Ultra-strong authentication to protect network access and assets



Similar documents
Ultra-strong authentication to protect network access and assets

Proven. Trusted.

Ultra-strong authentication to protect network access and assets

Keeping your VPN protected

Workspot, Inc. RSA SecurID Ready Implementation Guide. Partner Information. Last Modified: September 16, Product Information Partner Name

ADVANCED TWO-FACTOR AUTHENTICATION VIA YOUR MOBILE PHONE

ESET SECURE AUTHENTICATION. Product Manual

TECHNOLOGY LEADER IN GLOBAL REAL-TIME TWO-FACTOR AUTHENTICATION

Authentication Solutions. Versatile And Innovative Authentication Solutions To Secure And Enable Your Business

Mobile Access Software Blade

HOTPin Integration Guide: DirectAccess

STRONGER AUTHENTICATION for CA SiteMinder

Cisco ASA Adaptive Security Appliance Single Sign-On: Solution Brief

Enhanced Single Factor, 2 Factor & Multi-Factor Authentication Solutions

SafeWord 2008 Customer Release Notes

ADAPTIVE USER AUTHENTICATION

TECHNOLOGY LEADER IN GLOBAL REAL-TIME TWO-FACTOR AUTHENTICATION

Using Entrust certificates with VPN

Adaptive User Authentication

Two-Factor Authentication (2FA) Registration Instructions Symantec VIP Access

A brief on Two-Factor Authentication

RSA SecurID Software Token 1.0 for Android Administrator s Guide

HOTPin Integration Guide: Google Apps with Active Directory Federated Services

ADDING STRONGER AUTHENTICATION for VPN Access Control

Citrix Netscaler Advanced guide for SMS PASSCODE SMS PASSCODE 2014

RSA SecurID Two-factor Authentication

ESET SECURE AUTHENTICATION. Cisco ASA SSL VPN Integration Guide

Employee Active Directory Self-Service Quick Setup Guide

WHITEPAPER. SECUREAUTH 2-FACTOR AS A SERVICE 2FaaS

Authentication Solutions VERSATILE AND INNOVATIVE AUTHENTICATION SOLUTIONS TO SECURE AND ENABLE YOUR BUSINESS

SafeNet Authentication Manager Express. Administration Guide All versions

Client side. DESlock + Data Encryption

Strong Authentication in details

External authentication with Fortinet Fortigate UTM appliances Authenticating Users Using SecurAccess Server by SecurEnvoy

BYOD How-To Guide. Securely deliver business applications and data to BYOD using Workspace as a Service

ipad or iphone with Junos Pulse and Juniper SSL VPN appliance Authenticating Users Using SecurAccess Server by SecurEnvoy

CRYPTOCard. Strong Two Factor Authentication

HOTPin Integration Guide: Salesforce SSO with Active Directory Federated Services

These additional levels of security are NOT required if you are using a Derbyshire County Council machine on council premises.

DESlock+ Basic Setup Guide ENTERPRISE SERVER ESSENTIAL/STANDARD/PRO

300% increase 280 MILLION 65% re-use passwords $22 per helpdesk call Passwords can no longer protect you

VMware Horizon View for SMS PASSCODE SMS PASSCODE 2014

HOTPin Integration Guide: Microsoft Office 365 with Active Directory Federated Services

Step by step guide to implement SMS authentication to Cisco ASA Clientless SSL VPN and Cisco VPN

BlackBerry Enterprise Service 10 version 10.2 preinstallation and preupgrade checklist

YubiRADIUS Deployment Guide for corporate remote access. How to Guide

What s New in Juniper Networks Secure Access (SA) SSL VPN Version 6.4

An Introduction to RSA Authentication Manager Express. Helmut Wahrmann

Pulse Connect Secure. Supported Platforms Guide. Product Release 8.1. Document Revision 3.0 Published:

A Symantec Connect Document. A Total Cost of Ownership Viewpoint

CA Adapter. Installation and Configuration Guide for Windows. r2.2.9

OVERVIEW. DIGIPASS Authentication for Office 365

INTEGRATION GUIDE. DIGIPASS Authentication for Office 365 using IDENTIKEY Authentication Server with Basic Web Filter

INTEGRATION GUIDE. DIGIPASS Authentication for Citrix NetScaler (with AGEE)

External authentication with Astaro AG Astaro Security Gateway UTM appliances Authenticating Users Using SecurAccess Server by SecurEnvoy

Out-of-Band Multi-Factor Authentication Cloud Services Whitepaper

VMware Identity Manager Administration

DIGIPASS Authentication for Sonicwall Aventail SSL VPN

Kaspersky Lab Mobile Device Management Deployment Guide

Protect your laptop with ESET Anti-Theft

An Overview of Samsung KNOX Active Directory and Group Policy Features

IDENTIKEY Server DIGIPASS BY VASCO. VASCO s next generation authentication server

