1 Hitachi ID Password Manager. 2 Agenda. Managing the User Lifecycle Across On-Premises and Cloud-Hosted Applications



Similar documents
1 Hitachi ID Password Manager. 2 Agenda. Managing the User Lifecycle Across On-Premises and Cloud-Hosted Applications

1 Hitachi ID Suite. 2 Agenda. 3 Corporate. Managing the User Lifecycle Across On-Premises and Cloud-Hosted Applications

1 Hitachi ID Password Manager

Hitachi ID Password Manager Frequently Asked Questions for Network Architects

Hitachi ID Password Manager Frequently Asked Questions for Help Desk Managers

Hitachi ID Password Manager Telephony Integration

Large Scale Password Management With Hitachi ID Password Manager

Integrating Hitachi ID Suite with WebSSO Systems

Self-Service, Anywhere

1 Building an Identity Management Business Case. 2 Agenda. 3 Business Challenges

Hitachi ID Password Manager Deployment Best Practices

1 Maximizing Value. 2 Economics of self-service. Managing the User Lifecycle Across On-Premises and Cloud-Hosted Applications

Secure Management of Access to Privileged Accounts using Hitachi ID Privileged Access Manager

Successful Enterprise Single Sign-on Addressing Deployment Challenges

Approaches to Enterprise Identity Management: Best of Breed vs. Suites

From Password Reset to Authentication Management: the Evolution of Password Management Technology

IBM Tivoli Identity Manager

Password Management Before User Provisioning

Self-Service Active Directory Group Management

P-Synch by M-Tech Information Technology, Inc. ID-Synch by M-Tech Information Technology, Inc.

Password Self-Service for Novell edirectory. Brent McCormick Novell Corporate Technology Strategist

Service Offering: Outsourced IdM Administrator Service

Product overview. CA SiteMinder lets you manage and deploy secure web applications to: Increase new business opportunities

Securing your business

DirX Identity V8.4. Secure and flexible Password Management. Technical Data Sheet

DirX Identity V8.5. Secure and flexible Password Management. Technical Data Sheet

RSA SecurID Two-factor Authentication

WHITEPAPER. SECUREAUTH 2-FACTOR AS A SERVICE 2FaaS

Passlogix Sign-On Platform

Regulatory Compliance Using Identity Management

Oracle Enterprise Single Sign-on Technical Guide An Oracle White Paper June 2009

Security Guide. BlackBerry Enterprise Service 12. for ios, Android, and Windows Phone. Version 12.0

TFS ApplicationControl White Paper

STRONGER AUTHENTICATION for CA SiteMinder

Password Management Buyer s Guide. FastPass Password Manager V 3.3 Enterprise & Service Provider Editions

BlackBerry Enterprise Server for Microsoft Exchange Version: 5.0 Service Pack: 2. Feature and Technical Overview

Mobile Admin Architecture

AD Self-Service Suite for Active Directory

CA SiteMinder. Implementation Guide. r12.0 SP2

Data Replication in Privileged Credential Vaults

> Please fill your survey to be eligible for a prize draw. Only contact info is required for prize draw Survey portion is optional

For Managing Central Deployment, Policy Management, Hot Revocation, Audit Facilities, and Safe Central Recovery.

ManageEngine Password Manager Pro Vs Thycotic Secret Server

ProtectID. for Financial Services

The Benefits of an Industry Standard Platform for Enterprise Sign-On

1 The intersection of IAM and the cloud

Best Practices for Identity Management Projects

Open Directory. Apple s standards-based directory and network authentication services architecture. Features

Critical Issues with Lotus Notes and Domino 8.5 Password Authentication, Security and Management

Administration Guide. BlackBerry Enterprise Service 12. Version 12.0

Authentication: Password Madness

5 Day Imprivata Certification Course Agenda

CA SiteMinder SSO Agents for ERP Systems

Where are Organizations Today? The Cloud. The Current and Future State of IT When, Where, and How To Leverage the Cloud. The Cloud and the Players

ManageEngine (division of ZOHO Corporation) Infrastructure Management Solution (IMS)

RSA Identity Management & Governance (Aveksa)

NETWRIX PASSWORD MANAGER

and the software then detects and automates all password-related events for the employee, including:

