SlideShare a Scribd company logo
Understanding PortalGuard’s


Server-based Password Synchronization:
     Managing Multiple Passwords




  Highlighting the Self-service Password Reset Layer of the
                    PortalGuard Platform
By the end of this tutorial you will be able to…

 • How PortalGuard can help you
 • Understand password synch can be a midpoint between
   too many passwords and expensive SSO solutions
 • Learn about PortalGuard’s Server-based Password Synch
 • See the step-by-step Authentication Process
 • Know the technical requirements
The PortalGuard software is a Contextual Authentication platform
   which is focused on enhancing usability, while maintaining a
 balance between security, auditing and compliance for your web,
                 desktop and mobile applications.

   Usability                       Security
   • Single Sign-on                • Knowledge-based
   • Password Management           • Two-factor Authentication
   • Password Synchronization      • Contextual Authentication
   • Self-service Password Reset   • Real-time Reports/Alerts
Before going into the details…


• Configurable by user, group or domain hierarchy
• Comprehensive solution supporting multiple directories
• Enables self-service password reset, recovery and account unlock
• Force user enrollment (optional)
• Active Directory Password Filter (optional)
• Cost effective and competitively priced
• Easy to implement
Password Synchronization
Password Synchronization
Enterprise SSO
• Single password, single interface   • Cost effective

• Easier implementation               • Flexible

• Force enrollment                    • Server-based

• No client-side software required    • Self-service Password Reset

                Password Synch
The process of password synchronization…
   Correlates the passwords for multiple user accounts
Password Complexity Challenges



            Step One: Identifying Password Complexity Rules
  Rules differ from system to system causing
  a common hurdle to implementing
  password synch…
                       Step Two: Change Password Rules on Systems


WARNING:
Microsoft AD: no maximum password length or prevent specific characters
IBM System i: typically maximum length of 10 with special character limitations
Multiple Directories
  (including MS Active Directory, Novell eDirectory, IBM
  System i, LDAP v3-compliant, and custom SQL user tables )



                  Self-service Password Reset


       Real-time synch


          Consistent set of password rules


Active Directory Password Filter
Features:

• Ability to link a user’s primary account to accounts on multiple
  systems/directories
• All password changes, resets and account unlocks through
  PortalGuard flow to all linked systems in real-time
• Aligns password complexity rules to reduce barriers to password
  propagation
• Requirement to link accounts is policy driven which can be
  specific to the user, group or domain hierarchy
• Account linking can be enforced or made optional
• Supports multiple user account repositories
• Password Synch - eliminate the need for users to remember different
  passwords
• Ease of Use - manage passwords from single consistent interface
• Self-service - unlock accounts and reset passwords from one place
• Seamless Integration - with existing logins using “sidecar” mode
• Lower Costs - reduce password-related calls and required IT support
• Increased Productivity - and user adoption for new services/websites
HOW IT WORKS
How to link an account….
  Step 1: the user logs into a Windows workstation or an existing internal
  website. PortalGuard is notified of the logon and checks its policies to see if
  the user:



• Is required to link to
  an account in another
  directory, and

• If they have yet to do
  so
How to link an account….
Step 2: Once the user provides the correct password, the secondary account
password will be immediately synched with the primary if necessary
Step 1:
The user has forgotten their password and clicks “Forgot Password?” link
on the Windows logon screen or website logon page
Step 2:
The user chooses to reset their forgotten password and proves their identity
by correctly answering a series of challenge Q&A or entering an OTP
Step 3:
The user enters a new password that satisfies all linked account systems. The
PortalGuard server resets all linked accounts to use this password and
unlocks the accounts as well.
Step 4:
Immediate feedback is given to the user that the password reset was
successful on all linked accounts.
Configurable through the PortalGuard Configuration Utility:
• Password Synchronization         • Password Policies:
• Dictionary Words
• Regular Expressions
• Password History
• Minimum Length
• Maximum Length
• Minimum:
   • Lowercase characters
   • Uppercase characters
   • Numeric characters
   • Non-alphanumeric
      characters
• Enforce AD Complexity
• Password Rule Grouping
• Password Strength Meter
TECHNICAL REQUIREMENTS
PortalGuard Desktop – for Windows workstations

