then reset their own passwords, without the intervention of the helpdesk.
A combination of these solutions means time-consuming registration procedures are a thing of the past and the helpdesk is relieved of the problems. Users benefit from maximum user-friendliness, while productivity rises.
Learn more at our website.
Here are four simple solutions that you can introduce for managing complex passwords that won’t cause frustration among users.
Reduce the number of passwords with single sign-on. Reduce the number of passwords and ensure that employees only have to remember one (complex) password instead of dozens. Single sign-on (SSO) offers the ability to do this. SSO lets employees log in just once, after which access is automatically granted to all applications and systems the user might open. So the staff member doesn’t have to log in afresh for each application. And that saves an average of three to five logins with varying passwords each day.
Perhaps you want to do away with even this one remaining password? In that case, SSO can be deployed in combination with an access pass. The security card your employees use to gain access to the premises or parts of the premises, then replaces the final password/user name combination. By presenting a card to or into a reader and, if required, entering a PIN code, the user is automatically logged in. When the employee again presents the card to a reader, he or she is then logged out.
Automatic password synchronization. Wouldn’t it be ideal if the same password/username combination could be used for every application? The difficulty here is that the passwords almost always have an expiry date and need to be renewed regularly. Typically, the expiry date is not the same for every application. For some applications a new password has to be set monthly, while other software might only require it once a year. It’s virtually impossible for users to reset a newly introduced password in all the other required applications so that the password would then indeed be identical everywhere.
However you can actually automate this very well with solutions for password synchronization, which ensure that passwords are and remain synchronous in multiple systems. The newly set password is then immediately intercepted and forwarded to all other applications.
Help users to create strong passwords. Employees often find it difficult to come up with complex passwords. Some applications insist that the password must contain an uppercase letter, a punctuation mark or a figure. Or that the password must differ from the old one by X percentage.
That’s why users need some help in creating new, strong passwords. Password creation tools assist users in producing their passwords. The established complexity rules are shown when users configure a new password, and they are notified whether the relevant requirements have been met.
Let users reset their passwords themselves. As mentioned earlier, the introduction of complex passwords leads to an increase in the number of password reset requests to the helpdesk. To ease the burden on the helpdesk, it’s possible to let users reset their passwords themselves. Users identify themselves by correctly answering a number of personal questions (e.g. “What’s your mother’s maiden name?”) and can then reset their own passwords, without the intervention of the helpdesk.
A combination of these solutions means time-consuming registration procedures are a thing of the past and the helpdesk is relieved of the problems. Users benefit from maximum user-friendliness, while productivity rises.
Learn more at our website.
Friday, August 29, 2014
Benefits of SSO for all businesses
Single sign-on (SSO) solutions benefit system end users, allowing them to quickly log on to their accounts by entering only one set of credentials and thereafter automatically logging them into all their systems and applications. In addition to this benefit, SSO provides other features that can further help end users and system admins throughout any organization.
Additional advantages of SSO, that are often not discussed, include:
Reduction in calls to the helpdesk
Often, since end users are required to remember several different sets of log in credentials, many of which are complicated and require special characters, they have trouble remembering each combination of user name and password. This leads to them calling the helpdesk to reset their passwords. With an SSO solution, end users only need to remember one set of credentials, which drastically reduces calls to the helpdesk and allows them to focus on more important tasks.
Integrates with other solutions
SSO is often able to integrate with other beneficial software, such as self-service password resetting and user provisioning. This allows organizations the ability to easily integrate SSO with solutions they might already have in place or with new software. For password resets, applications that require a new password every month or so, SSO can automatically generate a new password. With user provisioning, SSO can automatically provision a password for a new user.
Follow me
Another additional feature that can be added to SSO is the principle of “follow me.” This allows end users that need to work on different computers, such as doctors in the hospital setting, to easily do so by being able to log in on one computer and then quickly log out and continue their work on another computer. With “follow me,” users can quickly move to different work stations and do not have to open all applications that they were previously working on.
