IMS Health Secure Outlook Web Access Portal Purpose: This service has been developed to allow access to the IMS Health email system for staff that can not access the email system through VPN which is preferred for secure access to IMS computer resources. Policy: Users of this service must take great care to ensure that any computer used to access IMS email has not been compromised and that email cannot be viewed by unauthorized people. Browser session connections to email are limited to 1 hour per login. In addition, sessions idle longer than 10 minutes will be prompted to be terminated or extended. Browser sessions must always be logged off before leaving the workstation used for access. Description: IMS uses RSA SecurID tokens to secure Internet Browser sessions connecting users to their email. These tokens generate a 6 digit number (called a tokencode) every 60 seconds. This six digit number combined with a 4 to 8 alphanumeric Personal ID (or PIN), chosen by the user, makes up the PASSCODE. The user enters this PASSCODE and the username they already use to log into their company computer. It is imperative that the PIN and token be kept separate to ensure security. Lost tokens must be immediately reported to ensure the security of the email system. Although the Oulook Web Access browser interface is similar to the full Microsoft Outlook software client, it does have limitations. This interface is being provided primarily to allow access to email messages using a browser. Initial Login: To access this service, each user will be issued a SecurID token. This token will only work with the username of the user to which it was issued. Also, the token will allow access only to the user s primary mailbox and no other. The web page to go to is: http://netmail.imshealth.com. Quick Setup 1. Navigate to: http://netmail.imshealth.com 2. Choose which region to connect. 3. Enter Username & Tokencode (First time ONLY) a. Username = Domain logon account b. Tokencode = 6 digit number on token 4. Create PIN (4 to 8 alphanumeric) 5. Logon with Username & PASSCODE a. Username = Domain logon account b. PASSCODE = PIN + Tokencode (must be a different Tokencode than used above) 6. The web page is sent to the person s primary mailbox. This process is illustrated on the following pages. Page 1 of 11
Once the user chooses which Region from which their email is supported, they will be challenged by the following web page: The first time the user tries to log in, they will enter their username into the User ID field, and only the 6 digit tokencode found on the SecurID token into the Passcode field. Page 2 of 11
NEW RSA SecurID PIN After clicking the Log In button, the user will be challenged with the following web page: The user will create a PIN on this page to be used in conjunction with the 6 digit tokencode to make up the user s PASSCODE for future logins. This PIN can only be changed by contacting the regional IT support teams who will reset the Token to Initial Login mode as described above. Page 3 of 11
RSA SecurID Log In After clicking the OK button, the user will be challenged with the following web page: The user will need to wait until the tokencode has changed. A tokencode can only be used once for any authentication attempt. Once used, the user must wait the remainder of 60 seconds for the next tokencode to appear. Once the tokencode has changed, the user will enter their new PIN followed by the new 6 digit tokencode which makes up the PASSCODE. Page 4 of 11
After clicking the Log In button, the following web page will briefly appear: The user will be automatically redirected to their primary mailbox after a few seconds. Page 5 of 11
RSA Invalid Login page: If the user does not wait for the next tokencode to appear, they will be challenged by the following web Navigation Guard If the user tries to navigate away from their active OWA session, the following web page will appear: Page 6 of 11
Time Guard After 10 minutes of inactivity, the user will be challenged by the following web page: After an hour, the user s OWA session will be terminated as shown below: Page 7 of 11
Log Out Once time has elapsed, or the user logs out gracefully, the following web page will briefly appear: When the user closes the browser session during an RSA web page, the following web page will briefly appear: Page 8 of 11
OWA Authentication with USB SecurID Token Plugged In Description: If the user s IMS Health PC has been installed with the software necessary to support the USB function of the SecurID Token, The following web pages & pop-ups will be encountered If the USB device is plugged in, the authentication pop-up presented when the browser navigates to the chosen IMS Region is: Please note that the Choose Token field is set to SecurID Software Token and that the SecurID Software Token field is set to the user s USB SecurID Token displayed as the serial number of that Token. Please also note that the user is not requested for the Tokencode from the device. The user need only enter their username and PIN. If the user did not have the USB device plugged in before launching Internet Explorer, the following pop-up is presented: Page 9 of 11
In this case, the user can both close and launch Internet Explorer again after plugging in the USB device or the user can manually enter their username and PASSCODE (PIN + Tokencode) As described previously, the first time the user tries to log in, they will enter their username into the Enter User Name field, and the 6 digit tokencode found on the SecurID token into the Passcode field. If the USB device is plugged in, the user will only enter their username as the tokencode will be automatically read from the USB device. After clicking the OK button, the user will receive the following pop-up: After clicking on the OK button, the user will receive the following pop-up: After clicking on the OK button, the user will receive the following pop-up: Page 10 of 11
After clicking on the OK button, the user will be challenged for their authentication credentials: or After clicking on the OK button, the user will be redirected to their primary mailbox. Page 11 of 11