An Overview of Samsung KNOX Active Directory and Group Policy Features

Two-Factor Authentication

Identity Management Terminology

White Paper. Anywhere, Any Device File Access with IT in Control. Enterprise File Serving 2.0

Is your mainframe less secure than your file server? Malcolm Trigg Solutions Consultant 24 th February 2016

(A) User Convenience. Password Express Benefits. Increase user convenience and productivity

Leverage Active Directory with Kerberos to Eliminate HTTP Password

2013 AWS Worldwide Public Sector Summit Washington, D.C.

DIGIPASS Authentication for Sonicwall Aventail SSL VPN

Server-based Password Synchronization: Managing Multiple Passwords

Simplify Identity Management with the CA Identity Suite

Guardium Change Auditing System (CAS)

TECHNOLOGY LEADER IN GLOBAL REAL-TIME TWO-FACTOR AUTHENTICATION

How To Make A Multi-Tenant Platform Secure And Secure

1 Introduction to Identity Management. 2 Identity and Access Needs are Ever-Changing

Configuration Guide BES12. Version 12.1

Aurora Hosted Services Hosted AD, Identity Management & ADFS

Mobile Admin Security

ADDING STRONGER AUTHENTICATION for VPN Access Control

Three Ways to Integrate Active Directory with Your SaaS Applications OKTA WHITE PAPER. Okta Inc. 301 Brannan Street, Suite 300 San Francisco CA, 94107

RSA Authentication Manager 8.1 Help Desk Administrator s Guide

Enterprise Single Sign-On

Sun Infrastructure Solution for Network Identity Seamlessly extend secure access to your enterprise fast, with reduced deployment time and cost

Configuration Guide BES12. Version 12.3

Configuration Guide. BlackBerry Enterprise Service 12. Version 12.0

Configuration Guide BES12. Version 12.2

Table of Contents. Page 1 of 6 (Last updated 30 July 2015)

Enterprise Governance and Planning

IBM Tivoli Access Manager for Enterprise Single Sign-On

Preparing for GO!Enterprise MDM On-Demand Service

The Centrify Vision: Unified Access Management

Enterprise IT is complex. Today, IT infrastructure spans the physical, the virtual and applications, and crosses public, private and hybrid clouds.

WHITEPAPER. Identity Access Management: Beyond Convenience

Enterprise Mobility Management Migration Migrating from Legacy EMM to an epo Managed EMM Environment. Paul Luetje Enterprise Solutions Architect

Role Based Identity and Access Management Basic Infrastructure for New Citizen Services and Lean Internal Administration

Citrix MetaFrame Password Manager 2.5

OracleAS Identity Management Solving Real World Problems

Security Specifications

RSA Authentication Manager 8.1 Help Desk Administrator s Guide. Revision 1

Introduction to the EIS Guide

Password Reset PRO INSTALLATION GUIDE

Copyright Giritech A/S. Secure Mobile Access

Transcription:

1 Hitachi ID Password Manager Managing the User Lifecycle Across On-Premises and Cloud-Hosted Applications Integrated Credential Management for Users: Passwords, encryption keys, tokens, smart cards and more. 2 Agenda Hitachi ID corporate overview. Hitachi ID Suite overview. Password problems and Hitachi ID Password Manager benefits. The HiPM solution. Software demonstration. 2015 Hitachi ID Systems, Inc. All rights reserved. 1

3 Hitachi ID Corporate Overview Hitachi ID delivers access governance and identity administration solutions to organizations globally. Hitachi ID solutions are used by Fortune 500 companies to secure access to systems in the enterprise and in the cloud. Founded as M-Tech in 1992. A division of Hitachi, Ltd. since 2008. Over 1200 customers. More than 14M+ licensed users. Offices in North America, Europe and APAC. Partners globally. 2015 Hitachi ID Systems, Inc. All rights reserved. 2

4 Representative Customers 5 Hitachi ID Suite 2015 Hitachi ID Systems, Inc. All rights reserved. 3

6 PM Differentiators Built-in Functionality: Hitachi ID Password Manager Password synchronization Password and PIN reset. HDD crypto key recovery. Enterprise single sign-on. Manage tokens, smart cards. Update locally cached passwords. Others Password reset. Always available: PC web browser, smart phone. PC login screen. Phone call. At work and off-site PC web browser. PC login screen. Only at work. Integrations: 110+ target types. 10+ ITSM ("ticketing") systems. Typically 1 to 10 connectors. No ticketing integration. Scalability: Multi-master, active-active, replicated. Load balanced, geographically distributed. Automatically discover users, manage enrollment. Single server, single location. Hope users enroll after a big mail blast. 2015 Hitachi ID Systems, Inc. All rights reserved. 4

