Enterprise Single Sign-On User Guide

Size: px
Start display at page:

Download "Enterprise Single Sign-On 8.0.3 User Guide"

Transcription

1 Enterprise Single Sign-On User Guide Advanced Login for Windows

2 Copyright Quest Software and/or its Licensors ALL RIGHTS RESERVED. This publication contains proprietary information protected by copyright. The software described in this publication is furnished under a software license or nondisclosure agreement. This software may be used or copied only in accordance with the terms of the applicable agreement. No part of this publication may be reproduced, stored in a retrieval system or transmitted in any form or by any means, electronic, mechanical or otherwise without the prior written permission of the publisher. DISCLAIMER The information in this publication is provided in connection with Quest branded products from Evidian. No license, express or implied, by estoppel or otherwise, to any intellectual property right is granted by this publication. EXCEPT AS OTHERWISE SPECIFIED IN THE END USER LICENSE AGREEMENT FOR THIS PRODUCT, EVIDIAN AND QUEST ASSUME NO LIABILITY WHATSOEVER AND DISCLAIM ANY EXPRESS, IMPLIED OR STATUTORY WARRANTY RELATING TO THIS PRODUCT, INCLUDING BUT NOT LIMITED TO, THE IMPLIED WARRANTY OF MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE, OR NON-INFRINGEMENT. IN NO EVENT SHALL EVIDIAN OR QUEST BE LIABLE FOR ANY DIRECT, INDIRECT, CONSEQUENTIAL, PUNITIVE, SPECIAL OR INCIDENTAL DAMAGES (INCLUDING, WITHOUT LIMITATION, DAMAGES FOR LOSS OF PROFITS, BUSINESS INTERRUPTION OR LOSS OF INFORMATION) ARISING OUT OF THE USE OR INABILITY TO USE THIS PUBLICATION, EVEN IF EVIDIAN OR QUEST HAVE BEEN ADVISED OF THE POSSIBILITY OF SUCH DAMAGES. Evidian and Quest make no representations or warranties with respect to the accuracy or completeness of the contents of this publication and reserve the right to make changes to specifications and product descriptions at any time without notice. Evidian and Quest do not make any commitment to update the information contained in this publication. The information and specifications in this publication are subject to change without notice. Trademarks Quest, Quest Software, the Quest Software logo, Aelita, AppAssure, Benchmark Factory, Big Brother, DataFactory, DeployDirector, ERDisk, Foglight, Funnel Web, I/Watch, Imceda, InLook, IntelliProfile, InTrust, IT Dad, I/Watch, JClass, Jint, JProbe, LeccoTech, LiteSpeed, LiveReorg, NBSpool, NetBase, Npulse, PerformaSure, PL/Vision, Quest Central, RAPS, SharePlex, Sitraka, SmartAlarm, Spotlight, SQL LiteSpeed, SQL Navigator, SQL Watch, SQLab, Stat, Stat!, StealthCollect, Tag and Follow, Toad, T.O.A.D., Toad World, Vintela, Virtual DBA, Xaffire, and XRT are trademarks and registered trademarks of Quest Software, Inc in the United States of America and other countries. The terms Evidian, AccessMaster, SafeKit, OpenMaster, SSOWatch, WiseGuard, Enatel and CertiPass are trademarks registered by Evidian. All other trademarks mentioned in this document are the propriety of their respective owners. World Headquarters, 5 Polaris Way, Aliso Viejo, CA Website: Please refer to our website for regional and international office information. Quest Enterprise SSO Updated January 2010 Software version 8.0.3

3 CONTENTS About This Guide... 3 Access Management... 3 Conventions Overview Advanced Login Usage Operating Modes Using Advanced Login on Windows 2000/XP Systems Welcome Screen Logging on to Windows Logging on to Windows using User Name/Password Logging on to Windows with Smart Cards Logging on to Windows using your Fingers Logging on to Windows Using Your RFID Badge Forcing Cache Update at Logon Displaying Session Information Shutting Down the Workstation Locking/Unlocking the Workstation Locking the Computer Unlocking the Computer Modifying Password or PIN Modifying Password Modifying your PIN Using the Emergency Access (SOS) Resetting Your Password Resetting Your PIN Logging on as an Administrator on a User Session ("Administrator Grace Period") Using Advanced Login on Windows Vista Systems The Initial Authentication Screen Logging on to Windows Vista Authenticating on Windows Vista Using User Name/Password Authenticating on Windows Vista Using Smart Cards Logging on to Windows using your Fingers Locking/Unlocking the Session Locking the Session Unlocking the Session Switching Users Modifying your Password or PIN Modifying your Password Modifying your PIN Using the Emergency Access Resetting Your Password Resetting Your PIN i

4 3.7 Managing Primary Accounts on Your Smart Card Logging on as an Administrator on a User Session ("Administrator Grace Period") 49 A. Advanced Login and Biometrics Configuration A.1 Advanced Login Configuration Parameters A.2 Biometrics Configuration Parameters A.3 Modifying the Authentication Screen Icons (Windows Vista only) About Quest Software, Inc Contacting Quest Software Contacting Quest Support ii

5 User Guide About This Guide Access Management Intended Reader Software/Hardware Required Supported Operating Systems This guide explains how to use Enterprise SSO Advanced Login for Windows User's Guide. Advanced Login end-users. Advanced Login Administrators. Quest Enterprise SSO Advanced Login 8.0 evolution 3 and later versions. For more information about the versions of the required operating systems and software solutions quoted in this guide, please refer to Quest Enterprise SSO Release Notes. Quest Enterprise SSO Advanced Login runs on the following systems: Windows. Linux. 3

6 Quest Enterprise SSO Advanced Login for Windows Conventions In order to help you get the most out of this guide, we have used specific formatting conventions. These conventions apply to procedures, icons, keystrokes and crossreferences. ELEMENT Select Bolded text Italic text Bold Italic text Blue text CONVENTION This word refers to actions such as choosing or highlighting various interface elements, such as files and radio buttons. Interface elements that appear in Quest products, such as menus and commands. Used for comments. Introduces a series of procedures. Indicates a cross-reference. When viewed in Adobe Acrobat, this format can be used as a hyperlink. Used to highlight additional information pertinent to the process being described. Used to provide Best Practice information. A best practice details the recommended course of action for the best result. Used to highlight processes that should be performed with care. + A plus sign between two keystrokes means that you must press them at the same time. A pipe sign between elements means that you must select the elements in that particular sequence. 4

7 User Guide 1. Overview Enterprise SSO Advanced Login is the authentication module of the Enterprise SSO (E-SSO) suite. It enables speedy implementation of connection procedures using authentication mechanisms with physical tokens (smart cards, USB keys, RFID badges) and biometrics, in addition to the standard authentication methods of login/password. 1.1 Advanced Login Usage Enterprise SSO Advanced Login is used to implement strong authentication in the following scenarios of use: Authentication with smart cards or USB keys with Windows workstations, without any need to deploy a PKI compatible with Windows Active Directory certificates. Authentication using non-windows methods, such as biometrics. Authentication of users through an enterprise directory, which is not part of the Windows network. Authentication with RFID badges. 1.2 Operating Modes Enterprise SSO Advanced Login can be configured either in one of the following modes: Client/server mode: users are directly authenticated in Enterprise SSO Console, the advanced access control module. Standalone mode: users are directly authenticated in Active Directory or in any other supported LDAP directories. 5

8 Quest Enterprise SSO Advanced Login for Windows 2. Using Advanced Login on Windows 2000/XP Systems This section describes the E-SSO authentication with Advanced Login on Windows 2000 or Windows XP systems. 2.1 Welcome Screen The Enterprise SSO Advanced Login welcome screen is displayed at workstation startup. It shows the log on methods which are allowed and installed on the workstation. To log on to Windows, you can: Press Ctrl+Alt+Del to connect using your user name/password, as explained in Section 2.2.1, Logging on to Windows using User Name/Password. Insert your smart card or USB key (if any), as explained in Section 2.2.2, Logging on to Windows with Smart Cards. Place your finger on the scanner (if any), as explained in Section 2.2.3, Logging on to Windows using your Fingers. Use your RFID badge (if any), as explained in Section 2.2.4, Logging on to Windows Using Your RFID Badge. Enterprise SSO Advanced Login respects the Ctrl+Alt+Del key combination that you can configure in Windows. 6

9 User Guide 2.2 Logging on to Windows Logging on to Windows using User Name/Password This section explains how to connect to Windows with your user name and password through Active Directory or any other supported directories. 1. In the Welcome window, press Ctrl+Alt+Del. The authentication window appears. If an RFID badge or a smart card is detected by the workstation, the RFID or smart card authentication window appears by default. In this case, press the Esc (Escape) key to open the login/password authentication window. 2. Enter the following information and click OK. User: type your user name. Password: type your password. Connected to: select your domain (Active Directory), or Root (any other directory) or local session. If you open a local session, you will not be protected by the advanced features of Enterprise SSO. If you have a number of accounts in one or more domains, and/or if none of them is known to the Enterprise SSO services, the following window prompts you to select the account to be used. 7

10 Quest Enterprise SSO Advanced Login for Windows The Windows domain definition can be done with the SSOStudio component of SSOWatch: define an application with a Windows application model. For more information on SSOWatch, see Enterprise SSO - SSOWatch Administrator Guide. 3. Select an account and click OK. If the account is unknown, an error message appears, informing you that the system needs to collect your authentication data (login/password) and the data collection window appears. 8

