SlideShare ist ein Scribd-Unternehmen logo
1 von 3
Downloaden Sie, um offline zu lesen
ADSelfService Plus Password Reset Process


© 2009 ManageEngine, ALL RIGHTS RESERVED
The information provided in this document is proprietary and copyrighted under applicable laws. None
of this information can be reproduced or disseminated through any means.

OBJECTIVE: To explain briefly the basic methodology of the password reset process of
ADSelfService Plus.


INTRODUCTION: ADSelfService Plus is a self-service password reset application, which empowers
you – the domain’s end user – with capabilities to reset passwords/ unlock accounts all by yourself.
Extending its capabilities, ADSelfService Plus also enables you to enter your personal information into
Active Directory.


THE SAFE AND SECURE PASSWORD RESET METHOD OF ADSELFSERVICE PLUS

ADSelfService Plus adopts a three-pronged approach to facilitate a password reset:

   •   First, it enrolls and formulates identification criteria for you, in case you are permitted (by
       system administrators) to reset passwords through it (Enrollment Process).
   •   Second, it uses these criteria to establish your identity when you request for password reset.
       (Verification Process)
   •   Third, it calls for the service of a Windows API to change the password for you. (Password
       Reset Process)

Given below is the detailed description of these three processes:

1. ENROLLMENT & IDENTITY CRITERIA FORMULATION:
A password reset software’s aim is to help you, in case, you should forget your password – a basic
identity criteria for a domain user. Thus it is imperative for such software to define identification
criteria that could be easily remembered and reproduced.
To address this issue, ADSelfService Plus has defined a set of questions – called Security Questions –
that elicit a very personal and unique response. Since it is personal information, you can remember it
easily and others cannot guess it. ADSelfService Plus also allows you to define your own questions,
enhancing security even better. But the number of questions you can define is entirely at a system
administrator's discretion.
It is mandatory that you answer all the necessary questions and complete enrollment, failing which you
will not be able to use the product. These answers are stored in the product's inbuilt database and
referenced to establish your identity, whenever you request a password reset.

    Storing answers to Security Questions: Since they are used to establish the identity of a
    user, the answers are stored in an encrypted format in the database to avoid any identity
    theft. This encryption is achieved through a one-way hash algorithm, meaning the encrypted
    answer cannot be traced back to its original form.
2. VERIFICATION PROCESS:

It begins right at Enrollment Process. When you attempt to enroll, ADSelf Service first verifies whether
you are a legitimate member of a domain or not. If yes, you are allowed to enroll, else denied access
and presented with an alert “Invalid Login Name/Password”.
The domain level check is performed only during enrollment and once you get enrolled, ADSelfService
Plus will always look into the enrollment list to locate you whenever you request a password reset.
 If you are recognized as an enrolled user, ADSelfService asks the Questions that were selected by/
defined by/ imposed on you during Enrollment. If you answer all the questions correctly, you are
allowed to reset the password, else denied access and prompted to enter correct answers.
[Users not enrolled will be prompted to enroll before continuing to use the software]


      Verifying answers to Security Questions: An ordinary compare-and-verify is not
      possible here, as the secret answers entered during Enrollment are stored in an encrypted
      format using a one-way algorithm. Therefore it is necessary that the answers submitted
      for verification also be encrypted by the same one-way algorithm and compared with the
      ones in the database, something similar to comparing fingerprints. This ensures
      maximum password security, to the extent that not even the administrator or product
      could retrieve user entered passwords!


3. PASSWORD RESET PROCESS:

Once your identity is established through the processes mentioned above, ADSelfService Plus calls for
the Windows API responsible for password reset and passes your new password to it. Acting much like
a relay, this function deposits the new password directly into Active Directory. Neither this function nor
any component of ADSelfService Plus has any provision to store/cache/reproduce the password.
Though a password reset product, ADSelfService Plus is completely sealed off from passwords that it
handles, making it a safe and secure password reset software.


ADVANTAGES OF ADSELFSERVICE PASSWORD RESET APPROACH
   1. Wider range of secret Q&A that elicits unique answers from users and therefore stand as reliable
      user identification criteria.
   2. Since the secret answers are encoded through a one-way (or irreversible) hash algorithm, not
      even the administrator or the software can retrieve them.
   3. It is impossible to retrieve any user's password through ADSelfService Plus, as it does not store/
      cache/reproduce user passwords intrinsically or anywhere other than the Active Directory
      database.