Fast user switching
In situations where users need to log in and out quickly, SSO can be very beneficial. Fast user switching allows users to quickly log on and have all of their applications started and logged in to on public computers. This can further be simplified by allowing the user to quickly swipe a pass card and have the same actions take place. Once they remove the card they are automatically signed out of all applications and the computer.
Fulfills compliance
SSO allows organizations to easily fulfill compliance and regulations. One way in which this is true is that an SSO solution can allow system admins to easily revoke access for a user in a single action, instead of having to go through each application. A report can also easily be generated to show which users have access to what applications to ensure that no users have access to information or applications that they shouldn’t. Lastly, SSO solutions can provide an additional check before the user logins to any critical application by requiring them to enter an additional PIN code or smart card.
Reduction of risks
A SSO solution not only makes the log on process more convenient and faster for the end user, it also makes the company’s information and applications more secure. When employees need to remember several different credentials they often write them down and keep them by their computers, which increases risk of someone unauthorized logging in. With and SSO solution the user only has to remember one set of credentials, reducing the chance that they will write them down.
For more information, please visit our website.
Additional advantages of SSO, that are often not discussed, include:
Reduction in calls to the helpdesk
Often, since end users are required to remember several different sets of log in credentials, many of which are complicated and require special characters, they have trouble remembering each combination of user name and password. This leads to them calling the helpdesk to reset their passwords. With an SSO solution, end users only need to remember one set of credentials, which drastically reduces calls to the helpdesk and allows them to focus on more important tasks.
Integrates with other solutions
SSO is often able to integrate with other beneficial software, such as self-service password resetting and user provisioning. This allows organizations the ability to easily integrate SSO with solutions they might already have in place or with new software. For password resets, applications that require a new password every month or so, SSO can automatically generate a new password. With user provisioning, SSO can automatically provision a password for a new user.
Follow me
Another additional feature that can be added to SSO is the principle of “follow me.” This allows end users that need to work on different computers, such as doctors in the hospital setting, to easily do so by being able to log in on one computer and then quickly log out and continue their work on another computer. With “follow me,” users can quickly move to different work stations and do not have to open all applications that they were previously working on.
Fast user switching
In situations where users need to log in and out quickly, SSO can be very beneficial. Fast user switching allows users to quickly log on and have all of their applications started and logged in to on public computers. This can further be simplified by allowing the user to quickly swipe a pass card and have the same actions take place. Once they remove the card they are automatically signed out of all applications and the computer.
Fulfills compliance
SSO allows organizations to easily fulfill compliance and regulations. One way in which this is true is that an SSO solution can allow system admins to easily revoke access for a user in a single action, instead of having to go through each application. A report can also easily be generated to show which users have access to what applications to ensure that no users have access to information or applications that they shouldn’t. Lastly, SSO solutions can provide an additional check before the user logins to any critical application by requiring them to enter an additional PIN code or smart card.
Reduction of risks
A SSO solution not only makes the log on process more convenient and faster for the end user, it also makes the company’s information and applications more secure. When employees need to remember several different credentials they often write them down and keep them by their computers, which increases risk of someone unauthorized logging in. With and SSO solution the user only has to remember one set of credentials, reducing the chance that they will write them down.
For more information, please visit our website.
Friday, August 15, 2014
Challenges of managing information in the cloud
The cloud continues to be much discussed and the many benefits it offers organizations of all sizes. Rarely is it mentioned, though, that there are a number of complications that come with managing data there, especially in regard to end user accounts and access of applications.
Using cloud applications surely can impact the security, compliance and IT-related cost savings of an organization. In relation to identity and access management, when several cloud applications are implemented, provisioning, password management and the monitoring of access begins to become quite a challenge. Because of this, organizational leaders should seriously consider implementing an automated cloud identity management solution if they’re using or making a move.
Auto provisioning
Creating accounts in cloud applications can be time consuming for both the IT department and the end user. System administrators must manually create accounts for users, which often delays users having access for days and not being able to get their work done. With an automated cloud identity management solution, user accounts are automatically created, modified, enabled or disabled via a synchronization with the HR system. The helpdesk or manager handling the process can easily make changes in one place and automatically synchronize these changes to all cloud applications.