11 User Guide Logging on to Windows with Smart Cards Logging on With a Smart Card Containing Account Data If your account data is enrolled on the smart card, you can log on to your windows session as explained in the following procedure. 1. Press Ctrl+Alt+Del. The authentication window appears. 2. Insert your smart card in the smart card reader. If your card can stored several accounts, the User field lists all the primary accounts stored on the smart card. If there is only one primary account in the card, this primary account is selected. 3. If needed, select the account with which you want to authenticate. 4. Enter the PIN of your smart card and click OK. You do not need to enter your username and domain name as they are already stored on the card when it is created by an Enterprise SSO administrator. If your log on password has expired, a new password is requested. The new password will be stored instead of the old one. If you have defined a password-generation policy in SSOWatch, the new password can be randomly generated. In this case, this screen never appears. 5. If there are several Windows accounts corresponding to the primary account, select an account in the role selection window that appears. The Windows session opens. 9

12 Quest Enterprise SSO Advanced Login for Windows Logging on Using a Blank Smart Card The first time you use a multi-account smart card to logon to your workstation, your account data is necessarily not stored on the smart card yet. The following procedure explains how to enroll your own account on a smart card. The following procedure only applies to smart cards that can handle self-enrolment and multi-accounts. 1. Press Ctrl+Alt+Del. The authentication window appears. 2. Insert your smart card in the smart card reader. As your account is not stored on the smart card yet (first smart card authentication), the User field displays "Smartcard empty: enroll an account". 3. Enter the PIN of your smart card and click OK. As this is the first time you authenticate with this smart card, you are prompted for your log on user name and password (which are stored in the directory). This information will be stored on the smart card and will no longer be requested, unless it is changed through an external procedure (administrator forcing a change, or a change initiated from a workstation not protected by Enterprise SSO Advanced Login). 10

13 User Guide 4. Type the required information and click OK. The account is created on the smart card and the session opens Logging on to Windows using your Fingers Advanced Login can work in three modes to authenticate users using their biometric data: STORE ON PC Mode In this mode, the biometric data is stored on the PC in the Enterprise SSO cache file. The finger replaces the ID/Password. You must enroll yourself on each PC that you connect to. STORE ON SMART CARD Mode In this mode, the biometric data is stored on a smart card. The finger replaces the PIN. STORE ON SERVER Mode In this mode, the biometric data is stored on a server. The finger replaces the ID/Password. 11

14 Quest Enterprise SSO Advanced Login for Windows First Log on To be able to log on to Windows using your finger, you must first enroll your biometric data. Before Starting Make sure the Enterprise SSO finger module is installed on the workstation. A finger reader must be installed on the workstation. The workstation can support only one reader. We strongly recommend that you download the latest: Drivers and licence of your product. Licence for the installation. If you use several finger readers, just plug in the one reader you want to use and restart the computer. For more information on supported biometric devices, see Quest Enterprise SSO Release Notes. If the administrator has configured a validation of your authentication, a second E-SSO user must authenticate him or herself after you. If the Biometric Enrollment tool is not available, modify the SSOWatch installation by selecting the Biometrics Enrollment tool option and restart the computer. Ensure that the Controller is available to be able to enroll in Store on Server Mode. 1. Depending on your biometric authentication mode, do one of the following: Store on PC: log on using your password, as described in Section 2.2.1, Logging on to Windows using User Name/Password. Store on Server: log on using your finger, as described in Section 2.2.3, Logging on to Windows using your Fingers. The Enterprise SSO Biometrics Enrollment tool starts after a successful authentication. 2. If it does not start: display the SSOWatch menu by right-clicking the SSOWatch icon in the notification area and clicking Biometric enrollment. 3. Follow the instructions of the Biometric Enrollment tool. 4. When you have successfully completed the scan of your finger(s), log off and try to log on using the finger print reader, as described in Section , Everyday Log on. There can only be one set of fingers per biometric reader. 12

15 User Guide Everyday Log on This section describes how to log on to Windows using your finger. Depending on your biometric authentication mode (STORE ON PC, STORE ON SMART CARD or STORE ON SERVER), the procedure is slightly different. Before Starting You must have enrolled your biometric data, as described in Section , Everyday Log on. s STORE ON PC Mode Each time you connect yourself to a new workstation in Store On PC mode, you must enroll your biometric data. 1. When the Advanced Login welcome screen appears, place your finger on the scanner. The following window appears: 2. Read the instructions displayed in the Fingerprint field. 3. Depending on your configuration, you log on automatically when your finger is successfully captured. If not, just fill in the User field and click OK. For details on how to enable the automatic validation, see Section A.1, Advanced Login Configuration Parameters. 13

16 Quest Enterprise SSO Advanced Login for Windows STORE ON SMART CARD Mode 1. When the Advanced Login welcome screen appears, insert your smart card in the reader. The following window appears: 2. Either enter your PIN, or place your finger on the scanner. 3. If you have entered your PIN, click OK (if your finger is successfully captured, you log on automatically). STORE ON SERVER Mode 1. When the Advanced Login welcome screen appears, place your finger on the scanner. The following window appears: 14

17 User Guide 2. Read the instructions displayed in the Fingerprint field. Depending on your configuration, you log on automatically when your finger is successfully captured. 3. If you are not logged on automatically, just fill in the User field and click OK. For details on how to enable the automatic validation, see Section A.1, Advanced Login Configuration Parameters. 4. If the authentication fails, you have to enter your ID to update the local cache Logging on to Windows Using Your RFID Badge This section explains how to authenticate with an RFID badge. The following figure illustrates how Enterprise SSO acts depending on the areas in which it detects the RFID badge. Unlock Area Sensor/ Antenna unlock range Session Kept Alive Visibility Area lock range Able to Open/ Unlock Session Locked/ Closed Lock Area 15

18 Quest Enterprise SSO Advanced Login for Windows First Log on Before Starting An RFID reader must be installed on the workstation. 1. Place the RFID badge in the unlock area so that Enterprise SSO detects it. The Advanced Login window appears and tells you that your RFID badge is not assigned. 2. Click OK to validate it. The Enroll an Account window appears. 16

19 User Guide 3. Enter your login and password to associate them with your RFID badge and click OK. If your are authenticated, the session opens. You can have as many RFID badges as you want, this enables you to lend them to other people. You can delete the badge enrollment by blacklisting it in the Administration Console. E-SSO policy cannot block auto-enrollment First Log on with a Smart Card Before Starting E-SSO Advanced Login must be installed on the workstation. An RFID and a Smart Card reader must be installed on the workstation. You must have both RFID badge and Smart Card to log on. If no RFID badge is detected, the RFID badge enrolment will not be suggested the next time you open your Windows session. 1. Insert your Smart Card in the Card reader. Your Smart Card and your RFID badge are detected, the following window appears: 2. Click the Enroll button to enroll your RFID badge. Your RFID badge is now enrolled. 17

20 Quest Enterprise SSO Advanced Login for Windows Everyday Log on 1. Place the RFID badge in the unlock area so that Enterprise SSO detects it. The authentication window appears. If several RFID badges are detected in the unlock area, the RFID owner field lists all the detected RFID badges. You can take your badge back before typing in your password. 2. In the RFID owner field, select the wanted RFID badge, type in your password and click OK. If you have taken your RFID badge back, you have 30 seconds to enter your password and validate. Your session opens Logging on through Citrix/TSE If you want to log on through Citrix/TSE, you must press the SHIFT key when placing your RFID badge in the unlock area Logging out There are two possibilities for logging out: If you have left your RFID badge in the unlock area, retrieve it and the session closes. Not relevant for HID Prox 125kHz badges. 18

21 User Guide If you retrieved your RFID badge when opening the session, you must place it back in the unlock area and retrieve it again to close the session. You can configure how the session closes in the Access Point Profile. If an E-SSO authentication: primary reauthentication, SSOStudio launch etc. is necessary, then placing the RFID badge in the unlock area will not lock the PC. If you have a contact chip badge, you must insert it in the RFID reader Forcing Cache Update at Logon By default, the authentication is done on the existing cache. The following procedure explains how to force the authentication to be done in the target directory and so to update the authentication data in the cache. 1. In the authentication window (whatever the authentication token used), provide your authentication information. 2. Select the Do not use user cache check box and click OK. The authentication is done in the directory and the cache is updated. 2.3 Displaying Session Information You can display your session information at any time as explained in the following procedure. Press Ctrl+Alt+Del. The session information window appears, as illustrated in the following example windows. The main session pieces of data are: The authenticated Enterprise SSO user. The Windows user account used. The date and time the Enterprise SSO session is opened. 19

22 Quest Enterprise SSO Advanced Login for Windows Example Active Directory Session Information Password Authentication The following illustration is an example of an Enterprise SSO Session Information window that appears when authenticating with a password through Active Directory: the Enterprise SSO and Windows accounts correspond to the same user, and you can change your password. Smart card Authentication The following illustration is an example of an Enterprise SSO Session Information window that appears when authenticating with a smart card through Active Directory: the Enterprise SSO and Windows accounts again correspond to the same user, and you can change your PIN. 20