Sidecar Mode – enforce account linking on existing website

AD Password Filter – enforce custom password policy for
native Ctrl+Alt+Del Windows password changes
A MSI is used to install PortalGuard on IIS 6 or 7.x.
This version of PortalGuard supports direct access and authentication
to cloud/browser-based applications, only.
        •   Microsoft Active Directory – Windows 2000 AD domain or later
        •   Novell eDirectory 8.7 or later
        •   IBM System i - V5R2 or later
        •   Any LDAP v3-compliant directory
        •   Custom SQL user tables
        •    Microsoft Windows Server 2000
        •    Microsoft Windows Server 2003 (32 or 64-bit)
        •    Microsoft Windows Server 2008 (32 or 64-bit)
        •    Microsoft Windows Server 2008 R2
        •    Windows Terminal Services on Win2003
        •    Remote Desktop Services on Win2008
        •   IBM WebSphere/WebSphere Portal v5.1 or higher
        •   Microsoft IIS 6.0 or higher
        •   Microsoft Windows SharePoint Services 3.0 or higher
        •   Microsoft Office SharePoint Server 2007 or later
THANK YOU
For more information visit PortalGuard.com or Contact Us

More Related Content

PPTX
Authentication and Authorization in Asp.Net
PDF
Self-service Password Reset
PPTX
single sign-on
PPTX
Overcoming the challenges of Office 365 user management in hybrid environments​
PPTX
Self-service password management and single sign-on for on-premises AD and cl...
PPTX
Windows 8.1 for IT-pros - presentation from Campus days 2013
PPTX
PortalGuard Product Tour
PDF
CNIT 129S - Ch 6a: Attacking Authentication
Authentication and Authorization in Asp.Net
Self-service Password Reset
single sign-on
Overcoming the challenges of Office 365 user management in hybrid environments​
Self-service password management and single sign-on for on-premises AD and cl...
Windows 8.1 for IT-pros - presentation from Campus days 2013
PortalGuard Product Tour
CNIT 129S - Ch 6a: Attacking Authentication

What's hot (20)

PDF
Microservices and Self-contained System to Scale Agile
PPTX
Fear and Loathing of 2fa
PPTX
Asp.net membership anduserroles_ppt
PDF
Microservices: Architecture to Support Agile
PPTX
ASP.NET Web Security
PDF
CNIT 129S: 11: Attacking Application Logic
PDF
Difference between authentication and authorization in asp.net
PDF
CNIT 129S: Ch 6: Attacking Authentication
PDF
CNIT 129S: 9: Attacking Data Stores (Part 2 of 2)
PDF
Nanoservices and Microservices with Java
PDF
Data Architecture not Just for Microservices
PDF
Microservices - not just with Java
PPTX
Cookies authentication
PDF
CNIT 129S: Ch 3: Web Application Technologies
PDF
CNIT 129S: 8: Attacking Access Controls
PDF
Microservices: Redundancy=Maintainability
PDF
CNIT 129S: 12: Attacking Users: Cross-Site Scripting (Part 1 of 2)
PPTX
Highly confidencial security system
PDF
CNIT 129S: 13: Attacking Users: Other Techniques (Part 2 of 2)
PDF
How Small Can Java Microservices Be?
Microservices and Self-contained System to Scale Agile
Fear and Loathing of 2fa
Asp.net membership anduserroles_ppt
Microservices: Architecture to Support Agile
ASP.NET Web Security
CNIT 129S: 11: Attacking Application Logic
Difference between authentication and authorization in asp.net
CNIT 129S: Ch 6: Attacking Authentication
CNIT 129S: 9: Attacking Data Stores (Part 2 of 2)
Nanoservices and Microservices with Java
Data Architecture not Just for Microservices
Microservices - not just with Java
Cookies authentication
CNIT 129S: Ch 3: Web Application Technologies
CNIT 129S: 8: Attacking Access Controls
Microservices: Redundancy=Maintainability
CNIT 129S: 12: Attacking Users: Cross-Site Scripting (Part 1 of 2)
Highly confidencial security system
CNIT 129S: 13: Attacking Users: Other Techniques (Part 2 of 2)
How Small Can Java Microservices Be?
Ad

Viewers also liked (11)

PPTX
Using FLCs to Extend ESL Content Beyond the SEI Classroom
PPTX
Visual learning 2
PPTX
Matsol gonzalez whitlow
PDF
Contextual Authentication
PDF
The Lexical Profile of Diverse and Sophisticated Academic Essays
DOCX
Responding to errors in esl writing
PPTX
Breaking Down the Article Writing Process for New Academics
DOC
14532813 example-letter-of-inquiry
DOC
Inquiry letter
PPT
Business Letters Power Point Presentation
PPTX
Enquiry letters
Using FLCs to Extend ESL Content Beyond the SEI Classroom
Visual learning 2
Matsol gonzalez whitlow
Contextual Authentication
The Lexical Profile of Diverse and Sophisticated Academic Essays
Responding to errors in esl writing
Breaking Down the Article Writing Process for New Academics
14532813 example-letter-of-inquiry
Inquiry letter
Business Letters Power Point Presentation
Enquiry letters
Ad

Similar to Password Synchronization (20)

