1 Introduction... 3 2 Product overview... 4. 2.1 Product description... 4. 3 System requirements... 7. 3.1 Software support... 7



Similar documents
Securing Administrator Access to Internal Windows Servers

Using RD Gateway with Azure Multifactor Authentication

Course MS20694A Virtualizing Enterprise Desktops and Apps. Length: 5 Days

Compiled By: Chris Presland v th September. Revision History Phil Underwood v1.1

SSM6437 DESIGNING A WINDOWS SERVER 2008 APPLICATIONS INFRASTRUCTURE

ADVANCED TWO-FACTOR AUTHENTICATION VIA YOUR MOBILE PHONE

KEYSTROKE DYNAMIC BIOMETRIC AUTHENTICATION FOR WEB PORTALS

TECHNOLOGY LEADER IN GLOBAL REAL-TIME TWO-FACTOR AUTHENTICATION

External Authentication with Windows 2012 R2 Server with Remote Desktop Web Gateway Authenticating Users Using SecurAccess Server by SecurEnvoy

OVERVIEW. DIGIPASS Authentication for Office 365

Requirements Collax Security Gateway Collax Business Server or Collax Platform Server including Collax SSL VPN module

TECHNOLOGY LEADER IN GLOBAL REAL-TIME TWO-FACTOR AUTHENTICATION

IGEL Linux and Microsoft Remote Desktop Connection Broker 2012 R2

Virtualizing Enterprise Desktops and Apps

STRONGER AUTHENTICATION for CA SiteMinder

Owner of the content within this article is Written by Marc Grote

PortWise Access Management Suite

Microsoft Virtualizing Enterprise Desktops and Apps

Mod 2: User Management

Cisco ASA Adaptive Security Appliance Single Sign-On: Solution Brief

Implementing and Managing Microsoft Desktop Virtualization

ZyWALL OTPv2 Support Notes

Microsoft Azure Multi-Factor authentication. (Concept Overview Part 1)

Remote Desktop Web Access. Using Remote Desktop Web Access

Keeping your VPN protected

Hosting topology SMS PASSCODE 2015

External Authentication with Citrix Secure Gateway - Presentation server Authenticating Users Using SecurAccess Server by SecurEnvoy

F5 BIG-IP: Configuring v11 Access Policy Manager APM

REMOTE DESKTOP WEB PORTAL (RD Web) ACCESS GUIDE Updated 12/30/2013

Password Power 8 Plug-In for Lotus Domino Single Sign-On via Kerberos

Contextual Authentication: A Multi-factor Approach

External authentication with Astaro AG Astaro Security Gateway UTM appliances Authenticating Users Using SecurAccess Server by SecurEnvoy

Authentication. Authentication in FortiOS. Single Sign-On (SSO)

Quest Soft Token for Windows Phone User Guide

Integrating VMware Horizon Workspace and VMware Horizon View TECHNICAL WHITE PAPER

How To Integrate Watchguard Xtm With Secur Access With Watchguard And Safepower 2Factor Authentication On A Watchguard 2T (V2) On A 2Tv 2Tm (V1.2) With A 2F

Microsoft Office365 with Active Directory Federated Services (ADFS) Authenticating Users Using SecurAccess Server by SecurEnvoy

HOTPin Integration Guide: Microsoft Office 365 with Active Directory Federated Services

Customizing Remote Desktop Web Access by Using Windows SharePoint Services Stepby-Step

SafeNet Authentication Service

Safety and Health Grant Program Database Remote Access Installation Guide

What s New in Juniper Networks Secure Access (SA) SSL VPN Version 6.4

Publish Cisco VXC Manager GUI as Microsoft RDS Remote App

Out-of-Band Multi-Factor Authentication Cloud Services Whitepaper

Lync SHIELD Product Suite

Administering Windows Server 2012

Implementation Guide for. Juniper SSL VPN SSO with OWA. with. BlackShield ID

DIGIPASS Pack for Citrix on WI 4.5 does not detect a login attempt. Creation date: 28/02/2008 Last Review: 04/03/2008 Revision number: 2