INTEGRATION GUIDE. DIGIPASS Authentication for Juniper SSL-VPN

External Authentication with Windows 2003 Server with Routing and Remote Access service Authenticating Users Using SecurAccess Server by SecurEnvoy

ESET SECURE AUTHENTICATION. Cisco ASA Internet Protocol Security (IPSec) VPN Integration Guide

MODERN THREATS DRIVE DEMAND FOR NEW GENERATION MULTI-FACTOR AUTHENTICATION

Dell SonicWALL and SecurEnvoy Integration Guide. Authenticating Users Using SecurAccess Server by SecurEnvoy

BlackBerry Enterprise Service 10. Version: Installation Guide

Deploying iphone and ipad Virtual Private Networks

Citrix Access Gateway Plug-in for Windows User Guide

Implementation Guide for protecting

FortiAuthenticator Agent for Microsoft IIS/OWA. Install Guide

Compatibility Matrix. VPN Authentication by BlackBerry. Version 1.7.1

Pulse Connect Secure. Supported Platforms Guide. Product Release 8.0. Document Revision 2.0 Published:

Establishing two-factor authentication with Cyberoam UTM appliances and HOTPin authentication server from Celestix Networks

Pulse Connect Secure. Supported Platforms Guide. Product Release 8.1. Document Revision 9.0 Published:

Secure your business DIGIPASS BY VASCO. The world s leading software company specializing in Internet Security

Allianz Global Investors Remote Access Guide

Moving Beyond User Names & Passwords

External Authentication with Juniper SSL VPN appliance Authenticating Users Using SecurAccess Server by SecurEnvoy

SingTel VPN as a Service. Quick Start Guide

NETWRIX IDENTITY MANAGEMENT SUITE

Technology Showcase Theatre

Application Note. Intelligent Application Gateway with SA server using AD password and OTP

Replacing legacy twofactor. with YubiRADIUS for corporate remote access. How to Guide

POINT-TO-POINT vs. MEAP THE RIGHT APPROACH FOR AN INTEGRATED MOBILITY SOLUTION

ZyWALL OTPv2 Support Notes

MITEL UNIFIED COMMUNICATOR ADVANCED

Proof of Concept Guide

Sharp Remote Device Manager (SRDM) Server Software Setup Guide

QUICK SELLING GUIDE THE FUTURE OF AUTHENTICATION

Platform support for UNIT4 Milestone 4

A Guide to New Features in Propalms OneGate 4.0

INUVIKA OPEN VIRTUAL DESKTOP FOUNDATION SERVER

Transcription:

Ultra-strong authentication to protect network access and assets ESET Secure Authentication provides powerful authentication to make remote access to the company network and sensitive data safe, but hassle-free. It is a mobile-based solution that uses two-factor, one time password (2FA OTP) authentication for accessing the company s VPN and OWA (Outlook Web App). The advantage of one-time passwords (OTPs) is that they are randomly generated and can t be predicted or reused. ESET Secure Authentication natively supports Outlook Web Access/App for Microsoft Exchange 2007, 2010 and 2013. Native support is also provided for critical endpoints such as the Exchange Control Panel in 2010 and the Exchange Administration Centre in 2013. Use it with a broad range of business tools, including Microsoft SharePoint, and Microsoft Dynamics CRM. Strengthen the protection of your sensitive data accessed from outside the company - via a Remote Desktop Web Access login or VMware Horizon View. Easily implement ESET Secure Authentication to your RADIUS-based services or use the API to integrate it with your existing authentication system based on Active Directory. The solution also supports integration of existing hardware tokens. Moreover, the app comes with an SDK that enables you to implement the solution into any proprietary system, without the need to use Active Directory.

Solves the problem of: How does ESET Secure Authentication work? Employees, upon remotely accessing the company network, receive a one-time password on their mobile phones (or use their current hardware token password). This password is then used to complement and strengthen the usual authentication process. As a result, the company data and assets are protected against intruders, dictionary attacks, password guessing and other forms of cybercrime. The technology used is two-factor, one time password authentication. Two-factor Authentication (2FA) explained As opposed to the standard password authentication, 2FA OTP uses two elements. These are something that the user knows, such as a password or a PIN code, and something that the user has, typically a mobile phone or hardware token. Used in combination, they provide greatly enhanced security for data access. Static passwords that can be intercepted User-created passwords that are not a random combination of characters and can be easily guessed Re-use of passwords intended for access to company assets for private accounts Passwords containing user-specific data e.g. a name, a date of birth Simple patterns to derive new passwords, such as peter1, peter2, etc. Business benefits Helps prevent the risk of breaches with unique passwords for each access Protects from poor password practices Saves costs - no additional hardware needed Easy to migrate to and use Supports existing hardware tokens to meet compliance requirements IT benefits API/SDK for easy integration into proprietary software and business tools App works without internet connection (once downloaded) Works with most VPN appliances Supports most types of mobile operating systems Global technical support in local languages Out-of-the-box solution