7 Problem: Too Many Passwords Every login account has its own: Password value. User interface. Strength rules. Expiration date. Password complexity creates business problems: High call volume : Users forget or lock out their passwords. This can be 30% of help desk workload. Sticky notes : Users write down their passwords and may leave them in public view. Bad passwords : Users choose simple, easily guessed passwords. 8 The HiPM Solution Hitachi ID Password Manager addresses the problems that arise from password complexity: Cost savings from simplified password management, rapid deployment, low TCO and fast ROI. Improved security from strong authentication, policy enforcement. Scalability to hundreds of thousands of users. Flexibility to integrate with existing infrastructure. 9 Problem: Password Management Costs End users: Support analysts: System administrators: Lose productivity when they have trouble logging in. Spend much of their time resolving password problem calls. Must be staffed for peak volume after holidays. Resolve escalated password problems. 2015 Hitachi ID Systems, Inc. All rights reserved. 5

10 HiPM Cost Savings Synchronization: Self-service reset: Eliminates 60% to 90% of password problems. When adopted by 40% to 70% of users, diverts problem resolution away from the help desk. Assisted reset: Shortens remaining password reset HD calls by 50% or more, to about 1 minute/call. 11 Problem: Password Security Policy: Authentication: Delegation: Accountability: Encryption: Users prefer easily guessed passwords, write and share passwords. Weak caller authentication prior to HD password resets. Support staff require too many administrative logins. For support staff who perform resets. Passwords should not be sent or stored in the clear. 12 HiPM Security Benefits Policy: Synchronization: Authentication: Delegation: Accountability: Encryption: Hitachi ID Password Manager can enforce over 50 password rules, on every system. No need to write down multiple passwords. Users are identified before being allowed a HD password reset. Support staff no longer require administrative credentials. All password-related events logged. Sensitive data is sent and stored encrypted. 2015 Hitachi ID Systems, Inc. All rights reserved. 6

13 The Hitachi ID Solution is Flexible Customize: Every aspect of the user interface Integrate with: Enforce: 110+ target system types Call tracking systems HR systems Authentication hardware Meta directories IVR servers Password policy Authentication rules 2015 Hitachi ID Systems, Inc. All rights reserved. 7

14 User Interface Flowchart Access Identify Authenticate Action Desktop Web Browser Network Login ID Network Password Update Passwords Workstation Login Prompt E-mail Address Hardware Token Attach Login IDs Smart Phone Employee Number Smart Card Enroll Security Questions Voice Call Answer Security Questions Register Voice Print Biometric Sample (voiceprint) Unlock OTP Device SMS/PIN PIN Reset on Smart Card Unlock Encrypted HDD 2015 Hitachi ID Systems, Inc. All rights reserved. 8

15 Included Connectors Many integrations to target systems included in the base price: Directories: Any LDAP, AD, WinNT, NDS, edirectory, NIS/NIS+. Unix: Linux, Solaris, AIX, HPUX, 24 more variants. ERP: JDE, Oracle ebiz, PeopleSoft, PeopleSoft HR, SAP R/3 and ECC 6, Siebel, Business Objects. WebSSO: CA Siteminder, IBM TAM, Oracle AM, RSA Access Manager. Servers: Windows NT, 2000, 2003, 2008[R2], 2012, Samba, Novell, SharePoint. Mainframes, Midrange: z/os: RACF, ACF2, TopSecret. iseries, OpenVMS. Collaboration: Lotus Notes, inotes, Exchange, GroupWise, BlackBerry ES. Help Desk: ServiceNow, BMC Remedy, SDE, HP SM, CA Unicenter, Assyst, HEAT, Altiris, Clarify, RSA Envision, Track-It!, MS System Center Service Manager Databases: Oracle, Sybase, SQL Server, DB2/UDB, Informix, Progress, ODBC, Oracle Hyperion EPM Shared Services, Cache. HDD Encryption: McAfee, CheckPoint, BitLocker, PGP. Tokens, Smart Cards: RSA SecurID, SafeWord, RADIUS, ActivIdentity, Schlumberger. Cloud/SaaS: WebEx, Google Apps, MS Office 365, Success Factors, Salesforce.com, SOAP (generic). 2015 Hitachi ID Systems, Inc. All rights reserved. 9