PortWise Access Management Suite

A Guide to New Features in Propalms OneGate 4.0

Defender Token Deployment System Quick Start Guide

Ultra-strong authentication to protect network access and assets

2 factor + 2. Authentication. way

External Authentication with Citrix Access Gateway Advanced Edition

Session 17 Windows 7 Professional DNS & Active Directory(Part 2)

Rohos Logon Key for Windows Remote Desktop logon with YubiKey token

Ultra-strong authentication to protect network access and assets

OTP Server Integration Module

Employee Active Directory Self-Service Quick Setup Guide

Implementing and Managing Microsoft Desktop Virtualization en

External Authentication with Checkpoint R75.40 Authenticating Users Using SecurAccess Server by SecurEnvoy

Single Sign-On: Reviewing the Field

BlackShield ID Agent for Remote Web Workplace

McAfee One Time Password

2 FACTOR + 2. Authentication WAY

Full disk encryption with Sophos Safeguard Enterprise With Two-Factor authentication of Users Using SecurAccess by SecurEnvoy

INTEGRATION GUIDE. DIGIPASS Authentication for Office 365 using IDENTIKEY Authentication Server with Basic Web Filter

Cloud Services ADM. Agent Deployment Guide

Cisco ASA 5500 Series Adaptive Security Appliance 8.2 Software Release

External authentication with Fortinet Fortigate UTM appliances Authenticating Users Using SecurAccess Server by SecurEnvoy

User Guide. Version R91. English

Establishing two-factor authentication with Barracuda NG Firewall and HOTPin authentication server from Celestix Networks

Dell SonicWALL and SecurEnvoy Integration Guide. Authenticating Users Using SecurAccess Server by SecurEnvoy

Technical Brief ActiveSync Configuration for WatchGuard SSL 100

Global Knowledge European Remote Labs Accessing the Remote Labs portal from Windows

USER GUIDE. Lightweight Directory Access Protocol (LDAP) Schoolwires Centricity

Planning and Designing Microsoft Virtualization Solutions

RDP Exploitation using Cain I will demonstrate how to ARP poison a connection between a Windows 7 and Windows 2008 R2 Server using Cain.

Designing a Windows Server 2008 Applications Infrastructure

Implementing Desktop Application Environments

Remote Desktop Services Overview. Prerequisites. Additional References

Owner of the content within this article is Written by Marc Grote

Allianz Global Investors Remote Access Guide

Administering Windows Server 2012

Enhancing Organizational Security Through the Use of Virtual Smart Cards

Department of Veterans Affairs Two-Factor Authentication MobilePASS Quick Start Guide November 18, 2015

Course 6437A: Designing a Windows Server 2008 Applications Infrastructure

How To Create A Virtual Private Cloud On Amazon.Com

External Authentication with Juniper SSL VPN appliance Authenticating Users Using SecurAccess Server by SecurEnvoy

DIGIPASS Authentication for Citrix Access Gateway VPN Connections

External Authentication with Windows 2003 Server with Routing and Remote Access service Authenticating Users Using SecurAccess Server by SecurEnvoy

Two-Factor Authentication

DIGIPASS Authentication for GajShield GS Series

Training module 2 Installing VMware View

Transcription:

Product announcement ----------------------------------------------------------------------------- ASEBA SxS PAAS module ---------------------------------------------------------------------------------------------------------- April 28 th, 2014

Contents 1 Introduction... 3 2 Product overview... 4 2.1 Product description... 4 3 System requirements... 7 3.1 Software support... 7 4 Licensing... 8 5 Contact... 9 SxS PAAS Module v1.0 Page 2