PDF
Sever-based Password Synchronization: Managing Multiple Passwords
PDF
Password Synchronization
PDF
Self-service Password Reset
PDF
PDF
Centralized Self-service Password Reset: From the Web and Windows Desktop
PDF
PDF
From Password Reset to Authentication Management
PPTX
Dell Password Manager Introduction
PDF
Configurable Password Management: Balancing Usability and Compliance
PDF
Hitachi ID Password Manager: Enrollment, password reset and password synchron...
PDF
ADSelf Service Password Flyer
PDF
SSPM Retail
PPTX
Active Directory Self-Service Suite Overview
PDF
Password Policies in Oracle Access Manager. How to improve user authenticatio...
PDF
Two-factor Authentication
PDF
Hitachi ID Privileged Access Manager: Randomize and control disclosure of pri...
PDF
Hitachi ID Solutions Support GLB Compliance
PPTX
The Cost and Loss of Not using Single Sign-On with Two-Factor Authentication
PDF
Oracle 4월 20일
PPTX
Dell Quest TPAM Privileged Access Control
Sever-based Password Synchronization: Managing Multiple Passwords
Password Synchronization
Self-service Password Reset
Centralized Self-service Password Reset: From the Web and Windows Desktop
From Password Reset to Authentication Management
Dell Password Manager Introduction
Configurable Password Management: Balancing Usability and Compliance
Hitachi ID Password Manager: Enrollment, password reset and password synchron...
ADSelf Service Password Flyer
SSPM Retail
Active Directory Self-Service Suite Overview
Password Policies in Oracle Access Manager. How to improve user authenticatio...
Two-factor Authentication
Hitachi ID Privileged Access Manager: Randomize and control disclosure of pri...
Hitachi ID Solutions Support GLB Compliance
The Cost and Loss of Not using Single Sign-On with Two-Factor Authentication
Oracle 4월 20일
Dell Quest TPAM Privileged Access Control

Recently uploaded (20)

PDF
7 ChatGPT Prompts to Help You Define Your Ideal Customer Profile.pdf
PDF
Unlocking AI with Model Context Protocol (MCP)
PPTX
Digital-Transformation-Roadmap-for-Companies.pptx
PDF
Assigned Numbers - 2025 - Bluetooth® Document
PDF
Machine learning based COVID-19 study performance prediction
PDF
Video forgery: An extensive analysis of inter-and intra-frame manipulation al...
PDF
MIND Revenue Release Quarter 2 2025 Press Release
PDF
Network Security Unit 5.pdf for BCA BBA.
PDF
Blue Purple Modern Animated Computer Science Presentation.pdf.pdf
PDF
Encapsulation_ Review paper, used for researhc scholars
PPTX
1. Introduction to Computer Programming.pptx
PPTX
cloud_computing_Infrastucture_as_cloud_p
PDF
Heart disease approach using modified random forest and particle swarm optimi...
PPTX
TLE Review Electricity (Electricity).pptx
PDF
Architecting across the Boundaries of two Complex Domains - Healthcare & Tech...
PDF
Accuracy of neural networks in brain wave diagnosis of schizophrenia
PPTX
Tartificialntelligence_presentation.pptx
PDF
Univ-Connecticut-ChatGPT-Presentaion.pdf
PDF
A comparative study of natural language inference in Swahili using monolingua...
PPT
Teaching material agriculture food technology
7 ChatGPT Prompts to Help You Define Your Ideal Customer Profile.pdf
Unlocking AI with Model Context Protocol (MCP)
Digital-Transformation-Roadmap-for-Companies.pptx
Assigned Numbers - 2025 - Bluetooth® Document
Machine learning based COVID-19 study performance prediction
Video forgery: An extensive analysis of inter-and intra-frame manipulation al...
MIND Revenue Release Quarter 2 2025 Press Release
Network Security Unit 5.pdf for BCA BBA.
Blue Purple Modern Animated Computer Science Presentation.pdf.pdf
Encapsulation_ Review paper, used for researhc scholars
1. Introduction to Computer Programming.pptx
cloud_computing_Infrastucture_as_cloud_p
Heart disease approach using modified random forest and particle swarm optimi...
TLE Review Electricity (Electricity).pptx
Architecting across the Boundaries of two Complex Domains - Healthcare & Tech...
Accuracy of neural networks in brain wave diagnosis of schizophrenia
Tartificialntelligence_presentation.pptx
Univ-Connecticut-ChatGPT-Presentaion.pdf
A comparative study of natural language inference in Swahili using monolingua...
Teaching material agriculture food technology

