Action
Identity
Identity Management
Information Center
Passlogix
Identity Management Solutions
Technology Services
Training & Consulting
Passlogix Solutions

Passlogix v-GO Self-Service Password Reset

Sound security practices dictate that it is essential to verify a user identity before allowing password reset or unlocking accounts. Yet, without a self-service function, securely resetting passwords for Windows consumes help desk resources and delays access users need to get their jobs done.

Passlogix v-GO Self-Service Password Reset provides users with a fast, secure way to regain access to their computer by automating Windows password reset. Users can reset their password or unlock their Windows account directly from their locked out workstation, so that they can get to their applications within seconds - without having to pick up the telephone or go to another workstation.

How Passlogix v-GO Self-Service Password Reset Works

Confidence-Based User Identity Verification Engine

Passlogix v-GO Self-Service Password Reset uses a question-and-answer process to initiate a reset. Users enroll by answering a series of meaningful and specific reset questions. When employees need to reset their password, they are prompted to "re-answer" the reset questions. v-GO Self-Service Password Reset delivers well-constructed questions requiring personal, unforgettable answers.

If the user answers a sufficient number of questions correctly a minimum confidence score is reached and the system allows a password reset or account unlock. Failure to attain a preset confidence score results in a denial.

Passlogix v-GO Self-Service Password Reset's unique identity verification engine reduces the number of false negatives from users who forget answers or type them incorrectly. Properly selected and weighted questions significantly reduce the risk of intrusions through social engineering or lucky guesses. For the user, it means resetting a password or unlocking accounts in seconds, without having to call the helpdesk and potentially waiting for a callback. For administrators, it means the added security of sound and sustainable password policies and practices.

Easy to Deploy

Deploying Passlogix Self-Service Password Reset is a simple two-part process: 1) administrator setup and 2) user enrollment. It starts with an administrator logging on to the intuitive Management Console to configure the Enrollment Interview and Reset Quiz. Users enroll by answering a one-time online Enrollment Interview.

Benefits of Passlogix v-GO Self-Service Password Reset

Improve Operational Efficiency, Reduce Costs
Passlogix v-GO Self-Service Password Reset eliminates help-desk calls and costs associated with password reset. Up to 30 percent of all helpdesk calls are password-reset requests, on average taking 20 minutes to resolve and costing more than $20 per call says market research firm, Gartner Group.

Passlogix v-GO Self-Service Password Reset exclusive In-The-Flow technology provides unparalleled usability, enabling users to enroll, reset passwords, and unlock accounts on their own in seconds.
Increase Adoption with In-The-Flow Access
Because helpdesk calls are costly and current password reset processes unproductive, an increasing number of organizations have evaluated self-help tools. However, many tools are inconvenient to use because they cannot be accessed from the computer on which the user is currently locked out.

Passlogix v-GO Self-Service Password Reset's In-The-Flow technology seamlessly and securely includes the enrollment and password-reset process into the Windows logon, providing users with a simple enrollment, reset, and unlock process where and when they need it. This easy to use process dramatically increases user adoption of the password reset tool, resulting in less time spent on resetting passwords and unlocking accounts.

Features of Passlogix v-GO Self-Service Password Reset

Windows® Password Reset featuring In-the-Flow™ Access First Confidence-Based User Identity Verification Engine Easy to Deploy • A First Step to Strong Authentication

It happens all the time. A user tries to log into a corporate network but can't remember his or her Windows password when prompted and is locked out of everything. Lock outs cost money because the user can't work and has to call the company's helpdesk to reset the password. As much as 30 percent of all helpdesk calls are password-reset requests, on average taking 20 minutes to resolve and costing more than $23 on helpdesk costs alone, says market research firm Gartner.

Passlogix v-GO Self-Service Password Reset (v-GO SSPR), eliminates those costs for the most frequently forgotten password–the Windows password. v-GO SSPR employs our exclusive In-the-Flow technology, which provides unparalleled usability to let users enroll and reset passwords on their own in minutes. The result: lower costs and higher productivity.

Passlogix v-GO SSPR integrates seamlessly with v-GO Single Sign-On (v-GO SSO), which eliminates the need for users to use all but their Windows password for sign-on to any application. v-GO SSPR extends the benefits of single sign-on by eliminating the need to call a helpdesk when users forget this last password they need to remember.

Passlogix v-GO SSPR completes the circle of eliminating helpdesk calls for password reset.
First Confidence-Based User Identity Verification Engine
v-GO SSPR uses a question-and-answer process to initiate a reset. When your employees enroll, they have to answer a set of questions that are meaningful and specific to them. When they need to reset their password, they will be presented a Reset Quiz, where they have to supply their answers again. v-GO SSPR's Confidence Based Verification resolves one of the major problems with the typical ”one strike and you are out“ approach to Self Service Reset– lots of false negatives from users who forgot an answer or typed incorrectly. With v-GO SSPR, users can recover from a minor mistake and still reset their password. For administrators, this means the security of sound password policy without unnecessary helpdesk calls.