                                               ---END---
Password Reset Process

Weitere ähnliche Inhalte

Kürzlich hochgeladen

IAC 2024 - IA Fast Track to Search Focused AI Solutions
IAC 2024 - IA Fast Track to Search Focused AI SolutionsIAC 2024 - IA Fast Track to Search Focused AI Solutions
IAC 2024 - IA Fast Track to Search Focused AI Solutions
Enterprise Knowledge
 
Artificial Intelligence: Facts and Myths
Artificial Intelligence: Facts and MythsArtificial Intelligence: Facts and Myths
Artificial Intelligence: Facts and Myths
Joaquim Jorge
 
EIS-Webinar-Prompt-Knowledge-Eng-2024-04-08.pptx
EIS-Webinar-Prompt-Knowledge-Eng-2024-04-08.pptxEIS-Webinar-Prompt-Knowledge-Eng-2024-04-08.pptx
EIS-Webinar-Prompt-Knowledge-Eng-2024-04-08.pptx
Earley Information Science
 

Kürzlich hochgeladen (20)

Strategies for Unlocking Knowledge Management in Microsoft 365 in the Copilot...
Strategies for Unlocking Knowledge Management in Microsoft 365 in the Copilot...Strategies for Unlocking Knowledge Management in Microsoft 365 in the Copilot...
Strategies for Unlocking Knowledge Management in Microsoft 365 in the Copilot...
 
IAC 2024 - IA Fast Track to Search Focused AI Solutions
IAC 2024 - IA Fast Track to Search Focused AI SolutionsIAC 2024 - IA Fast Track to Search Focused AI Solutions
IAC 2024 - IA Fast Track to Search Focused AI Solutions
 
How to Troubleshoot Apps for the Modern Connected Worker
How to Troubleshoot Apps for the Modern Connected WorkerHow to Troubleshoot Apps for the Modern Connected Worker
How to Troubleshoot Apps for the Modern Connected Worker
 
Axa Assurance Maroc - Insurer Innovation Award 2024
Axa Assurance Maroc - Insurer Innovation Award 2024Axa Assurance Maroc - Insurer Innovation Award 2024
Axa Assurance Maroc - Insurer Innovation Award 2024
 
A Domino Admins Adventures (Engage 2024)
A Domino Admins Adventures (Engage 2024)A Domino Admins Adventures (Engage 2024)
A Domino Admins Adventures (Engage 2024)
 
Boost PC performance: How more available memory can improve productivity
Boost PC performance: How more available memory can improve productivityBoost PC performance: How more available memory can improve productivity
Boost PC performance: How more available memory can improve productivity
 
Evaluating the top large language models.pdf
Evaluating the top large language models.pdfEvaluating the top large language models.pdf
Evaluating the top large language models.pdf
 
GenCyber Cyber Security Day Presentation
GenCyber Cyber Security Day PresentationGenCyber Cyber Security Day Presentation
GenCyber Cyber Security Day Presentation
 
Powerful Google developer tools for immediate impact! (2023-24 C)
Powerful Google developer tools for immediate impact! (2023-24 C)Powerful Google developer tools for immediate impact! (2023-24 C)
Powerful Google developer tools for immediate impact! (2023-24 C)
 
Workshop - Best of Both Worlds_ Combine KG and Vector search for enhanced R...
Workshop - Best of Both Worlds_ Combine  KG and Vector search for  enhanced R...Workshop - Best of Both Worlds_ Combine  KG and Vector search for  enhanced R...
Workshop - Best of Both Worlds_ Combine KG and Vector search for enhanced R...
 
08448380779 Call Girls In Greater Kailash - I Women Seeking Men
08448380779 Call Girls In Greater Kailash - I Women Seeking Men08448380779 Call Girls In Greater Kailash - I Women Seeking Men
08448380779 Call Girls In Greater Kailash - I Women Seeking Men
 
04-2024-HHUG-Sales-and-Marketing-Alignment.pptx
04-2024-HHUG-Sales-and-Marketing-Alignment.pptx04-2024-HHUG-Sales-and-Marketing-Alignment.pptx
04-2024-HHUG-Sales-and-Marketing-Alignment.pptx
 
08448380779 Call Girls In Diplomatic Enclave Women Seeking Men
08448380779 Call Girls In Diplomatic Enclave Women Seeking Men08448380779 Call Girls In Diplomatic Enclave Women Seeking Men
08448380779 Call Girls In Diplomatic Enclave Women Seeking Men
 
Exploring the Future Potential of AI-Enabled Smartphone Processors
Exploring the Future Potential of AI-Enabled Smartphone ProcessorsExploring the Future Potential of AI-Enabled Smartphone Processors
Exploring the Future Potential of AI-Enabled Smartphone Processors
 