Password Synchronization

  • 1. Understanding PortalGuard’s Server-based Password Synchronization: Managing Multiple Passwords Highlighting the Self-service Password Reset Layer of the PortalGuard Platform
  • 2. By the end of this tutorial you will be able to… • How PortalGuard can help you • Understand password synch can be a midpoint between too many passwords and expensive SSO solutions • Learn about PortalGuard’s Server-based Password Synch • See the step-by-step Authentication Process • Know the technical requirements
  • 3. The PortalGuard software is a Contextual Authentication platform which is focused on enhancing usability, while maintaining a balance between security, auditing and compliance for your web, desktop and mobile applications. Usability Security • Single Sign-on • Knowledge-based • Password Management • Two-factor Authentication • Password Synchronization • Contextual Authentication • Self-service Password Reset • Real-time Reports/Alerts
  • 4. Before going into the details… • Configurable by user, group or domain hierarchy • Comprehensive solution supporting multiple directories • Enables self-service password reset, recovery and account unlock • Force user enrollment (optional) • Active Directory Password Filter (optional) • Cost effective and competitively priced • Easy to implement
  • 8. • Single password, single interface • Cost effective • Easier implementation • Flexible • Force enrollment • Server-based • No client-side software required • Self-service Password Reset Password Synch
  • 9. The process of password synchronization… Correlates the passwords for multiple user accounts
  • 10. Password Complexity Challenges Step One: Identifying Password Complexity Rules Rules differ from system to system causing a common hurdle to implementing password synch… Step Two: Change Password Rules on Systems WARNING: Microsoft AD: no maximum password length or prevent specific characters IBM System i: typically maximum length of 10 with special character limitations
  • 11. Multiple Directories (including MS Active Directory, Novell eDirectory, IBM System i, LDAP v3-compliant, and custom SQL user tables ) Self-service Password Reset Real-time synch Consistent set of password rules Active Directory Password Filter
  • 12. Features: • Ability to link a user’s primary account to accounts on multiple systems/directories • All password changes, resets and account unlocks through PortalGuard flow to all linked systems in real-time • Aligns password complexity rules to reduce barriers to password propagation • Requirement to link accounts is policy driven which can be specific to the user, group or domain hierarchy • Account linking can be enforced or made optional • Supports multiple user account repositories
  • 13. • Password Synch - eliminate the need for users to remember different passwords • Ease of Use - manage passwords from single consistent interface • Self-service - unlock accounts and reset passwords from one place • Seamless Integration - with existing logins using “sidecar” mode • Lower Costs - reduce password-related calls and required IT support • Increased Productivity - and user adoption for new services/websites
  • 15. How to link an account…. Step 1: the user logs into a Windows workstation or an existing internal website. PortalGuard is notified of the logon and checks its policies to see if the user: • Is required to link to an account in another directory, and • If they have yet to do so
  • 16. How to link an account…. Step 2: Once the user provides the correct password, the secondary account password will be immediately synched with the primary if necessary
  • 17. Step 1: The user has forgotten their password and clicks “Forgot Password?” link on the Windows logon screen or website logon page
  • 18. Step 2: The user chooses to reset their forgotten password and proves their identity by correctly answering a series of challenge Q&A or entering an OTP
  • 19. Step 3: The user enters a new password that satisfies all linked account systems. The PortalGuard server resets all linked accounts to use this password and unlocks the accounts as well.
  • 20. Step 4: Immediate feedback is given to the user that the password reset was successful on all linked accounts.
  • 21. Configurable through the PortalGuard Configuration Utility: • Password Synchronization • Password Policies: • Dictionary Words • Regular Expressions • Password History • Minimum Length • Maximum Length • Minimum: • Lowercase characters • Uppercase characters • Numeric characters • Non-alphanumeric characters • Enforce AD Complexity • Password Rule Grouping • Password Strength Meter
  • 22. TECHNICAL REQUIREMENTS PortalGuard Desktop – for Windows workstations Sidecar Mode – enforce account linking on existing website AD Password Filter – enforce custom password policy for native Ctrl+Alt+Del Windows password changes
  • 23. A MSI is used to install PortalGuard on IIS 6 or 7.x. This version of PortalGuard supports direct access and authentication to cloud/browser-based applications, only. • Microsoft Active Directory – Windows 2000 AD domain or later • Novell eDirectory 8.7 or later • IBM System i - V5R2 or later • Any LDAP v3-compliant directory • Custom SQL user tables • Microsoft Windows Server 2000 • Microsoft Windows Server 2003 (32 or 64-bit) • Microsoft Windows Server 2008 (32 or 64-bit) • Microsoft Windows Server 2008 R2 • Windows Terminal Services on Win2003 • Remote Desktop Services on Win2008 • IBM WebSphere/WebSphere Portal v5.1 or higher • Microsoft IIS 6.0 or higher • Microsoft Windows SharePoint Services 3.0 or higher • Microsoft Office SharePoint Server 2007 or later
  • 24. THANK YOU For more information visit PortalGuard.com or Contact Us