23 User Guide Finger Authentication The following illustration is an example of an Enterprise SSO Session Information window that appears when authenticating with your finger through Active Directory: the Enterprise SSO and Windows accounts correspond to the same user, and the Change your password button is disabled. LDAP Directories (other than Active Directory) Session Information Session data when authenticating with any supported LDAP directory except Active Directory. The Enterprise SSO and Windows accounts are different. 21

24 Quest Enterprise SSO Advanced Login for Windows 2.4 Shutting Down the Workstation The Advanced Login shutdown functionality is the same as with classical Windows sessions. It allows you to: Close the session. Shutdown the workstation. Reboot the workstation. Put the workstation into a sleep state. Put the workstation into a hibernate state (if activated in the system parameters). 1. Press Ctrl+Alt+Del. The session information window appears. 2. Click the Shutdown button The shutdown window appears. 22

25 User Guide 2.5 Locking/Unlocking the Workstation Locking the Computer The Lock state enables you to prevent anybody from using the workstation in your absence. This section describes the possible means to lock a computer. To lock the computer, do one of the following: Press Ctrl+Alt+Del keys and click the Lock computer button. If you have authenticated with a smart card, remove the smart card from the reader (or a USB key from its port) and do not take any action for 10 seconds. The administrator can modify the default workstation behavior when a token is removed, from the Enterprise SSO Console. If the session is not locked at token removal, it means that your administrator has modified this option. If you have authenticated with an RFID badge, place the RFID badge outside the visibility area (lock area). Put the computer into a sleep state. 23

26 Quest Enterprise SSO Advanced Login for Windows Unlocking the Computer A computer can only be unlocked by the user who has locked it (unless it is unlocked using the "Fast-user switching" option). To unlock the computer, you must re-authenticate as at session opening. The authentication method does not necessarily need to be the same as for opening the main session. If you have authenticated with an RFID badge and locked the session by placing the RFID badge outside the unlock area, the session is automatically unlocked if you come back with your RFID badge in the unlock area before the grace period (which has been set by your administrator). A user with administration rights on the workstation can force the closure of a locked administration session. To unlock the computer, do one of the following: Press Ctrl+Alt+Del keys and log on as described in Section 2.2.1, Logging on to Windows using User Name/Password. Insert your smart card (if any) and log on as described in Section 2.2.2, Logging on to Windows with Smart Cards. Place your finger on the scanner (if any) and log on as described in Section 2.2.3, Logging on to Windows using your Fingers. Place your RFID badge inside the unlock area: If the grace period is exceeded, log on as described in Section 2.2.4, Logging on to Windows Using Your RFID Badge. If the grace period is not exceeded, the session is automatically unlocked. The grace period is set by your administrator. 2.6 Modifying Password or PIN If you are allowed to by your administrator, you can change your password or PIN, as explained in the following procedure. This section also explains how to modify the password of another user. 24

27 User Guide Modifying Password This section explains how to modify your own password or the password of another user (if you are allowed to). 1. Open your session as explained in Section 2.2.1, Logging on to Windows using User Name/Password and press Ctrl+Alt+Del. 2. Click the Change a Password button. The change password screen appears. If the change password option has been disabled by your administrator, clicking on Change a Password will have no effect. 3. Enter the information required and click OK. To modify the password of another user, type the following information in the User field: <user domain>\<user name> or <user name>@<domain name> The password is modified in the LDAP directory. 25

28 Quest Enterprise SSO Advanced Login for Windows Modifying your PIN This section explains how to modify the PIN of your smart card. 1. Open your session as explained in Section 2.2.2, Logging on to Windows with Smart Cards and press Ctrl+Alt+Del. 2. Click the Change PIN button. The change PIN screen appears. If the change PIN option has been disabled by your administrator, clicking on Change PIN will have no effect. 3. Enter the information required and click OK. The smart card PIN is modified. 2.7 Using the Emergency Access (SOS) The Emergency Access feature allows you to: Reset your password in case you have forgotten it: see Section 2.7.1, Resetting Your Password. Reset you PIN in case you have forgotten it or to unlock your smart card (only accessible in disconnected mode): see Section 2.7.2, Resetting Your PIN. 26

29 User Guide Resetting Your Password The Reset Password functionality allows you to reset you password in case you have forgotten it. Before Starting To be able to reset your primary password, SSOWatch must be installed on your workstation, and you must have chosen a set of questions (optional) and recorded the associated answers using the E-SSO Emergency Access Wizard (see Appendix Enterprise SSO - Getting Started with SSOWatch. 1. In the session opening window, click the SOS button. The Emergency Access wizard appears. 2. Follow the displayed instructions. If the following window appears, call the Help Desk and give them the displayed challenge, so that it can give you back the administrator challenge. The need to call the Help Desk to reset your password depends on the configuration set by your administrator in the Enterprise SSO Console. You can not use a second time the challenge given by the Help Desk. When the Wizard terminates, your password is reset and a session opens. You can then use the new password for subsequent logon. If the password has been reset in disconnected mode, you will be asked to change it again the next time you connect to the network. 27

30 Quest Enterprise SSO Advanced Login for Windows Resetting Your PIN The Reset PIN functionality allows you to: Reset your PIN in case you have forgotten it. Unlock your smartcard. Restriction The reset PIN feature is only available in disconnected mode (set by the administrator). Before Starting To be able to reset your PIN, you must have chosen a set of questions (optional) and recorded the associated answers using the E-SSO Emergency Access initialization Wizard (see Appendix Enterprise SSO - Getting Started with SSOWatch). 1. In the session opening window, click the SOS button. The Emergency Access wizard appears. 2. Follow the displayed instructions: When the following window appears, call the Help Desk and give it the displayed challenge, so that it can give you back the administrator challenge. You can not use a second time the challenge given by the Help Desk. When the Wizard terminates, your PIN is reset and a session opens. You can then use the new PIN for subsequent logon. 28

31 2.8 Logging on as an Administrator on a User Session ("Administrator Grace Period") User Guide An administrator can log on a user's session using his own smart card, even though the user opened his Windows session using a smart card. 1. Press the Shift key during the logged user smart card withdrawal. The user session is left unchanged. If the SSOWatch engine was running, it is automatically set to a locked mode. 2. Insert your administrator smartcard and enter your PIN before the end of the grace period (the default value is 60 seconds). The length of the grace period can be configured from the Enterprise SSO Console. This authentication allows E-SSO to verify your identification data. The user Windows session stays open, so your Windows permissions do not apply. 3. Perform your administration tasks on the user workstation: if you run an E- SSO application (Enterprise SSO Studio, ), the authentication is done using your administrator smart card. 4. When you are finished with the user's workstation, withdraw your smart card The user session appears as it was before the smart card removal. The user is prompted to insert his smart card and provide his PIN code to turn the SSOWatch engine back to the unlocked mode. 29

32 Quest Enterprise SSO Advanced Login for Windows 3. Using Advanced Login on Windows Vista Systems This section describes the E-SSO authentication with Advanced Login on Windows Vista systems. 3.1 The Initial Authentication Screen The initial authentication screen appears when you press Ctrl+Alt+Del at workstation startup, or when you want to switch user. In the following example screen, two sessions are already open. The initial authentication screen shows several tiles corresponding to the log on methods (credential providers) which are allowed and installed on the workstation, and to the users logged on the workstation. On Windows Vista, several users can be logged at the same time on a workstation, but only one session can be active on the workstation. Advanced Login provides the following authentication methods on Windows Vista systems: User name/password authentication (two middle tiles in the example screen). Several users can be logged at the same time on the workstation. The screen shows one tile for each logged user, or if no user is logged, it shows one tile with the name of the last logged user. The "Other User" tile allows another user to open a session. See Section 3.2.1, Authenticating on Windows Vista Using User Name/Password. 30

33 User Guide Smart card authentication (first tile in the example screen): The initial authentication screen shows as many tiles as accounts stored on the smart card. See Section 3.2.2, Authenticating on Windows Vista Using Smart Cards. Biometric authentication (last tile in the example screen) See Section 3.2.3, Logging on to Windows using your Fingers. 3.2 Logging on to Windows Vista Authenticating on Windows Vista Using User Name/Password This section explains how to connect to Windows with your user name and password through Active Directory or any other supported directories. 1. Press Ctrl+Alt+Del. The initial authentication screen appears. 2. If any, click the tile corresponding to your name, or if no tile shows your name, click the Other User tile. The authentication screen appears. The following example window shows the "Other User" authentication tile. 31

34 Quest Enterprise SSO Advanced Login for Windows 3. Do one of the following : To log on to the domain displayed on screen, type you user name and password. To log on to another domain than the one displayed on the screen, type <domain name>\<user name>. If you need to open a local session (you will not be protected by the advanced features of Enterprise SSO), type <workstation name>\<user name>. Click. The Windows session opens Authenticating on Windows Vista Using Smart Cards Logging on With a Smart Card Containing Account Data If your account data is enrolled on the smart card, you can log on to your windows session as explained in the following procedure. 1. Press Ctrl+Alt+Del. The initial authentication screen appears. 2. Insert your smart card in the smart card reader. The initial authentication screen appears, displaying as many tiles as primary accounts stored on the smart card. By default, the tile corresponding to the last primary account used to log on the workstation is selected. If none of the listed primary accounts correspond to the last used primary account, one of the listed primary accounts is randomly selected. If there is only one primary account in the card, this primary account is selected. 32