16 Rapid Integration with Custom Apps Hitachi ID Password Manager easily integrates with custom, vertical and hosted applications using flexible agents. Each flexible agent connects to a class of applications: API bindings (C, C++, Java, COM, ActiveX, MQ Series). Telnet / TN3270 / TN5250 / sessions with TLS or SSL. SSH sessions. HTTP(S) administrative interfaces. Web services. Win32 and Unix command-line administration programs. SQL scripts. Custom LDAP attributes. Integration takes a few hours to a few days. Fixed cost service available from Hitachi ID. 17 Multi-Master Architecture IVR server VPN server TCP/IP + AES Various Protocols Secure Native Protocol HTTPS Reverse web proxy E-mail system Load balancer Notifications and invitations Incident mgmt system Validate pw Tickets HR SQL DB Hitachi ID server System of record Native password change AD, Unix, OS/390, LDAP, AS400 Load balancer Password synch trigger systems SQL DB Replication Firewall Hitachi ID server Firewall Target systems with local agent: OS/390, unix, older RSA Proxy server (if needed) Data center A Data center B Web services Target systems with remote agent: AD, SQL, SAP, Notes, etc Target Systems Cloud-hosted, SaaS apps Remote Remote data data center center 2015 Hitachi ID Systems, Inc. All rights reserved. 10

18 Scalability and Fault-Tolerance Multiple, load-balanced Hitachi ID Password Manager servers: Active/active architecture. Data replication between nodes: Built-in, easy to configure. WAN-friendly (high latency, low bandwidth, insecure channels). Reliable (multiple retry queues). Proxy servers resolve connection problems: Across firewalls. Over slow, insecure network routes. Large production deployments: 5M users. 130,000 managed systems. 12 load balanced IAM servers. 10,000 completed transactions/hour. 19 Password Synchronization Problem Users have too many passwords: On different systems, with different policies, expiring at different times. Complexity leads users to do bad things: Write down passwords ("sticky notes"). Forget/lock out passwords and call the help desk. Reuse old passwords. Solution Password synchronization pushes password updates from one system to another: Multiple physical passwords. Same value everywhere. Password synchronization allows users to: Remember a single password value. Manage it on a single schedule. Comply with a single password policy. 2015 Hitachi ID Systems, Inc. All rights reserved. 11

20 Transparent Password Synchronization Password synchronization is designed to help users maintain a single, strong password across multiple login IDs. Transparent password synchronization leverages an existing user interface. Users change their passwords natively on: Active Directory. Unix servers. LDAP directories. OS400 / iseries servers. z/os mainframes (RACF, CA-ACF2, CA-TopSecret). Hitachi ID Password Manager enforces a global policy, blocking weak passwords. Approved passwords are synchronized to other accounts belonging to the same user. 21 Transparent Synchronization Architecture User Load Balancer Native password change Start synch. Password Synch Trigger Systems Hitachi ID Identity and Access Management Suite Target Systems with local agent: OS/390, Unix, RSA Target Systems with remote agent TCP/IP + AES Secure Native Protocol 2015 Hitachi ID Systems, Inc. All rights reserved. 12

22 Web Password Synchronization Password synchronization is designed to help users maintain a single, strong password across multiple login IDs. Web password synchronization exposes a new user interface. Access a Web-based password change screen using any browser. Enter a trusted network login ID and password. Select a new password for one or all systems and accounts. Review results from the password update on each system. 23 Web Password Synchronization Architecture User Web Web Load Balancer Hitachi ID Identity and Access Management Suite Target Systems with local agent: OS/390, Unix, RSA Target Systems with remote agent TCP/IP + AES Secure Native Protocol 2015 Hitachi ID Systems, Inc. All rights reserved. 13