A closer look The architecture of ESET Secure Authentication is designed to only use your existing company infrastructure. In addition to the ESET Secure Authentication app on employee mobiles the client side it contains a server application that seamlessly integrates with the familiar network administrator environment of the MMC (Microsoft Management Console) and ADUC (Active Directory Users & Computers). With the authentication API, you can integrate ESET Secure Authentication with an existing authentication system. Moreover, the app s SDK enables integration of the solution into any proprietary system, without the need to use Active Directory. Take advantage of native support of Microsoft Exchange Server 2013, VMware Horizon View, Citrix XenApp and many VPNs. The solution is also easily implemented with hardware tokens (used in place of employee mobile phones). To distribute the ESET Secure Authentication app on mobile phones, all you need to know is the employee phone number. ESET Secure Authentication will send the user an SMS with an activation link. Clicking on the link automatically downloads an installer for that mobile platform. Installation and first initialization ESET back-end ESET back-end 1x SMS Client s authentication server Client s authentication server Provisioning server Provisioning server 1x SMS App download & initialization info App download & initialization info mobile phone mobile phone App download App download App stores / Provisioning server App stores / Provisioning server Client side communication Secured company network OTP Enter OTP Authenticate OTP valid Secured company network OTP Enter OTP Authenticate OTP valid Mobile app installed Mobile app installed computer computer Client s authentication Client s server authentication server Intranet Intranet MS Outlook MS Outlook Access to secured company network granted Access to secured company network granted

Datasheet Two-factor Authentication Mobile-based, two-factor (2FA) one-time password (OTP) authentication for a higher level of security Native protection of Outlook Web App (OWA), Remote Desktop Protocol, VPNs and all RADIUS-based services Native support of Microsoft Exchange and other business tools Software only solution no need to carry additional device or token Convenient for the mobile workforce Support for hardware tokens Client Side (mobile app) One-tap installation, simple and effective user interface Delivery of OTP via client application, SMS or hardware token OTP generation works independently of an available internet connection Compatible with any mobile phone supporting SMS messaging Supports a broad range of mobile operating systems PIN-protected access to prevent fraud in case of device theft or loss Serves multiple OTP zones, e.g. OWA access, VPN access, and others Apps available in these languages: English, German, Russian, French, Spanish, Slovak Server Side Out-of-the-box solution Easy double-click installation and setup The installer automatically recognizes OS and selects all suitable components Custom Integration Options In Active Directory environment, use either ESET Secure Authentication API or User Management API for easy integration into proprietary systems SDK allows for implementation for non-active Directory users Remote Management Supports Microsoft Management Console (MMC) Active Directory integration ESET Secure Authentication extends Active Directory Users & Computers (ADUC plugin) with additional features to enable managing the users two-factor authentication settings

Supported platforms overview Remote Login Platforms Remote Desktop Protocol VPN Protection: Barracuda Cisco ASA F5 FirePass Fortinet FortiGate www.eset.com Copyright 1992 2015 ESET, spol. s r. o. ESET, ESET logo, ESET android figure, NOD32, ESET Smart Security, SysInspector, ThreatSense, ThreatSense.Net, LiveGrid, LiveGrid logo and/or other mentioned products of ESET, spol. s r. o., are registered trademarks of ESET, spol. s r. o. Windows is a trademark of the Microsoft group of companies. Other here mentioned companies or products might be registered trademarks of their proprietors. Produced according to quality standards of ISO 9001:2008. Citrix Access Gateway Juniper Citrix NetScaler Palo Alto Check Point Software Cyberoam SonicWall Contact information: Supported VDI Platforms VMware Horizon View Citrix XenApp Microsoft Web Applications Microsoft Web Applications Microsoft Dynamics CRM 2011, 2013 Outlook Web Access Microsoft SharePoint 2010, 2013 Microsoft Exchange 2010 Outlook Web App Exchange Control Panel Microsoft Remote Desktop Web Access Microsoft Terminal Services Web Access Microsoft Remote Web Access Microsoft Exchange 2013 Outlook Web App Exchange Admin Center Custom Integration Operating Systems (Server Side) ESET Secure Authentication easily integrates with your RADIUS-based services, as well as via the ESET Secure Authentication API or the User Management API to your existing Active Directory-based authentication. Non Active Directory customers with custom systems can use the easy to deploy SDK. Windows Server 2003(32&64bit), 2003 R2 (32&64bit), 2008 (32&64bit), 2008 R2, 2012, 2012 R2 Windows Small Business Server 2008, 2011 Windows Server 2012 Essentials, 2012 R2 Essentials Management tools are also supported on client operating systems from Windows XP SP3 onwards, in both 32-bit and 64-bit versions. Mobile Phone Operating Systems (Client Side App) ios 4.3 or higher (iphone) Android 2.1 or higher Windows Phone 7 or newer Windows Mobile 6 BlackBerry 4.3 to 7.1 and 10 and higher Symbian - all supporting J2ME All J2ME enabled phones For full compatibility details please contact your ESET representative or consult the product manual