Identity Management Solutions 101: Password Management
Posted by Ash Motiwala on Tue, Oct 14, 2008
So, you're an IT Manager and need the low down on a new buzzword in the realm of Identity Management, and you need it quick...You've come to the right place! This series is designed especially for you.
This entry is about Password Management. Enjoy!
If you need more details on this and other disciplines in the world of Identity Management, or you'd like to get some other folks from your staff to join in on the fun, you might be interested in an on-site Identity Management Workshop.
Alias:
| Self-Service Password Reset, SSPR, Password Synchronization |
Function:
| Empowering the end user to manage their own passwords (without stickies!). To enable users to reset their own passwords to target systems by first correctly answering a series of challenge/response questions through an application. To enable synchronization of passwords across heterogeneous systems. |
Misc. Facts:
| Password Management capabilities are accomplished by different technologies. Some provisioning vendors will provide this capability, while others provide it as a standalone application. ESSO (Enterprise Single Sign-On) vendors provide this capability, although typically only to Active Directory. |
Business Benefits:
| - Real ROI. According to this article, each call to helpdesk costs the organization $22
- Central place to manage password policy
- Reduce the load on helpdesk by up to 30%
|
Use Cases:
| - After 2 weeks on vacation, a user forgets their password...SSPR!
- An end-user is required to change their Windows password. Changing it changes passwords to all other systems.
- A road warrior is on the road in a hotel, and forgot his/her password. Clicks on the "Forgot my PW" link on the logon screen, and resets the password.
- IVR - Change your password over the phone.
|
High Level Architecture:
| For password management that is bundled with provisioning products, the architecture is very similar to the provisioning architecture. Other components may include a Windows GINA wrapper, and a DLL that sits on Domain Controllers. |
Caveats:
| Most products perform uni-directional synchronizations, which means that if native password resets in target systems are performed, passwords will get out of sync. |