24 Prompting Users to Synchronize Users do not volunteer to change their passwords. Hitachi ID Password Manager can identify users who should change their passwords either based on upcoming expiration on a target system, or based on the last HiPM update. Users are asked to change their passwords: By e-mail, with an embedded URL to the HiPM server. By a Web browser, automatically opened during the network login script. 25 Benefits of Password Synchronization Improved user service. Users have fewer password problems, so waste less time with login problems and call the help desk less frequently. New passwords meet global quality standards. All passwords are changed regularly. 26 Self-Service Password Reset Problem Some users continue to forget passwords or trigger lockouts. These users still call the help desk. High call volume is expensive. Solution Self-service password reset enables users to authenticate themselves with something else (a token, biometric, personal questions, etc.) and reset their own password(s). Hitachi ID Password Manager SSPR allows these users to resolve their own problems: This lowers help desk call volume. User service is available 24x7. Accessible via web browser, phone or from the login prompt. 2015 Hitachi ID Systems, Inc. All rights reserved. 14

27 Access from Login Prompt Problem Users who forget their network password cannot launch a Web browser to access the self-service password reset application. Solution Secure Kiosk Account (SKA): access to SSPR without client software ("guest" account). GINA service: access to SSPR from UI extension no GINA DLL. Hitachi ID Phone Password Manager: turn-key telephone access to SSPR. Temporary VPN: access to SSPR from outside the corporate network. 28 Secure Kiosk Account (SKA) Support locked out users without deploying client software. User signs on with the login ID HELP No password is required to sign into the SKA. The SKA account has a special security policy. The policy specifies an alternate to the Windows shell. The Hitachi ID Password Manager shell opens a kiosk-mode Web browser to the self-service password reset Web page. Applies both to on-line and mobile users. Can be used to reset/unlock both local and networked passwords. No browser navigation, controls, border, etc. Closing the browser logs the user off. 2015 Hitachi ID Systems, Inc. All rights reserved. 15

29 GINA Extensions Support locked out users without a "generic" domain account: Extend the Windows Graphical Identification and Authentication (GINA) subsystem, which: is responsible for capturing Ctrl-Alt-Del, presents the login screen and handles screen savers. The Windows GINA can be replaced by third-party DLLs, such as: Novell NetWare. Strong authentication products (smart cards, biometrics, etc.). Hitachi ID Password Manager includes two GINA extension approaches, both of them: Launch a kiosk-mode web browser. Run the browser with an unprivileged account. The first is a GINA wrapper DLL that adds a password reset button in the login prompt. The second is a GINA service program that adds a password reset button without modifying the native GINA DLL. 30 Self-service via Telephone Identification options: Numeric ID (e.g., employee number). Numeric mapping of network login ID. Authentication options: Numeric security questions (e.g., driver s license, DoB). Biometric voice print verification. Hardware token. Features: Password reset / unlock. Token PIN reset. HDD encryption key recovery. Platform options: Use HiTPM (turn-key system). Extend call logic on an existing IVR, using Hitachi ID Password Manager API. Limitations: Cannot reset PINs on smart cards. Cannot update cached credentials on mobile PCs. 2015 Hitachi ID Systems, Inc. All rights reserved. 16

31 Flexible, Secure Authentication Hardware tokens: generated password + keyed PIN. Biometric: voice print, finger print. PKI: smart cards, software certificates. Challenge/response using: Built-in or external data source. Both user-defined and standard questions. A flexible algorithm to validate answers. Multiple sets of multiple questions. Open architecture: Easily integrate with new authentication systems. 32 Benefits of Self-Service Password Reset Savings 40% to 70% of users resolve their own problem, and do not call the help desk. Security Stronger authentication prior to password resets. Reset passwords meet quality controls. Detailed audit trail of authentication attempts, resets. 33 Help Desk Password Reset Problem Even with synchronization and self-service password reset, some users continue to call the help desk. These calls can take 5-15 minutes to resolve and cost $25 $35. Solution Assisted password reset shortens password-related support calls. One process and UI handles everything: Authenticate the analyst. Authenticate the caller. Reset multiple passwords. Clear lockouts. Create/close a support incident (ticket). Reduce call duration to about 1 minutes. Lower incident cost. 2015 Hitachi ID Systems, Inc. All rights reserved. 17

