NETWRIX IDENTITY MANAGEMENT SUITE FEATURES AND REQUIREMENTS Product Version: 3.3 February 2013.
Legal Notice The information in this publication is furnished for information use only, and does not constitute a commitment from NetWrix Corporation of any features or functions discussed. NetWrix Corporation assumes no responsibility or liability for the accuracy of the information presented, which is subject to change without notice. NetWrix is a registered trademark of NetWrix Corporation. The NetWrix logo and all other NetWrix product or service names and slogans are registered trademarks or trademarks of NetWrix Corporation. Active Directory is a trademark of Microsoft Corporation. All other trademarks and registered trademarks are property of their respective owners. Disclaimers This document may contain information regarding the use and installation of non-netwrix products. Please note that this information is provided as a courtesy to assist you. While NetWrix tries to ensure that this information accurately reflects the information provided by the supplier, please refer to the materials provided with any non-netwrix product and contact the supplier for confirmation. NetWrix Corporation assumes no responsibility or liability for incorrect or incomplete information provided about non-netwrix products. 2013 NetWrix Corporation. All rights reserved. Page 2 of 10
Table of Contents 1. IDENTITY MANAGEMENT SUITE OVERVIEW... 4 1.1. Key Features and Benefits... 4 1.2. Identity Management Suite Modules... 4 1.3. Identity Management Suite Modules Overview... 5 1.4. Licensing Information... 6 2. SYSTEM REQUIREMENTS... 7 2.1. Hardware Requirements... 7 2.2. Software Requirements... 7 2.3. Requirements to the Managed Environment... 8 A APPENDIX: SUPPORTING DATA... 9 A.1 How to Install IIS on Different Windows Versions... 9 A.2 Related Documentation... 10 Page 3 of 10
1. IDENTITY MANAGEMENT SUITE OVERVIEW 1.1. Key Features and Benefits NetWrix Identity Management Suite comprises the solutions that help organizations solve their most pressing password management and account management issues. These solutions help automate and secure the following tasks: Logon auditing: Automatic consolidation, archiving and reporting on successful and failed logon events from all Active Directory domain controllers, servers and workstations. Restore and reset forgotten passwords: self-service password management eliminates a great number of help-desk calls and eases implementation of password policies. Notify remote users on password expiration: remote (VPN, OWA), as well as Linux and Mac desktops users, who do not have password change prompts, can be notified automatically about expiring passwords by email. Manage account lockouts: account lockout detection, investigation of the root cause and automated resolution. De-provisioning of inactive accounts: inactive users accounts can be tracked and deactivated automatically based on their last logon time. Track changes to AD objects and their attributes: get a summary of all changes to AD objects with the information on what changed where and when. 1.2. Identity Management Suite Modules NetWrix Identity Management Suite 3.3 contains the following modules: NetWrix Inactive Users Tracker 3.0 NetWrix Logon Reporter 2.0 NetWrix Password Expiration Notifier 3.3 NetWrix Password Manager 6.5 NetWrix Account Lockout Examiner 4.1 (Freeware) NetWrix Active Directory Change Reporter 7.2 (Freeware Edition) Page 4 of 10
1.3. Identity Management Suite Modules Overview The table below provides a short description of all NetWrix products forming the Identity Management Suite: Table 1: NetWrix Identity Management Suite Modules Overview Module Inactive Users Tracker Logon Reporter Password Expiration Notifier Password Manager Account Lockout Examiner (Freeware) Active Directory Change Reporter (Freeware Edition) Description A tool for automated tracking of inactive user and computer accounts. The product performs the following tasks: Checks domains or specific organizational units by inquiring all domain controllers, and notifies managers and administrators about accounts that have been inactive for a specified number of days. Automatically deactivates inactive accounts by settings a random password, disabling, deleting or moving them to a specified organizational unit. Automatically consolidates and archives all types of logon events from all Active Directory domain workstations and servers. It collects data from event logs from multiple computers across the network and stores it centrally in a compressed format, enabling convenient analysis and rich reporting capabilities. Product reports reflect successful and failed logons and logoffs for the following event types: interactive, network, batch, service, unlock, network clear text, new credentials, remote interactive, cached interactive, user initiated logoff, account password changes and resets, account lockouts and unlocks. Checks which domain accounts and/or passwords are to expire in a specified number of days and sends notifications to users via email or text messages (SMS). It also generates summary reports that can be delivered to system administrators and/or users managers. The product also allows checking the effects of a password policy change before applying it to the managed domain. A tool for automated password management. The product does the following: Provides end-users with self-service web access to common password management tasks. Allows help-desk operators to manage user accounts and view reports on their status through a simple web interface. Allows administrators to enforce restrictions on what kind of passwords can be used, and to apply security policies and identity verification procedures to the managed domain(s). A client-server application that runs as a service and allows efficient handling of account lockout issues. The product performs the following tasks: Monitors Security event logs on specific domain controllers and detects account lockouts in real-time. Automatically notifies specified recipients on account lockouts. Unlocks accounts on the domain controllers where they were locked (for example, when the service account has been updated, or a network drive has been remapped) and allows Active Directory to replicate this change to other domain controllers. Examines account lockouts for possible lockout reasons and displays examination results in a user-friendly form. An Active Directory auditing solutions that tracks and reports on all changes made to an AD domain. For detailed information and instructions on how to install, configure and use the products forming NetWrix Identity Management Suite, refer to the corresponding documentation (see Page 5 of 10