1 Introduction Asseco SEE announces the newest addition to the two-factor authentication product family. ASEBA SxS PAAS module is a Pluggable Authentication and Authorization service which serves as an extension of the ASEBA SxS server to provide two-factor authentication services for Microsoft Virtual Desktop Infrastructure (VDI). By using the ASEBA SxS PAAS module users can use their security authentication tokens (HW tokens, soft tokens, etc.) combined with static credentials to access remote desktops and applications in the Microsoft Virtual Desktop Infrastructure environment. Microsoft Virtual Desktop Infrastructure (VDI) delivers desktops and applications to users on a variety of devices in such a way that applications and data stay in the datacenter so the risk of information loss from lost and stolen devices is reduced. SxS PAAS Module v1.0 Page 3

2 Product overview 2.1 Product description ASEBA SxS PAAS module enables organizations to establish a higher level of security when they are accessing virtual desktops and applications in Microsoft VDI. Besides verification of static domain credentials, a two-factor authentication step has been introduced where users need to enter an OTP (One-time password) generated by their authentication device in the RD Web Access login screen. This ensures a high level of security and protection of sensitive and important data for users that are accessing remote desktops and applications. Figure 1 RemoteApp and Desktop connection login page ASEBA SxS PAAS module utilizes Microsoft PAA framework which defines interfaces for integrating custom authentication and authorization schemes. SxS PAAS Module v1.0 Page 4

Figure 2 RemoteApp and Desktops ASEBA SxS PAAS module is comprised of the following components: SxS RD Gateway module (.dll module) SxS RD Web Access module (.dll module) SxS Cache Server Authentication flow with ASEBA SxS PAAS module and components is as follows: 1. User accesses RD Web access portal and enters his credentials (User name + static password + OTP) 2. SxS RD Web Access module sends user credentials for validation (Static credentials are sent to Active Directory server and OTP to the SxS server) 3. Authenticated user selects a remote application from the application list 4. SxS RD Web Access module then requests a session token from the SxS Cache server 5. SxS Cache server returns the generated session token to the SxS RD Web Access module 6. SxS RD Web Access module generates a RDP file with the session token and sends it to the user 7. On the user side the RDP file is started and session token is sent to the RD Gateway. 8. RD Gateway through the SxS RD Gateway module send the session token to the SxS Cache server for validation 9. If a session token is validated the user is granted access to the remote application Once the session is established the user can use different applications during that valid session (SSO functionality) without the need to authenticate themselves again. SxS PAAS Module v1.0 Page 5

Figure 3 Authentication flow with SxS PAAS modules in VDI SxS PAAS Module v1.0 Page 6

3 System requirements ASEBA SxS PAAS Module is specifically designed to support Microsoft Windows Server 2012 R2. 3.1 Software support SxS PAAS module is supported with the following Asseco products: Product type Product version ASEBA SxS authentication server Version 5.x SxS PAAS Module v1.0 Page 7

4 Licensing SxS PAAS module is subject to the Asseco SEE License Agreement. The Asseco License Agreement authorizes the customer to use the software to support up to the number of licensed users specified in the contract. Therefore, Asseco does not print the authorized numbers of users directly on the License Agreement. The contract is the only legal agreement specifying the number of licensed users. SxS PAAS module is delivered as an add-on license to existing Asseco SEE clients who already have SxS authentication server deployed within their infrastructure or to new clients who need to implement two-factor authentication services for Microsoft VDI with the SxS authentication server. To learn more about Asseco SEE products, services and solutions please contact your local sales representative or our global sales representative listed on page 9 of this document. SxS PAAS Module v1.0 Page 8

5 Contact Address Asseco SEE d.o.o. Ulica grada Vukovara 269d 10000 Zagreb Croatia Web site www.asseco-see.hr www.asseco-see.com E-mail Sales Contact: Technical Contact: info@asseco-see.hr Mario Komljenović Key Account Manager mario.komljenovic@asseco-see.hr Viktor Olujić Head of Authentication viktor.olujic@asseco-see.hr Phone +385-1-30-30-000 Fax +385-1-30-30-010 SxS PAAS Module v1.0 Page 9