34 Assisted Password Reset Process Help desk analysts use a Hitachi ID Password Manager Web page to: Login (authenticate the analyst). Look up the caller s record. Authenticate the caller. Reset one or more passwords. Automatically create a ticket in the call tracking system. Call resolution time is reduced to 1 2 minutes. Help desk analysts don t require direct access to target systems. 35 Incident, E-mail Integration Open architecture to push event notification to other systems. Simple configuration specifies what events to capture and what actions to take. Binary integration programs are included for: Altiris Assyst BMC Remedy SDE Footprints CA Unicenter Clarify HEAT HP Service Desk ServiceNow Tivoli Track-It! Extensible via SMTP, HTTP(S), XML, ODBC. 2015 Hitachi ID Systems, Inc. All rights reserved. 18

36 HiPM Assisted Service Notes Help desk analysts may: Either see, or be required to type answers to caller-authenticating questions. Either reset passwords, or reset-and-expire passwords. Enable or disable caller access to Hitachi ID Password Manager self-service. Be granted the ability to: See or edit answers to security questions. See or edit login ID profiles data. Manage SecurID tokens. 37 Benefits of Assisted Password Reset Savings Remaining password reset calls are reduced to approximately 1 minute. Security Ensure that callers are always authenticated prior to password resets. Reduce the number of people with administrative rights. Improve accountability for help desk password resets. Enforce password policy over reset passwords. 2015 Hitachi ID Systems, Inc. All rights reserved. 19

38 Impact of Synchronization and SSPR calls problems 2015 Hitachi ID Systems, Inc. All rights reserved. 20

39 RSA SecurID Token Management Problem Users with RSA SecurID tokens forget their PINs, lose their tokens, require clock synchronization, etc. Solution Users can clear, synchronize or reset their token PINs; synchronize their token clocks; enable/disable their tokens or get emergency access passcodes using the Hitachi ID Password Manager self-service token management feature. 40 Token Management Process Users authenticate with a password. Once authenticated, users can: Enable / disable tokens. Request emergency access codes. Clear / set their PIN. Re-synchronize tokens. 41 Benefits of Token Management Savings Fewer, shorter help desk calls for token problems. Security Fewer people with ACE administration privileges. Stronger authentication prior to token support. 2015 Hitachi ID Systems, Inc. All rights reserved. 21

42 Managed User Enrollment Problem Deployment may require new user profile data: Question/answer pairs for authentication. Login ID reconciliation between systems. Biometric samples (e.g., voice prints). Solution Hitachi ID Password Manager includes a managed enrollment system, which identifies users that need to enroll and invites them to do so. 43 Reconcile Login IDs Between Systems Where login IDs are different on some systems, and there is no existing directory, meta directory, matching attribute or map file to connect them, users can be prompted to "claim" their own IDs: Users sign into a secure Hitachi ID Password Manager registration Web page. Users enter a login ID and password. HiPM finds unallocated instances of the login ID in the identity cache and tries to sign into those target systems with the password the user provided. The login ID / target system ID is added to the user s profile if the password worked. 44 Benefits of Managed Enrollment Savings Simple to setup, low-cost data gathering. Security Secure authentication prior to registration. Collect answers to security questions. Correlate login IDs across all systems. Identify orphan accounts. 2015 Hitachi ID Systems, Inc. All rights reserved. 22

45 Rapid Deployment and Low TCO Optimized to minimize effort: HiPM: Initial deployment: 1 2 months. Ongoing maintenance: 0.25 0.5 FTE. Using Hitachi ID Password Manager technology: Built-in discovery, mapping of IDs, entitlements. Managed user enrollment (e.g., Q&A). Client software optional. 110 connectors out of the box (more easy to add). 46 Technology Advantages Unique features "Administration" and "governance" in one product. Access, authorization built around relationships. Self-service from any device, any location. Intercept "Access Denied" errors to simplify requests. "One stop shopping" with implementer workflows. SoD engine detects effective violations. Scalable platform Real-time data replication. Multi-master, active-active. Proxy server to cross firewalls. Native code + stored procedures. Rapid deployment Reference builds accelerate deployment. Key features built-in: Integrations Request forms. Authorization workflow. Access certification. 110+ included connectors. Flexible/scriptable connectors. Incident management/ticketing. SIEM. 2015 Hitachi ID Systems, Inc. All rights reserved. 23