35 User Guide 3. Enter the PIN of your smart card and click. You do not need to enter your username and domain name as they are already stored on the card when it is created by an Enterprise SSO administrator. If your log on password has expired, a new password is requested. The new password will be stored instead of the old one. 4. If there are several Windows accounts corresponding to the primary account, select an account in the role selection window that appears. The Windows session opens Logging on Using a Blank Smart Card The first time you use a smart card to logon to your workstation, your account data is not stored on the smart card yet. The following procedure explains how to enroll your own account on the smart card. The following procedure only applies to smart cards that can handle self-enrolment and multi-accounts. 1. Press Ctrl+Alt+Del. The initial authentication screen appears. 2. Insert your smart card in the smart card reader. As your account is not stored on the smart card yet (first smart card authentication), the smart card tile displays "Not assigned". 33

36 Quest Enterprise SSO Advanced Login for Windows 3. Click the "Not assigned" smart card tile. The authentication screen appears. 4. Enter the PIN of your smart card and click. As this is the first time you authenticate with this smart card, you are prompted for your log on user name and password (which are stored in the directory). This information will be stored on the smart card and will no longer be requested, unless it is changed through an external procedure (administrator forcing a change, or a change initiated from a workstation not protected by Enterprise SSO Advanced Login). 5. Type the required information and click OK. The account is created on the smart card and the session opens. 34

37 User Guide Enrolling a New Account on a Smart Card If your smart card can stores several accounts, Advanced Login allows you to enroll new accounts on your smart card, as explained in the following procedure. The account you want to store on the smart card must exist in the users' directory. 1. Press Ctrl+Alt+Del. The initial authentication screen appears. 2. Insert your smart card in the smart card reader. The tile corresponding to the last primary account used to log on the workstation is selected. 3. Enter the PIN of your smart card. 4. Select the Create a new account check box and click. The Windows Account Entry window appears 35

38 Quest Enterprise SSO Advanced Login for Windows 5. Type the required information and click OK. The account is created on the smart card and the Windows session opens Forcing Cache Update at Logon By default, the authentication is done on the existing cache. The following procedure explains how to force the authentication to be done in the target directory and so to update the authentication data in the cache. 1. Insert your smart card in the smart card reader. 2. Click I want to modify login options. The login option window appears. 3. Select the Update User Cache check box and click OK. 36

39 User Guide Logging on to Windows using your Fingers Advanced Login can work in two modes to authenticate users using their biometric data: STORE ON PC Mode In this mode, the biometric data is stored on the PC in the Enterprise SSO cache file. The finger replaces the ID/Password. You must enroll yourself on each PC that you connect to. STORE ON SERVER Mode In this mode, the biometric data is stored on a server. The finger replaces the ID/Password First Log on To be able to log on to Windows using your finger, you must first enroll your biometric data. Before Starting Make sure the Enterprise SSO fingerprint module is installed on the workstation. A fingerprint reader must be installed on the workstation. The workstation can support only one reader. We strongly recommend that you download the latest: Drivers and licence of your product; Licence for the installation. If you use several fingerprint readers, just plug in the one reader you want to use and restart the computer. For more information on supported biometric devices, see Quest Enterprise SSO Release Notes. If the administrator has configured a validation of your authentication, a second E-SSO user must authenticate him or herself after you. If the Biometric Enrollment tool is not available, modify the SSOWatch installation by selecting the Biometrics Enrollment tool option and restart the computer. Ensure that the Controller is available to be able to enroll in Store on Server Mode. 37

40 Quest Enterprise SSO Advanced Login for Windows 1. Log on using your password, as described in Section 3.2.1, Authenticating on Windows Vista Using User Name/Password. The Enterprise SSO Biometric Enrollment tool starts after a successful authentication. 2. If it does not start: display the SSOWatch menu by right-clicking the SSOWatch icon in the notification area and clicking Biometric Enrollment. 3. Follow the instructions of the Biometric Enrollment tool. 4. When you have successfully completed the scan of your finger(s), log off and try to log on using the finger print reader, as described in Section , Everyday Log on. There can only be one set of fingers per biometric reader Everyday Log on This section describes how to log on to Windows using your finger. Depending on your biometric authentication mode (STORE ON PC or STORE ON SERVER), the procedure is slightly different. Before Starting You must have enrolled your biometric data, as described in Section , Everyday Log on. s STORE ON PC Mode Each time you connect yourself to a new workstation in Store on PC mode, you must enroll your biometric data. 1. When the Advanced Login welcome screen appears, place your finger on the scanner. The following tile appears: 38

41 User Guide Depending on your configuration, you log on automatically when your finger is successfully captured. If not, the following window appears: 2. Make sure your Login is correct and click the to validate. For details on how to enable the automatic validation, see Section A.1, Advanced Login Configuration Parameters. STORE ON SERVER Mode 1. When the Advanced Login welcome screen appears, place your finger on the scanner. The following tile appears: 39

42 Quest Enterprise SSO Advanced Login for Windows Depending on your configuration, you log on automatically when your finger is successfully captured. If not, the following window appears: 2. Make sure your Login is correct and click the to validate. If the authentication fails, you have to check your ID. If it is not the right one, enter the correct ID. For details on how to enable the automatic validation, see Section A.1, Advanced Login Configuration Parameters Forcing Cache Update at Logon By default, the authentication is done on the existing cache. The following procedure explains how to force the authentication to be done in the target directory and so to update the authentication data in the cache. This is only available if Automatic Validation is disabled by the Administrator in the Enterprise SSO Console Administrator Guide. 40

43 User Guide 1. After choosing the tile, click I want to modify login options. The Login Options window appears. 2. Select the Update User Cache check box and click OK. 3.3 Locking/Unlocking the Session Locking the Session The Lock state enables you to prevent anybody from accessing your session on the workstation in your absence. This section describes the possible means to lock a computer. When your session is open, do one of the following to lock the computer: Press Ctrl+Alt+Del keys and click the Lock this computer option. If you have authenticated with a smart card, remove the smart card from the reader (or a USB key from its port). The default workstation behavior when a token is removed can be modified by the administrator from the Enterprise SSO Console. If the session is not locked at token removal, it means that your administrator has modified this option. Put the computer into a sleep state. The workstation gets in the lock state and the "Ctrl+Alt+Del" screen appears. 41

44 Quest Enterprise SSO Advanced Login for Windows Unlocking the Session To unlock the computer, you must re-authenticate as at session opening. The authentication method does not necessarily need to be the same as for opening the main session. If a station is in the locked state, another user can unlock it by login on with its own credentials, without unlocking the first user locked session. Unlocking Your own Session 1. To unlock the session you have locked, press Ctrl+Alt+Del. The authentication screen corresponding to the authentication method used appears. The following example screen shows the unlock authentication screen for a user authenticated with a smart card. 2. Enter your PIN or password and click. Your session is unlocked. 42

45 User Guide Logging on a Workstation Locked by Someone Else 1. To log on a workstation locked by someone else, press Ctrl+Alt+Del. The authentication screen corresponding to the authentication method used by the other user to lock his/her session appears. 2. Click the Other Credentials button. 3. Click the Switch User button. The initial authentication screen appears. 4. Log on to the workstation as explained in Section 3.2, Logging on to Windows Vista. 3.4 Switching Users This section explains how to rapidly switch users on a workstation. When a session is open, press Ctrl+Alt+Del and click the Switch User option. The initial authentication screen appears and another user can log on the workstation. The first user session stays locked on the workstation. 3.5 Modifying your Password or PIN If you are allowed to by your administrator, you can change your password or PIN, as explained in the following procedure Modifying your Password If you have authenticated with your smart card, you can modify the password of the account that you have used to authenticate, as explained in the following procedure. The password will be modified on the smart card and in the directory. If you have authenticated using your user name and password, you can modify your password as explained in the following procedure. 43

46 Quest Enterprise SSO Advanced Login for Windows 1. Open your session as explained in Section 3.2.1, Authenticating on Windows Vista Using User Name/Password and press Ctrl+Alt+Del. 2. Click the Change a Password option. The change password screen appears. If the change password option has been disabled by your administrator, clicking on Change a Password will have no effect. The following example screen shows a change password screen for a user authenticated with a smart card. 3. Enter the information required and click. The password is modified on your smart card (if you have logged on with a smart card) and in the LDAP directory. 44

47 User Guide Modifying your PIN The Advanced Login Credential Manager feature is automatically started at logon time and allows you to change your PIN. 1. Open a Windows session as explained in Section 3.2.2, Authenticating on Windows Vista Using Smart Cards. 2. In the Notification area, right click the icon and select Change PIN. The change PIN screen appears. 3. Enter the required information and click OK. The smart card PIN is modified. 3.6 Using the Emergency Access The Emergency Access feature allows you to: Reset your password in case you have forgotten it: see Section 3.6.1, Resetting Your Password. Reset you PIN in case you have forgotten it or to unlock your smart card (only accessible in disconnected mode): see Section 3.6.2, Resetting Your PIN. 45