Security
When an organization begins to use several cloud applications, it often becomes difficult to determine that the correct people have the correct access to systems and applications. Users may have access to systems and applications that they shouldn’t, leaving data vulnerable to breach. With a role-based access control (RBAC) module, for example, system administrators can easily control access to the company’s cloud applications on the basis of an employee’s department or job title based on records from the human resource system. So doing, ensures that each employee has the correct access to systems, even in cloud applications.
Password issues
Passwords often become a problem when implementing numerous cloud applications. Since IT administrators need to manage passwords for countless users, who often have trouble remembering several sets of credentials, the responsibility falls on the IT department to deal with resetting these passwords when users forget them. A cloud SSO solution can be used so that end users only must remember one set of credentials for all of their cloud applications, which can be based on their existing Active Directory credentials. If for any reason a password needs to be reset, it can be changed in one place, Active Directory, and then be automatically synchronized with all cloud applications.
Audit
As more cloud applications are deployed in an organization, the need for reporting of whom is using what applications and systems become paramount. The complexity of managing this process is increased by the number of cloud applications deployed and the number of users accessing the systems. A centralized dashboard can be used in an automated identity management solution to easily see on overview of usage and logging in. This allows management to easily review the report for auditing purposes, as well as controlling license costs.
Overall, cloud IAM solutions offer benefits to end users, IT departments and even management. End users are able to receive their account access quickly and not have to wait to perform their jobs if locked out and IT has full control over the applications and authorizations without having to spend countless hours on account management.
For management, audit and compliance is made easier because of the solutions. They don’t need to spend money on expenses in relation to the applications or the helpdesk, and are able to receive the full benefits of using cloud applications as originally expected.
For more information, please visit our website.
Using cloud applications surely can impact the security, compliance and IT-related cost savings of an organization. In relation to identity and access management, when several cloud applications are implemented, provisioning, password management and the monitoring of access begins to become quite a challenge. Because of this, organizational leaders should seriously consider implementing an automated cloud identity management solution if they’re using or making a move.
Auto provisioning
Creating accounts in cloud applications can be time consuming for both the IT department and the end user. System administrators must manually create accounts for users, which often delays users having access for days and not being able to get their work done. With an automated cloud identity management solution, user accounts are automatically created, modified, enabled or disabled via a synchronization with the HR system. The helpdesk or manager handling the process can easily make changes in one place and automatically synchronize these changes to all cloud applications.
Security
When an organization begins to use several cloud applications, it often becomes difficult to determine that the correct people have the correct access to systems and applications. Users may have access to systems and applications that they shouldn’t, leaving data vulnerable to breach. With a role-based access control (RBAC) module, for example, system administrators can easily control access to the company’s cloud applications on the basis of an employee’s department or job title based on records from the human resource system. So doing, ensures that each employee has the correct access to systems, even in cloud applications.
Password issues
Passwords often become a problem when implementing numerous cloud applications. Since IT administrators need to manage passwords for countless users, who often have trouble remembering several sets of credentials, the responsibility falls on the IT department to deal with resetting these passwords when users forget them. A cloud SSO solution can be used so that end users only must remember one set of credentials for all of their cloud applications, which can be based on their existing Active Directory credentials. If for any reason a password needs to be reset, it can be changed in one place, Active Directory, and then be automatically synchronized with all cloud applications.
Audit
As more cloud applications are deployed in an organization, the need for reporting of whom is using what applications and systems become paramount. The complexity of managing this process is increased by the number of cloud applications deployed and the number of users accessing the systems. A centralized dashboard can be used in an automated identity management solution to easily see on overview of usage and logging in. This allows management to easily review the report for auditing purposes, as well as controlling license costs.
Overall, cloud IAM solutions offer benefits to end users, IT departments and even management. End users are able to receive their account access quickly and not have to wait to perform their jobs if locked out and IT has full control over the applications and authorizations without having to spend countless hours on account management.
For management, audit and compliance is made easier because of the solutions. They don’t need to spend money on expenses in relation to the applications or the helpdesk, and are able to receive the full benefits of using cloud applications as originally expected.