47 HiPM Animated Demonstration The following animations illustrate core Hitachi ID Password Manager user interfaces and processes: Security question enrollment: A user authenticates and completes his personal profile of questions and answers. Alias enrollment: A user attaches non-standard login IDs to his profile. Password expiration: A user is invited, via e-mail, to change soon-to-expire passwords. Self-service password reset (SSPR) using Secure Kiosk Account: A locked out user resolves his own problem, from the login prompt, without client software deployment. SSPR with GINA Extension: A locked out user resolves his own problem, from the login prompt, using a GINA extension. SSPR with Vista credential provider: A locked out user resolves his own problem, from the login prompt, using a Windows Vista credential provider. Assisted password reset: A help desk analyst signs in with an RSA SecurID token and resets a caller s password. PIN Reset for an RSA SecurID token: A user resets his RSA SecurID token PIN with HiPM. 48 Locked out Windows 7 user resets own password Animation:../../pics/camtasia/v9/hipm-pw-reset-vista-nb/hipm-pw-reset-vista-nb.mp4 49 Locked out Windows XP user resets own password Animation:../../pics/camtasia/v8/hipm-pw-reset-gina/hipm-pw-reset-gina.cam 2015 Hitachi ID Systems, Inc. All rights reserved. 24

50 Locked out Windows user resets own password (no software footprint) Animation:../../pics/camtasia/v8/hipm-pw-reset-ska/hipm-pw-reset-ska.cam 51 Enrollment of security questions Animation:../../pics/camtasia/v9/hipm-qa-enrollment/hipm-qa-enrollment.mp4 52 Enrollment of non-standard login IDs Animation:../../pics/camtasia/v82/hipm-alias-enrollment/hipm-alias-enrollment.cam 53 RSA SecurID Self Service Token Support Animation:../../pics/camtasia/v82/hipm-rsa-token-reset/hipm-rsa-token-reset.cam 54 Reminder to change passwords Animation:../../pics/camtasia/v9/hipm-pw-expired-email/hipm-pw-expired-email.mp4 2015 Hitachi ID Systems, Inc. All rights reserved. 25

55 Assisted Password Reset Animation:../../pics/camtasia/v9/hipm-assisted-pw-reset/hipm-assisted-pw-reset.mp4 56 Hitachi ID Professional Services Hitachi ID offers a variety of services relating to Hitachi ID Password Manager, including: Needs analysis and solution design. Fixed price system deployment. Project planning. Roll-out management, including maximizing user adoption. Ongoing system monitoring. Training. Services are based on extensive experience with the Hitachi ID solution delivery process. The Hitachi ID professional services team is highly technical and have years of experience deploying IAM solutions. Hitachi ID partners with integrators that also offer business process and system design services to mutual customers. All implementation services are fixed price: Solution design. Statement of work. 57 Hitachi ID Solution Delivery Approach Fixed-price: All work is delivered on a fixed-price, fixed-deliverables basis. The "meter" is never running. Phases, milestones: Hitachi ID recommends breaking up long projects into phases of 1 3 months. Work is reviewed and payment is due when milestones are met. Open assignment: Templates: Customer portal: Each phase may be undertaken by Hitachi ID, the customer, a systems integrator or a combination of the participants. Template documents and sample business logic are used to expedite work. A self-service portal supports discovery, client/partner/vendor interaction, document distribution and more. 2015 Hitachi ID Systems, Inc. All rights reserved. 26

58 AdMax: Maximizing User Adoption Successful implementation of an identity and access management system must be supported by an effective user adoption program. AdMax is an Hitachi ID professional services program, used to plan for and execute effective user enrollment projects. AdMax is designed to maximize adoption of and ROI from Hitachi ID identity management solutions, using: Best practices, case studies and industry norms. Enrollment, user adoption and ROI measurement. Incentive and disincentive programs. Presentations and training materials for users and HD staff. Project roles and responsibilities. Sample project plans, promotional materials, e-mails, graphics and other user communications. Workbooks for project implementation. 59 Summary An integrated solution for managing credentials: Immediate security benefit: password policy, help desk caller authentication. Low deployment cost, minimal ongoing investment, significant IT support savings. Always accessible: Web browser on PC, phone or tablet. Windows login prompt. Pre-boot encryption password prompt. Phone call / IVR. Available at work and while off-site. 110+ connectors included. Learn more at Hitachi-ID.com/Password-Manager 500, 1401-1 Street SE, Calgary AB Canada T2G 2J3 Tel: 1.403.233.0740 Fax: 1.403.233.0725 E-Mail: sales@hitachi-id.com www.hitachi-id.com Date: May 14, 2015 File: PRCS:pres