Appendix A.2 Related Documentation for links or download a complete documentation package from NetWrix Identity Management Suite website page). 1.4. Licensing Information When you install NetWrix Identity Management Suite, the Enterprise Editions of the following modules are installed: Password Manager Password Expiration Notifier Inactive Users Tracker Logon Reporter The Enterprise Editions of all NetWrix products can be evaluated for 20 days. For an unlimited use of the modules integrated in NetWrix Identity Management Suite, you must request the corresponding licenses from NetWrix. The suite also contains two freeware products: Account Lockout Examiner: a free product with no limitations. Active Directory Change Reporter: a Freeware Edition is included in the suite. It has a limited set of features but never expires (see a detailed comparison of the product Freeware and Enterprise Editions). Page 6 of 10
2. SYSTEM REQUIREMENTS 2.1. Hardware Requirements Before installing NetWrix Identity Management Suite 3.2, make sure that your system meets the following hardware requirements: Table 2: NetWrix Identity Management Suite Hardware Requirements Minimum Recommended Processor Intel or AMD 32 bit, 2GHz Intel or AMD 64 bit, 3GHz, 4 Core Memory 512 M 4 G Hard Disk 50 M for each component 2 drives with 50 G of free space (in total) 2.2. Software Requirements The table below lists the software requirements for the NetWrix Identity Management Suite components. The General Requirements section of this table lists the requirements that are common for all NetWrix products included in NetWrix Identity Management Suite. Other sections list the requirements specific to separate products in addition to the general requirements. Make sure that this software has been installed on the corresponding machines before proceeding with the installation. Table 3: NetWrix Identity Management Suite Software Requirements NetWrix Product Required Software General Requirements Windows XP SP3 or above.net Framework 3.5 SP1 Windows Installer 3.1 or above NetWrix Account Lockout Examiner Help-Desk Portal: IIS 6.0 or above* NetWrix Inactive Users Tracker NetWrix Password Expiration Notifier Microsoft Management Console 3.0 or above Note: Microsoft Management Console is included in the Windows XP or above operating systems. NetWrix Password Manager Core Service and Web Application: IIS 6.0 or above* Microsoft Internet Explorer 6.0 or later / Mozilla FireFox 2.0 or later / Apple Safari 2.0 or later / Google Chrome 4.0 or later Password Manager Client: Microsoft Internet Explorer 6.0 or later * For detailed instructions on how to install IIS, refer to Appendix A.1 How to Install IIS on Different Windows Versions. Page 7 of 10
2.3. Requirements to the Managed Environment This section lists the requirements to the target environment that can be monitored and managed with NetWrix products forming NetWrix Identity Management Suite: Active Directory (domain and forest functional levels) Domain controller OS versions: o o o o o Windows Server 2000 SP4 Windows Server 2003 SP2 Windows Server 2003 R2 SP2 Windows Server 2008 SP2 Windows Server 2008 R2 SP1 MS Exchange Server: o MS Exchange Server 2003 o MS Exchange Server 2007 o MS Exchange Server 2010 Page 8 of 10
A APPENDIX: SUPPORTING DATA A.1 How to Install IIS on Different Windows Versions This section provides detailed instructions on how to install Internet Information Services (IIS) on different Windows versions. Procedure 1. It contains the following procedures: To install IIS on Windows XP To install IIS on Windows 2003 To install IIS on Windows 7 / Windows Vista To install IIS on Windows 2008 / 2008 R2 To install IIS on Windows XP 1. Navigate to Start Settings Control Panel Add or Remove Programs. 2. Click on Add/Remove Windows Components. 3. Select Internet Information Services (IIS) and click OK to install this component. Procedure 2. To install IIS on Windows 2003 Procedure 3. Procedure 4. 1. Navigate to Start Settings Control Panel Add or Remove Programs. 2. Click on Add/Remove Windows Components. 3. Double-click Application Server and select Internet Information Services (IIS). Click OK to install this component. To install IIS on Windows 7 / Windows Vista 1. Navigate to Start Control Panel Programs and Features. 2. Double-click Turn Windows features on or off. 3. Select Internet Information Services. 4. Enable the following features prior to the installation: IIS 6 Management Compatibility ASP extension Windows Integrated Authentication Anonymous Authentication ASP.NET To install IIS on Windows 2008 / 2008 R2 1. Navigate to Start Control Panel Programs and Features. 2. Double-click Turn Windows features on or off. 3. Click Add Roles, then Server Roles and select Web Server (IIS). 4. Enable the following features prior to the installation: IIS 6 Management Compatibility Page 9 of 10
ASP extension Windows Integrated Authentication Anonymous Authentication ASP.NET Note: For detailed instructions on how to install the Web Server role, refer to the following article: install the Web Server role, refer to the following article: Installing the Web Server Role. A.2 Related Documentation This section provides links to documentation on all NetWrix products included in NetWrix Identity Management Suite. You can also download a complete documentation package from NetWrix Identity Management Suite website page. Table 4: NetWrix Identity Management Suite Modules Documentation Links Module Name NetWrix Inactive Users Tracker NetWrix Logon Reporter NetWrix Password Expiration Notifier NetWrix Password Manager NetWrix Account Lockout Examiner NetWrix Active Directory Change Reporter Documentation Link Page 10 of 10