48 Quest Enterprise SSO Advanced Login for Windows Resetting Your Password The Reset Password functionality allows you to reset you password in case you have forgotten it. Before Starting To be able to reset your primary password, SSOWatch must be installed on your workstation, and you must have chosen a set of questions (optional) and recorded the associated answers using the E-SSO Emergency Access Wizard (see Enterprise SSO - Getting Started with SSOWatch). 1. In the authentication screen, click I have forgotten my password. If the I have forgotten my password option does not appears on the screen, it means that your administrator has disabled it (see Section A.1, Advanced Login Configuration Parameters for more details). The Reset password wizard appears. 2. Follow the displayed instructions. If the following window appears, call the Help Desk before the end of the two minutes during which the Exchange with help desk window stays open. Give them the displayed challenge, so that they can give you back the administrator challenge. You cannot use a second time the challenge given by the Help Desk. The need to call the Help Desk to reset your password depends on the configuration set by your administrator in the Enterprise SSO Console. When the Wizard terminates, your password is reset and a session opens. You can then use the new password for subsequent logon. If the password has been reset in disconnected mode, you will be asked to change it again the next time you connect to the network. 46

49 User Guide Resetting Your PIN The Reset PIN functionality allows you to: Reset your PIN in case you have forgotten it. Unlock your smartcard. Restriction The reset PIN feature is only available in disconnected mode (set by the administrator). Before Starting To be able to reset your PIN, you must have chosen a set of questions (optional) and recorded the associated answers using the E-SSO Emergency Access initialization Wizard (see Enterprise SSO - Getting Started with SSOWatch). 1. In the authentication screen, click I have forgotten my PIN. If the I have forgotten my PIN option does not appears on the screen, it means that your administrator has disabled it (see Section A.1, Advanced Login Configuration Parameters for more details. The Reset PIN wizard appears. 2. Follow the displayed instructions: When the following window appears, call the Help Desk before the end of the 2 minutes during which the Exchange with help desk window stays open. Give them the displayed challenge, so that they can give you back the administrator challenge. You can not use a second time the challenge given by the Help Desk. When the Wizard terminates, your PIN is reset and a session opens. You can then use the new PIN for subsequent logon. 47

50 Quest Enterprise SSO Advanced Login for Windows 3.7 Managing Primary Accounts on Your Smart Card The Advanced Login Credential Manager feature is automatically started at logon time and allows you among other actions to delete or create a primary account on a smart card. The following procedure only applies to smart cards that can store several SSO accounts. You can delete all the accounts stored on the smart card, even the one you used to logon. In this case, after the account deletion, the session stays open. Do not lock it because you won't be able to unlock it. 1. Open your session as explained in Section 3.2.2, Authenticating on Windows Vista Using Smart Cards. 2. In the Notification area, right click the icon and select Manage Primary Accounts. The account management window appears and lists the accounts stored on the smart card. If you delete the account that you have used to logon, the session will stay open: do not lock it because you won't be able to unlock it. We recommend you to log off the session after the account deletion. Select the account you want to add or remove and click the Add or Remove button. Follow the displayed instructions and click OK. The account is created or removed on the smart card. 48

51 3.8 Logging on as an Administrator on a User Session ("Administrator Grace Period") User Guide An administrator can log on a user s session using his own smart card, even though the user opened his Windows session using a smart card. 1. Press the SHIFT key during the logged user smart card withdrawal. The user session is left unchanged. If the SSOWatch engine was running, it is automatically set to a locked mode. 2. Insert your administrator smart card and enter your PIN before the end of the grace period, the default value being 60 seconds. The length of the grace period can be configured from the Enterprise SSO Console. This authentication enables E-SSO to check your identification data. The user Windows session stays open, so your Windows permissions do not apply. 3. Perform your administration tasks on the user workstation: if you run an E- SSO application (Enterprise SSO Studio, etc.), the authentication is done using your administrator smart card. 4. When you have finished with the user s workstation, withdraw your smart card. The user session appears as it was before the smart card removal. The user is prompted to insert his smart card and provide his PIN to switch the SSOWatch engine back to the unlocked mode. 49

Enterprise Single Sign-On 8.0.3

Enterprise Single Sign-On 8.0.3 For Internal Use Only Enterprise Single Sign-On 8.0.3 Additional Dedicated Server Instance Copyright 1998-2009 Quest Software and/or its Licensors ALL RIGHTS RESERVED. This publication contains proprietary

More information

Enterprise Single Sign-On 8.0.3 Installation and Configuration Guide

Enterprise Single Sign-On 8.0.3 Installation and Configuration Guide Enterprise Single Sign-On 8.0.3 Installation and Configuration Guide Dedicated Directory Replication Copyright 1998-2009 Quest Software and/or its Licensors ALL RIGHTS RESERVED. This publication contains

More information

Enterprise Single Sign-On 8.0.3. Getting Started with SSOWatch

Enterprise Single Sign-On 8.0.3. Getting Started with SSOWatch Enterprise Single Sign-On 8.0.3 Getting Started with SSOWatch Copyright 1998-2009 Quest Software and/or its Licensors ALL RIGHTS RESERVED. This publication contains proprietary information protected by

More information

2007 Quest Software, Inc. ALL RIGHTS RESERVED. TRADEMARKS. Disclaimer

2007 Quest Software, Inc. ALL RIGHTS RESERVED. TRADEMARKS. Disclaimer What s New 6.7 2007 Quest Software, Inc. ALL RIGHTS RESERVED. This guide contains proprietary information protected by copyright. The software described in this guide is furnished under a software license

More information

Quest Management Agent for Forefront Identity Manager

Quest Management Agent for Forefront Identity Manager Quest Management Agent for Forefront Identity Manager Version 1.0 Administrator Guide 2010 Quest Software, Inc. ALL RIGHTS RESERVED. This guide contains proprietary information protected by copyright.

More information

Enterprise Single Sign-On 8.0.6. SSOWatch Administrator Guide

Enterprise Single Sign-On 8.0.6. SSOWatch Administrator Guide Enterprise Single Sign-On 8.0.6 SSOWatch Administrator Guide 2013 Quest Software, Inc. and/or its Licensors ALL RIGHTS RESERVED. This publication contains proprietary information protected by copyright.

More information

Quest Site Administrator 4.4

Quest Site Administrator 4.4 Quest Site Administrator 4.4 for SharePoint Product Overview 2011 Quest Software, Inc. ALL RIGHTS RESERVED. This guide contains proprietary information, which is protected by copyright. The software described

More information

10.2. Auditing Cisco PIX Firewall with Quest InTrust

10.2. Auditing Cisco PIX Firewall with Quest InTrust 10.2 Auditing Cisco PIX Firewall with Quest InTrust 2010 Quest Software, Inc. ALL RIGHTS RESERVED. This guide contains proprietary information protected by copyright. The software described in this guide

More information

8.0. Quick Start Guide

8.0. Quick Start Guide 8.0 Quick Start Guide 2011 Quest Software, Inc. ALL RIGHTS RESERVED. This guide contains proprietary information protected by copyright. The software described in this guide is furnished under a software

More information

Defender Delegated Administration. User Guide

Defender Delegated Administration. User Guide Defender Delegated Administration User Guide 2012 Quest Software, Inc. ALL RIGHTS RESERVED. This guide contains proprietary information protected by copyright. The software described in this guide is furnished

More information

An Introduction to Toad Extension for Visual Studio. Written By Thomas Klughardt Systems Consultant Quest Software, Inc.

An Introduction to Toad Extension for Visual Studio. Written By Thomas Klughardt Systems Consultant Quest Software, Inc. An Introduction to Toad Extension for Visual Studio Written By Thomas Klughardt Systems Consultant Quest Software, Inc. Contents Introduction... 2 Installation... 3 Creating Projects... 4 Working with

More information

2010 Quest Software, Inc. ALL RIGHTS RESERVED. Trademarks. Third Party Contributions

2010 Quest Software, Inc. ALL RIGHTS RESERVED. Trademarks. Third Party Contributions 4.9 Evaluator Guide 2010 Quest Software, Inc. ALL RIGHTS RESERVED. This guide contains proprietary information protected by copyright. The software described in this guide is furnished under a software

More information

Quick Connect Express for Active Directory

Quick Connect Express for Active Directory Quick Connect Express for Active Directory Version 5.2 Quick Start Guide 2012 Dell Inc. ALL RIGHTS RESERVED. This guide contains proprietary information protected by copyright. The software described in

More information

Direct Migration from SharePoint 2003 to SharePoint 2010

Direct Migration from SharePoint 2003 to SharePoint 2010 Direct Migration from SharePoint 2003 to SharePoint 2010 It s Easy with Quest Migration Manager for SharePoint Written By Alexander Kirillov, Quest Software TECHNICAL BRIEF 2010 Quest Software, Inc. ALL

More information

Quest Site Administrator 4.4

Quest Site Administrator 4.4 Quest Site Administrator 4.4 for SharePoint Quick Start Guide 2011 Quest Software, Inc. ALL RIGHTS RESERVED. This guide contains proprietary information, which is protected by copyright. The software described

More information

Foglight 5.5.4.5 for SQL Server

Foglight 5.5.4.5 for SQL Server Foglight 5.5.4.5 for SQL Server Managing SQL Server Database Systems 2010 Quest Software, Inc. ALL RIGHTS RESERVED. This guide contains proprietary information protected by copyright. The software described

More information

Defender 5.7. Remote Access User Guide

Defender 5.7. Remote Access User Guide Defender 5.7 Remote Access User Guide 2012 Quest Software, Inc. ALL RIGHTS RESERVED. This guide contains proprietary information protected by copyright. The software described in this guide is furnished