The administrator presets a Confidence Score... if the user answers a sufficient number of questions correctly and reaches this score, the system allows a password reset. Failure to reach this score results in a password reset denial. Some questions are more secure than others, depending on how difficult it is for a third party to obtain the right answer. For example, someone's date-of-birth is easier to find out than the first name of someone's first love. v-GO SSPR allows the administrator to give different point scores to right answers, depending on this difficulty. However, when someone gives the wrong answer to an easy question, that could raise a significant red flag. While the correct answer to the user's middle name would yield a small positive score, the wrong answer should yield a large negative score, making it difficult, if not impossible, to reach the Confidence Score.
Easy to Deploy
Putting v-GO SSPR to work is a simple process consisting of setup by the administrator followed by user enrollment. v-GO SSPR uses an intuitive Management Console to configure the Enrollment Interview and Reset Quiz. The administrator inputs question text, scoring values, and the Confidence Score limit that complies with the organization's security policies. Administrators may add or modify questions as needed to maintain appropriate security levels, and the Console keeps an audit of enrollment/reset activity and status. During a one-time Enrollment Interview the user answers the questions that will randomly appear during the Reset Quiz.
The First Step in Strong Authentication
Many companies are evaluating or implementing strong authentication technologies, such as smart cards or biometrics. When deployed with v-GO SSO, those technologies secure access to all network applications and resources, including logon to Windows. But when the authenticator is not available, for example because the user misplaced the smart card, the fallback is usually the Windows password for log on. As users probably cannot remember that password, v-GO SSPR enables them to pick a new Windows password and be on their way in less than a minute. With v-GO SSO and v-GO SSPR, companies pave the way for a seamless and efficient deployment of strong authentication.
v-GO Self-Service Password Reset
v-GO SSPR delivers a secure, and easy-to-use, easy-to-administer, self-service password-reset solution for the Windows environment. It encourages enrollment and adoption by providing a convenient means for the user to access the reset process without assistance.
User Set-up and Enrollment Options
  • Simple, configurable Web-based question-and-answer process
  • In-the-flow, automatic initiation at the Windows system logon that provides easy access, encourages enrollment and, as an option, enforces enrollment
v-GO SSPR System Access
  • Addresses “the last password” in a v-GO SSO deployment and “the first password” in the user's day
  • Simple Web-based access for end users and administrators
  • In-the-flow user access when Windows access is denied at system startup. Provides easy recovery at the most logical point, such as when the user tries to log on, increasing likelihood of usage
User Authentication
  • Configurable question-and-answer process
    • Administrative control over questions
    • Support for role/group-specific challenge questions
    • Ability to control response expectations, such as format (mmddyyyy, #-#-##), answer length, and case sensitivity
  • Unique scoring model provides high security while reducing false negatives
    • Highly secure, flexible, more closely representative of real-world helpdesk-based identity verification
    • Recognition that some questions are more secure than others and that not all errors and memory lapses should default to helpdesk calls
    • Confidence based on the users answering a sufficient number of the right questions correctly to reach a verification threshold: The Confidence Score
    • Answers can be validated against one or more external data sources
Reset
  • Windows (or AD) domain password via Internet Explorer browser
  • In-the-flow support on Windows 2000, Windows XP, Windows Server 2003, and Microsoft Vista Business Edition
  • Supports remote authentication, such as for Terminal Services, Citrix MetaFrame® software, and Citrix MetaFrame Password Manager, with the standard Microsoft Windows GINA
Administration
  • Simple, Web-based interface and MMC plug-in support for all domains in your environment
  • Configurable user interface
  • Configurable backend repository for storing questions and encrypted enrollment answers (Microsoft Active Directory, Microsoft ADAM, Microsoft SQL 2000, Oracle Database v10g or later)
  • Scoring model-based control that reduces false negatives while maintaining security
  • External Validation API
  • Reports for Active Users, Enrolled Users, User Enrollment Status, Enrollment Score, Password Resets (completed, cancelled, or failed with score), log of IP address where all resets or attempts occurred
  • Detailed technical documentation to assist administrator to set up and manage user authentication securely
Deployment
  • Utilizes Windows Installer technology
  • Deploys using most deployment tools, such as SMS, Tivoli, Zenworks, and Novadigm
Security and Reliability
  • User's answers are stored by the v-GO SSPR server as a salted SHA-I hash
  • User's answers are never stored in the clear and never on the user's client
  • SSL guarantees protection of all communication
  • Fault tolerance is based on Microsoft Internet Information Server and Active Directory settings
Want to learn more about how GCA Identity Management solutions can significantly benefit you and your business?
Our IDM experts are ready to help! Contact us today.
Newsletter Signup
Send this page to a Colleague
Tags:

Identity Management

|

Access Management

|

Password Management

|

IDM