For more information, please visit our website.
Friday, August 8, 2014
How two factor authentication can easily add security for access
Organizations large and small can easily add security to their login procedures with two-factor authentication, which is a simple process that requires users to enter more than one piece of information to access accounts. For example, in addition to simply entering a user name and password, two-factor authentication requires use of another identifier, such as a smart card or a PIN code.
Major organizations are making use of two-factor authorization — Twitter and Google. And while its primary goal is to improve security of systems and applications, the solutions also provide additional features that can be of benefit to all organizations. Here are some of the uses, and features, of two-factor authentication that can benefit employees and their organization:
Easily customizable: System administrations can customize the two-factor authentication process to meet their needs. For example, rules can be created that mandate that during the time a user is logged into an organization’s systems, his smart card also must be in the reader the whole time the employee is working. In this scenario, if the user removes the card he is then automatically logged out of the system. On the other hand, rules also can be written that requires a user to present the card for a few seconds when first logging in for him to access all needed systems.
PIN code memory: Though end users have to enter a PIN code for two-factor authentication, the internal systems have the ability to remember PIN codes for a defined period of time. Users then only have to enter their PIN code once when first logging into the computer at the beginning of the workday and not again after that. Each time after, during the same day, employees or users only have to present their smart card to access systems and not their PIN. This ensures that systems are secure, but does not inconvenience users by requiring them to enter both the PIN code and card each time they login.
Self-service registration: When first implementing smart card use, end users can securely register their smart cards themselves, taking the burden off of the IT department. Once a user inserts his card, which is not registered into the reader, it will enable a user to assign their username and password to this card.
Advanced authentication for resetting passwords: Two-factor authentication can be used to enable users to reset their own passwords. In addition to answering a series of questions that they previously provided answers to, end users can be sent a code via SMS or email that they will have to enter before being able to reset their passwords.
PIN code sent via email or SMS: The PIN code or password that end users provide as one source of authentication does not have to be something that the user actually remembers; nor does it have to be the same password every time. A password PIN can be automatically generated and sent to the user via text message to her cell phone or to her email account, which she then inputs to gain access to her account.
For more information, please visit our website.
Major organizations are making use of two-factor authorization — Twitter and Google. And while its primary goal is to improve security of systems and applications, the solutions also provide additional features that can be of benefit to all organizations. Here are some of the uses, and features, of two-factor authentication that can benefit employees and their organization:
Easily customizable: System administrations can customize the two-factor authentication process to meet their needs. For example, rules can be created that mandate that during the time a user is logged into an organization’s systems, his smart card also must be in the reader the whole time the employee is working. In this scenario, if the user removes the card he is then automatically logged out of the system. On the other hand, rules also can be written that requires a user to present the card for a few seconds when first logging in for him to access all needed systems.
PIN code memory: Though end users have to enter a PIN code for two-factor authentication, the internal systems have the ability to remember PIN codes for a defined period of time. Users then only have to enter their PIN code once when first logging into the computer at the beginning of the workday and not again after that. Each time after, during the same day, employees or users only have to present their smart card to access systems and not their PIN. This ensures that systems are secure, but does not inconvenience users by requiring them to enter both the PIN code and card each time they login.
Self-service registration: When first implementing smart card use, end users can securely register their smart cards themselves, taking the burden off of the IT department. Once a user inserts his card, which is not registered into the reader, it will enable a user to assign their username and password to this card.
Advanced authentication for resetting passwords: Two-factor authentication can be used to enable users to reset their own passwords. In addition to answering a series of questions that they previously provided answers to, end users can be sent a code via SMS or email that they will have to enter before being able to reset their passwords.
PIN code sent via email or SMS: The PIN code or password that end users provide as one source of authentication does not have to be something that the user actually remembers; nor does it have to be the same password every time. A password PIN can be automatically generated and sent to the user via text message to her cell phone or to her email account, which she then inputs to gain access to her account.
For more information, please visit our website.
Subscribe to:
Posts (Atom)