More information

Quest ChangeAuditor 4.8

Quest ChangeAuditor 4.8 Quest ChangeAuditor 4.8 Migration Guide Copyright Quest Software, Inc. 2009. All rights reserved. This guide contains proprietary information protected by copyright. The software described in this guide

More information

formerly Help Desk Authority 9.1.3 Upgrade Guide

formerly Help Desk Authority 9.1.3 Upgrade Guide formerly Help Desk Authority 9.1.3 Upgrade Guide 2 Contacting Quest Software Email: Mail: Web site: info@quest.com Quest Software, Inc. World Headquarters 5 Polaris Way Aliso Viejo, CA 92656 USA www.quest.com

More information

formerly Help Desk Authority 9.1.3 HDAccess Administrator Guide

formerly Help Desk Authority 9.1.3 HDAccess Administrator Guide formerly Help Desk Authority 9.1.3 HDAccess Administrator Guide 2 Contacting Quest Software Email: Mail: Web site: info@quest.com Quest Software, Inc. World Headquarters 5 Polaris Way Aliso Viejo, CA 92656

More information

4.0. Offline Folder Wizard. User Guide

4.0. Offline Folder Wizard. User Guide 4.0 Offline Folder Wizard User Guide Copyright Quest Software, Inc. 2007. All rights reserved. This guide contains proprietary information, which is protected by copyright. The software described in this

More information

FOR WINDOWS FILE SERVERS

FOR WINDOWS FILE SERVERS Quest ChangeAuditor FOR WINDOWS FILE SERVERS 5.1 User Guide Copyright Quest Software, Inc. 2010. All rights reserved. This guide contains proprietary information protected by copyright. The software described

More information

Quest ChangeAuditor 5.1 FOR ACTIVE DIRECTORY. User Guide

Quest ChangeAuditor 5.1 FOR ACTIVE DIRECTORY. User Guide Quest ChangeAuditor FOR ACTIVE DIRECTORY 5.1 User Guide Copyright Quest Software, Inc. 2010. All rights reserved. This guide contains proprietary information protected by copyright. The software described

More information

Go Beyond Basic Up/Down Monitoring

Go Beyond Basic Up/Down Monitoring Go Beyond Basic Up/Down Monitoring Extending the Value of SCOM with Spotlight on SQL Server Enterprise and Foglight Performance Analysis for SQL Server Introduction Microsoft Systems Center Operations

More information

Quest ChangeAuditor 5.0. For Windows File Servers. Events Reference

Quest ChangeAuditor 5.0. For Windows File Servers. Events Reference Quest ChangeAuditor For Windows File Servers 5.0 Events Reference 2010 Quest Software, Inc. ALL RIGHTS RESERVED. This guide contains proprietary information protected by copyright. The software described

More information

Taking Unix Identity and Access Management to the Next Level

Taking Unix Identity and Access Management to the Next Level Taking Unix Identity and Access Management to the Next Level Now that you ve taken care of local users and groups what s next? Written by Quest Software, Inc. TECHNICAL BRIEF 2010 Quest Software, Inc.

More information

Dell Statistica Document Management System (SDMS) Installation Instructions

Dell Statistica Document Management System (SDMS) Installation Instructions Dell Statistica Document Management System (SDMS) Installation Instructions 2015 Dell Inc. ALL RIGHTS RESERVED. This guide contains proprietary information protected by copyright. The software described

More information

8.7. Target Exchange 2010 Environment Preparation

8.7. Target Exchange 2010 Environment Preparation 8.7 Target Exchange 2010 Environment Preparation 2011 Quest Software, Inc. ALL RIGHTS RESERVED. This document contains proprietary information protected by copyright. The software described in this document

More information

Dell Statistica 13.0. Statistica Enterprise Installation Instructions

Dell Statistica 13.0. Statistica Enterprise Installation Instructions Dell Statistica 13.0 2015 Dell Inc. ALL RIGHTS RESERVED. This guide contains proprietary information protected by copyright. The software described in this guide is furnished under a software license or

More information

Foglight 5.6.4. Managing SQL Server Database Systems Getting Started Guide. for SQL Server

Foglight 5.6.4. Managing SQL Server Database Systems Getting Started Guide. for SQL Server Foglight for SQL Server 5.6.4 Managing SQL Server Database Systems Getting Started Guide 2012 Quest Software, Inc. ALL RIGHTS RESERVED. This guide contains proprietary information protected by copyright.

More information

Foglight 5.6.5.2. Managing SQL Server Database Systems Getting Started Guide. for SQL Server

Foglight 5.6.5.2. Managing SQL Server Database Systems Getting Started Guide. for SQL Server Foglight for SQL Server 5.6.5.2 Managing SQL Server Database Systems Getting Started Guide 2013 Quest Software, Inc. ALL RIGHTS RESERVED. This guide contains proprietary information protected by copyright.

More information

Foglight for Oracle. Managing Oracle Database Systems Getting Started Guide

Foglight for Oracle. Managing Oracle Database Systems Getting Started Guide Foglight for Oracle Managing Oracle Database Systems Getting Started Guide 2014 Quest Software, Inc. ALL RIGHTS RESERVED. This guide contains proprietary information protected by copyright. The software

More information

Spotlight Management Pack for SCOM

Spotlight Management Pack for SCOM Spotlight Management Pack for SCOM User Guide January 2015 The is used to display data from alarms raised by Spotlight on SQL Server Enterprise in SCOM (System Center Operations Manager). About System

More information

Dell Spotlight on Active Directory 6.8.3. Server Health Wizard Configuration Guide

Dell Spotlight on Active Directory 6.8.3. Server Health Wizard Configuration Guide Dell Spotlight on Active Directory 6.8.3 Server Health Wizard Configuration Guide 2013 Dell Software Inc. ALL RIGHTS RESERVED. This guide contains proprietary information protected by copyright. The software

More information

Dell InTrust 11.0. Preparing for Auditing Microsoft SQL Server

Dell InTrust 11.0. Preparing for Auditing Microsoft SQL Server 2014 Dell Inc. ALL RIGHTS RESERVED. This guide contains proprietary information protected by copyright. The software described in this guide is furnished under a software license or nondisclosure agreement.

More information

Foglight. Foglight for Virtualization, Free Edition 6.5.2. Installation and Configuration Guide

Foglight. Foglight for Virtualization, Free Edition 6.5.2. Installation and Configuration Guide Foglight Foglight for Virtualization, Free Edition 6.5.2 Installation and Configuration Guide 2013 Quest Software, Inc. ALL RIGHTS RESERVED. This guide contains proprietary information protected by copyright.

More information

formerly Help Desk Authority 9.1.2 Quest Free Network Tools User Manual

formerly Help Desk Authority 9.1.2 Quest Free Network Tools User Manual formerly Help Desk Authority 9.1.2 Quest Free Network Tools User Manual 2 Contacting Quest Software Email: Mail: Web site: info@quest.com Quest Software, Inc. World Headquarters 5 Polaris Way Aliso Viejo,

More information

Check Point FDE integration with Digipass Key devices

Check Point FDE integration with Digipass Key devices INTEGRATION GUIDE Check Point FDE integration with Digipass Key devices 1 VASCO Data Security Disclaimer Disclaimer of Warranties and Limitation of Liabilities All information contained in this document

More information

Quest Privilege Manager Console 1.1.1. Installation and Configuration Guide

Quest Privilege Manager Console 1.1.1. Installation and Configuration Guide Quest Privilege Manager Console 1.1.1 Installation and Configuration Guide 2008 Quest Software, Inc. ALL RIGHTS RESERVED. This guide contains proprietary information protected by copyright. The software

More information

8.7. Resource Kit User Guide

8.7. Resource Kit User Guide 8.7 Resource Kit User Guide 2011 Quest Software, Inc. ALL RIGHTS RESERVED. This document contains proprietary information protected by copyright. The software described in this document is furnished under

More information

Foglight. Managing Hyper-V Systems User and Reference Guide

Foglight. Managing Hyper-V Systems User and Reference Guide Foglight Managing Hyper-V Systems User and Reference Guide 2014 Quest Software, Inc. ALL RIGHTS RESERVED. This guide contains proprietary information protected by copyright. The software described in this

More information

Dell One Identity Cloud Access Manager 8.0.1 - How to Configure for SSO to SAP NetWeaver using SAML 2.0

Dell One Identity Cloud Access Manager 8.0.1 - How to Configure for SSO to SAP NetWeaver using SAML 2.0 Dell One Identity Cloud Access Manager 8.0.1 - How to Configure for SSO to SAP NetWeaver using SAML 2.0 May 2015 About this guide Prerequisites and requirements NetWeaver configuration Legal notices About

More information

Dell One Identity Cloud Access Manager 8.0.1 - How to Configure Microsoft Office 365

Dell One Identity Cloud Access Manager 8.0.1 - How to Configure Microsoft Office 365 Dell One Identity Cloud Access Manager 8.0.1 - How to Configure Microsoft Office 365 May 2015 This guide describes how to configure Microsoft Office 365 for use with Dell One Identity Cloud Access Manager

More information

Quick Connect for Cloud Services

Quick Connect for Cloud Services Quick Connect for Cloud Services Version 3.5 Administrator Guide 2013 Quest Software, Inc. ALL RIGHTS RESERVED. This guide contains proprietary information protected by copyright. The software described

More information

2.0. Quick Start Guide

2.0. Quick Start Guide 2.0 Quick Start Guide Copyright Quest Software, Inc. 2007. All rights reserved. This guide contains proprietary information, which is protected by copyright. The software described in this guide is furnished

More information

Secure and Efficient Log Management with Quest OnDemand

Secure and Efficient Log Management with Quest OnDemand Secure and Efficient Log Management with Quest OnDemand TECHNICAL BRIEF 2011 Quest Software, Inc. ALL RIGHTS RESERVED. This document contains proprietary information protected by copyright. No part of

More information

Foglight. Foglight for Virtualization, Enterprise Edition 7.2. Virtual Appliance Installation and Setup Guide

Foglight. Foglight for Virtualization, Enterprise Edition 7.2. Virtual Appliance Installation and Setup Guide Foglight Foglight for Virtualization, Enterprise Edition 7.2 Virtual Appliance Installation and Setup Guide 2014 Quest Software, Inc. ALL RIGHTS RESERVED. This guide contains proprietary information protected

More information

Introduction to Version Control in

Introduction to Version Control in Introduction to Version Control in In you can use Version Control to work with different versions of database objects and to keep the database updated. You can review, manage, compare, and revert to any

More information

Quest SQL Optimizer 6.5. for SQL Server. Installation Guide

Quest SQL Optimizer 6.5. for SQL Server. Installation Guide Quest SQL Optimizer for SQL Server 6.5 2008 Quest Software, Inc. ALL RIGHTS RESERVED. This guide contains proprietary information protected by copyright. The software described in this guide is furnished

More information

ChangeAuditor 6.0. Web Client User Guide

ChangeAuditor 6.0. Web Client User Guide ChangeAuditor 6.0 Web Client User Guide 2013 Quest Software, Inc. ALL RIGHTS RESERVED This guide contains proprietary information protected by copyright. The software described in this guide is furnished

More information

NetIQ Advanced Authentication Framework - Client. User's Guide. Version 5.1.0

NetIQ Advanced Authentication Framework - Client. User's Guide. Version 5.1.0 NetIQ Advanced Authentication Framework - Client User's Guide Version 5.1.0 Table of Contents 1 Table of Contents 2 Introduction 4 About This Document 4 NetIQ Advanced Authentication Framework Overview

More information

Dell One Identity Cloud Access Manager 8.0 - How to Configure vworkspace Integration

Dell One Identity Cloud Access Manager 8.0 - How to Configure vworkspace Integration Dell One Identity Cloud Access Manager 8.0 - How to Configure vworkspace Integration February 2015 This guide describes how to configure Dell One Identity Cloud Access Manager to communicate with a Dell

More information

Migrating Your Applications to the Cloud

Migrating Your Applications to the Cloud Migrating Your Applications to the Cloud How to Overcome the Challenges and Reduce the Costs Written By Quest Software, Inc. Contents Abstract... 2 Introduction... 3 What is the Cloud?... 3 Current and

More information

ChangeAuditor 6.0 For Windows File Servers. Event Reference Guide

ChangeAuditor 6.0 For Windows File Servers. Event Reference Guide ChangeAuditor 6.0 For Windows File Servers Event Reference Guide 2013 Quest Software, Inc. ALL RIGHTS RESERVED. This guide contains proprietary information protected by copyright. The software described

More information

6.7. Quick Start Guide

6.7. Quick Start Guide 6.7 Quick Start Guide 2010 Quest Software, Inc. ALL RIGHTS RESERVED. This guide contains proprietary information protected by copyright. The software described in this guide is furnished under a software

More information

Security Analytics Engine 1.0. Help Desk User Guide

Security Analytics Engine 1.0. Help Desk User Guide 2015 Dell Inc. ALL RIGHTS RESERVED. This guide contains proprietary information protected by copyright. The software described in this guide is furnished under a software license or nondisclosure agreement.

More information

ChangeAuditor 5.6. For Windows File Servers Event Reference Guide

ChangeAuditor 5.6. For Windows File Servers Event Reference Guide ChangeAuditor 5.6 For Windows File Servers Event Reference Guide 2011 Quest Software, Inc. ALL RIGHTS RESERVED. This guide contains proprietary information protected by copyright. The software described

More information

Dell Enterprise Reporter 2.5. Configuration Manager User Guide

Dell Enterprise Reporter 2.5. Configuration Manager User Guide Dell Enterprise Reporter 2.5 2014 Dell Inc. ALL RIGHTS RESERVED. This guide contains proprietary information protected by copyright. The software described in this guide is furnished under a software license

More information

Foglight 5.2.0. Foglight Experience Viewer (FxV) Upgrade Field Guide

Foglight 5.2.0. Foglight Experience Viewer (FxV) Upgrade Field Guide Foglight 5.2.0 Foglight Experience Viewer (FxV) 2009 Quest Software, Inc. ALL RIGHTS RESERVED. This guide contains proprietary information protected by copyright. The software described in this guide is

More information

Deployment Guide 6.7

Deployment Guide 6.7 Deployment Guide 6.7 2007 Quest Software, Inc. ALL RIGHTS RESERVED. This guide contains proprietary information protected by copyright. The software described in this guide is furnished under a software

More information

Eight Best Practices for Identity and Access Management

Eight Best Practices for Identity and Access Management Eight Best Practices for Identity and Access Management BUSINESS BRIEF 2011 Quest Software, Inc. ALL RIGHTS RESERVED. This document contains proprietary information protected by copyright. No part of this

More information

2010 Quest Software, Inc. ALL RIGHTS RESERVED. Trademarks. Third Party Contributions

2010 Quest Software, Inc. ALL RIGHTS RESERVED. Trademarks. Third Party Contributions 4.9 User Guide 2010 Quest Software, Inc. ALL RIGHTS RESERVED. This guide contains proprietary information protected by copyright. The software described in this guide is furnished under a software license

More information

Foglight. Dashboard Support Guide

Foglight. Dashboard Support Guide Foglight Dashboard Support Guide 2013 Quest Software, Inc. ALL RIGHTS RESERVED. This guide contains proprietary information protected by copyright. The software described in this guide is furnished under

More information

7.5 7.5. Spotlight on Messaging. Evaluator s Guide

7.5 7.5. Spotlight on Messaging. Evaluator s Guide 7.5 Spotlight on Messaging 7.5 Evaluator s Guide 2010 Quest Software, Inc. ALL RIGHTS RESERVED. This guide contains proprietary information protected by copyright. The software described in this guide

More information

Dell Recovery Manager for Active Directory 8.6. Quick Start Guide

Dell Recovery Manager for Active Directory 8.6. Quick Start Guide Dell Recovery Manager for Active Directory 8.6 2014 Dell Inc. ALL RIGHTS RESERVED. This guide contains proprietary information protected by copyright. The software described in this guide is furnished

More information

How to Use Custom Site Templates and Definitions supporting Corporate look-and-feel

How to Use Custom Site Templates and Definitions supporting Corporate look-and-feel l 10.3 1.0 Auditing Installation and and Monitoring Configuration Microsoft Guide IIS How to Use Custom Site Templates and Definitions supporting Corporate look-and-feel 2010 Quest Software, Inc. ALL RIGHTS

More information

Quest One Password Manager

Quest One Password Manager Quest One Password Manager Version 5.0 Administrator Guide 2013 Quest Software, Inc. ALL RIGHTS RESERVED. This guide contains proprietary information protected by copyright. The software described in this

More information

formerly Help Desk Authority 9.1.3 HDAccess User Manual

formerly Help Desk Authority 9.1.3 HDAccess User Manual formerly Help Desk Authority 9.1.3 HDAccess User Manual 2 Contacting Quest Software Email: Mail: Web site: info@quest.com Quest Software, Inc. World Headquarters 5 Polaris Way Aliso Viejo, CA 92656 USA

More information

2009 Quest Software, Inc. ALL RIGHTS RESERVED. Trademarks. Disclaimer

2009 Quest Software, Inc. ALL RIGHTS RESERVED. Trademarks. Disclaimer 6.5 User Guide 2009 Quest Software, Inc. ALL RIGHTS RESERVED. This guide contains proprietary information protected by copyright. The software described in this guide is furnished under a software license

More information

Enterprise Self Service Quick start Guide

Enterprise Self Service Quick start Guide Enterprise Self Service Quick start Guide Software version 4.0.0.0 December 2013 General Information: info@cionsystems.com Online Support: support@cionsystems.com 1 2013 CionSystems Inc. ALL RIGHTS RESERVED.

More information

How to Use Custom Site Templates and Definitions supporting Corporate look-and-feel

How to Use Custom Site Templates and Definitions supporting Corporate look-and-feel l 10.3 1.0 Installation Auditing and Configuration Microsoft ISA Server Guide How to Use Custom Site Templates and Definitions supporting Corporate look-and-feel 2010 Quest Software, Inc. ALL RIGHTS RESERVED.

More information

How Password Lifecycle Management Can Save Money and Improve Security

How Password Lifecycle Management Can Save Money and Improve Security How Password Lifecycle Management Can Save Money and Improve Security by Don Jones Quest Software, Inc. WHITE PAPER 2010 Quest Software, Inc. ALL RIGHTS RESERVED. This document contains proprietary information

More information

Quest Migration Manager 3.2

Quest Migration Manager 3.2 Quest Migration Manager 3.2 for SharePoint User Guide 2011 Quest Software, Inc. ALL RIGHTS RESERVED. This guide contains proprietary information, which is protected by copyright. The software described

More information

Security Explorer 9.5. User Guide

Security Explorer 9.5. User Guide 2014 Dell Inc. ALL RIGHTS RESERVED. This guide contains proprietary information protected by copyright. The software described in this guide is furnished under a software license or nondisclosure agreement.

More information

Using Stat with Custom Applications

Using Stat with Custom Applications Using Stat with Custom Applications Written by Quest Software Inc. TECHNICAL BRIEF 2010 Quest Software, Inc. ALL RIGHTS RESERVED. This document contains proprietary information protected by copyright.

More information

Dell InTrust 11.0. Preparing for Auditing and Monitoring Microsoft IIS

Dell InTrust 11.0. Preparing for Auditing and Monitoring Microsoft IIS Preparing for Auditing and Monitoring Microsoft IIS 2014 Dell Inc. ALL RIGHTS RESERVED. This guide contains proprietary information protected by copyright. The software described in this guide is furnished

More information

Object Level Authentication

Object Level Authentication Toad Intelligence Central Version 2.5 New in This Release Wednesday, 4 March 2015 New features in this release of Toad Intelligence Central: Object level authentication - Where authentication is required

More information

VeriSign PKI Client Government Edition v 1.5. VeriSign PKI Client Government. VeriSign PKI Client VeriSign, Inc. Government.

VeriSign PKI Client Government Edition v 1.5. VeriSign PKI Client Government. VeriSign PKI Client VeriSign, Inc. Government. END USER S GUIDE VeriSign PKI Client Government Edition v 1.5 End User s Guide VeriSign PKI Client Government Version 1.5 Administrator s Guide VeriSign PKI Client VeriSign, Inc. Government Copyright 2010

More information

ScriptLogic Desktop Authority Password Self-Service version 4.7 Administrator Guide

ScriptLogic Desktop Authority Password Self-Service version 4.7 Administrator Guide ScriptLogic Desktop Authority Password Self-Service version 4.7 Administrator Guide Password Self-Service 4.7 Administrator Guide ii 2010 Quest Software, Inc. ALL RIGHTS RESERVED. Licensed to ScriptLogic

More information

Using Self Certified SSL Certificates. Paul Fisher. Quest Software. Systems Consultant. Desktop Virtualisation Group

Using Self Certified SSL Certificates. Paul Fisher. Quest Software. Systems Consultant. Desktop Virtualisation Group Using Self Certified SSL Certificates Paul Fisher Systems Consultant paul.fisher@quest.com Quest Software Desktop Virtualisation Group Quest Software (UK) Limited Ascot House Maidenhead Office Park Westacott

More information

DIGIPASS KEY series and smart card series for Juniper SSL VPN Authentication

DIGIPASS KEY series and smart card series for Juniper SSL VPN Authentication DIGIPASS KEY series and smart card series for Juniper SSL VPN Authentication Certificate Based 2010 Integration VASCO Data Security. Guideline All rights reserved. Page 1 of 31 Disclaimer Disclaimer of

More information

Full Disk Encryption Pre-Boot Authentication Reference

Full Disk Encryption Pre-Boot Authentication Reference www.novell.com/documentation Full Disk Encryption Pre-Boot Authentication Reference ZENworks 11 Support Pack 4 Beta April 2015 Legal Notices Novell, Inc., makes no representations or warranties with respect

More information

Dell Statistica. Statistica Document Management System (SDMS) Requirements

Dell Statistica. Statistica Document Management System (SDMS) Requirements Dell Statistica Statistica Document Management System (SDMS) Requirements 2014 Dell Inc. ALL RIGHTS RESERVED. This guide contains proprietary information protected by copyright. The software described

More information

Dell One Identity Cloud Access Manager 8.0.1- How to Configure for High Availability

Dell One Identity Cloud Access Manager 8.0.1- How to Configure for High Availability Dell One Identity Cloud Access Manager 8.0.1- How to Configure for High Availability May 2015 Cloning the database Cloning the STS host Cloning the proxy host This guide describes how to extend a typical

More information

System Requirements and Platform Support Guide

System Requirements and Platform Support Guide Foglight 5.6.7 System Requirements and Platform Support Guide 2013 Quest Software, Inc. ALL RIGHTS RESERVED. This guide contains proprietary information protected by copyright. The software described in

More information

Dell One Identity Cloud Access Manager 7.0.2. Installation Guide

Dell One Identity Cloud Access Manager 7.0.2. Installation Guide Dell One Identity Cloud Access Manager 7.0.2 2014 Dell Inc. ALL RIGHTS RESERVED. This guide contains proprietary information protected by copyright. The software described in this guide is furnished under

More information

ScriptLogic Desktop Authority Password Self-Service version 4.6 Quick Start Guide

ScriptLogic Desktop Authority Password Self-Service version 4.6 Quick Start Guide ScriptLogic Desktop Authority Password Self-Service version 4.6 Quick Start Guide Password Self-Service 4 ii 2010 Quest Software, Inc. ALL RIGHTS RESERVED. Licensed to ScriptLogic Corporation This guide

More information

Foglight 5.5.5. Managing Microsoft Active Directory Installation Guide

Foglight 5.5.5. Managing Microsoft Active Directory Installation Guide Foglight 5.5.5 Managing Microsoft Active Directory 2010 Quest Software, Inc. ALL RIGHTS RESERVED. This guide contains proprietary information protected by copyright. The software described in this guide

More information

Foglight. Managing Java EE Systems Supported Platforms and Servers Guide

Foglight. Managing Java EE Systems Supported Platforms and Servers Guide Foglight Managing Java EE Systems Supported Platforms and Servers Guide 2013 Quest Software, Inc. ALL RIGHTS RESERVED. This guide contains proprietary information protected by copyright. The software described

More information

Dell Client Profile Updating Utility 5.5.6

Dell Client Profile Updating Utility 5.5.6 Complete Product Name with Trademarks Version Dell 5.5.6 April 21, 2015 These release notes provide information about the Dell release. Welcome to What's New Known issues Upgrade and Compatibility System

More information

ActiveRoles 6.9. Replication: Best Practices and Troubleshooting

ActiveRoles 6.9. Replication: Best Practices and Troubleshooting ActiveRoles 6.9 Replication: Best Practices and Troubleshooting 2013 Quest Software, Inc. ALL RIGHTS RESERVED. This guide contains proprietary information protected by copyright. The software described

More information

Active Directory Change Notifier Quick Start Guide

Active Directory Change Notifier Quick Start Guide Active Directory Change Notifier Quick Start Guide Software version 3.0 Mar 2014 Copyright 2014 CionSystems Inc., All Rights Reserved Page 1 2014 CionSystems Inc. ALL RIGHTS RESERVED. This guide may not

More information

Web Portal Installation Guide 5.0

Web Portal Installation Guide 5.0 Web Portal Installation Guide 5.0 2011 Quest Software, Inc. ALL RIGHTS RESERVED. This guide contains proprietary information protected by copyright. The software described in this guide is furnished under

More information

Spotlight Management Pack for SCOM

Spotlight Management Pack for SCOM Spotlight Management Pack for SCOM User Guide March 2015 The Spotlight Management Pack for SCOM is used to display data from alarms raised by Spotlight on SQL Server Enterprise in SCOM (System Center Operations

More information

6.5. Web Interface. User Guide

6.5. Web Interface. User Guide 6.5 Web Interface User Guide 2009 Quest Software, Inc. ALL RIGHTS RESERVED. This guide contains proprietary information protected by copyright. The software described in this guide is furnished under a

More information

6.7. Replication: Best Practices and Troubleshooting

6.7. Replication: Best Practices and Troubleshooting 6.7 Replication: Best Practices and Troubleshooting 2010 Quest Software, Inc. ALL RIGHTS RESERVED. This guide contains proprietary information protected by copyright. The software described in this guide

More information

About Recovery Manager for Active

About Recovery Manager for Active Dell Recovery Manager for Active Directory 8.6.1 May 30, 2014 These release notes provide information about the Dell Recovery Manager for Active Directory release. About Resolved issues Known issues System

More information

Foglight 1.0.0.0. Cartridge for Active Directory Installation Guide

Foglight 1.0.0.0. Cartridge for Active Directory Installation Guide Foglight 1.0.0.0 Cartridge for Active Directory Installation Guide 2010 Quest Software, Inc. ALL RIGHTS RESERVED. This guide contains proprietary information protected by copyright. The software described

More information

ActiveRoles 6.8. Web Interface User Guide

ActiveRoles 6.8. Web Interface User Guide ActiveRoles 6.8 Web Interface User Guide 2012 Quest Software, Inc. ALL RIGHTS RESERVED. This guide contains proprietary information protected by copyright. The software described in this guide is furnished

More information

Microsoft Windows Server 2003 Integration Guide

Microsoft Windows Server 2003 Integration Guide 15370 Barranca Parkway Irvine, CA 92618 USA Microsoft Windows Server 2003 Integration Guide 2008 HID Global Corporation. All rights reserved. 47A3-905, A.1 C200 and C700 December 1, 2008 Crescendo Integration

More information