Artificial Intelligence: Facts and Myths
Artificial Intelligence: Facts and MythsArtificial Intelligence: Facts and Myths
Artificial Intelligence: Facts and Myths
 
Handwritten Text Recognition for manuscripts and early printed texts
Handwritten Text Recognition for manuscripts and early printed textsHandwritten Text Recognition for manuscripts and early printed texts
Handwritten Text Recognition for manuscripts and early printed texts
 
EIS-Webinar-Prompt-Knowledge-Eng-2024-04-08.pptx
EIS-Webinar-Prompt-Knowledge-Eng-2024-04-08.pptxEIS-Webinar-Prompt-Knowledge-Eng-2024-04-08.pptx
EIS-Webinar-Prompt-Knowledge-Eng-2024-04-08.pptx
 
Boost Fertility New Invention Ups Success Rates.pdf
Boost Fertility New Invention Ups Success Rates.pdfBoost Fertility New Invention Ups Success Rates.pdf
Boost Fertility New Invention Ups Success Rates.pdf
 
[2024]Digital Global Overview Report 2024 Meltwater.pdf
[2024]Digital Global Overview Report 2024 Meltwater.pdf[2024]Digital Global Overview Report 2024 Meltwater.pdf
[2024]Digital Global Overview Report 2024 Meltwater.pdf
 
🐬 The future of MySQL is Postgres 🐘
🐬  The future of MySQL is Postgres   🐘🐬  The future of MySQL is Postgres   🐘
🐬 The future of MySQL is Postgres 🐘
 

Empfohlen

How Race, Age and Gender Shape Attitudes Towards Mental Health
How Race, Age and Gender Shape Attitudes Towards Mental HealthHow Race, Age and Gender Shape Attitudes Towards Mental Health
How Race, Age and Gender Shape Attitudes Towards Mental Health
ThinkNow
 
Social Media Marketing Trends 2024 // The Global Indie Insights
Social Media Marketing Trends 2024 // The Global Indie InsightsSocial Media Marketing Trends 2024 // The Global Indie Insights
Social Media Marketing Trends 2024 // The Global Indie Insights
Kurio // The Social Media Age(ncy)
 

Empfohlen (20)

2024 State of Marketing Report – by Hubspot
2024 State of Marketing Report – by Hubspot2024 State of Marketing Report – by Hubspot
2024 State of Marketing Report – by Hubspot
 
Everything You Need To Know About ChatGPT
Everything You Need To Know About ChatGPTEverything You Need To Know About ChatGPT
Everything You Need To Know About ChatGPT
 
Product Design Trends in 2024 | Teenage Engineerings
Product Design Trends in 2024 | Teenage EngineeringsProduct Design Trends in 2024 | Teenage Engineerings
Product Design Trends in 2024 | Teenage Engineerings
 
How Race, Age and Gender Shape Attitudes Towards Mental Health
How Race, Age and Gender Shape Attitudes Towards Mental HealthHow Race, Age and Gender Shape Attitudes Towards Mental Health
How Race, Age and Gender Shape Attitudes Towards Mental Health
 
AI Trends in Creative Operations 2024 by Artwork Flow.pdf
AI Trends in Creative Operations 2024 by Artwork Flow.pdfAI Trends in Creative Operations 2024 by Artwork Flow.pdf
AI Trends in Creative Operations 2024 by Artwork Flow.pdf
 
Skeleton Culture Code
Skeleton Culture CodeSkeleton Culture Code
Skeleton Culture Code
 
PEPSICO Presentation to CAGNY Conference Feb 2024
PEPSICO Presentation to CAGNY Conference Feb 2024PEPSICO Presentation to CAGNY Conference Feb 2024
PEPSICO Presentation to CAGNY Conference Feb 2024
 
Content Methodology: A Best Practices Report (Webinar)
Content Methodology: A Best Practices Report (Webinar)Content Methodology: A Best Practices Report (Webinar)
Content Methodology: A Best Practices Report (Webinar)
 
How to Prepare For a Successful Job Search for 2024
How to Prepare For a Successful Job Search for 2024How to Prepare For a Successful Job Search for 2024
How to Prepare For a Successful Job Search for 2024
 
Social Media Marketing Trends 2024 // The Global Indie Insights
Social Media Marketing Trends 2024 // The Global Indie InsightsSocial Media Marketing Trends 2024 // The Global Indie Insights
Social Media Marketing Trends 2024 // The Global Indie Insights
 
Trends In Paid Search: Navigating The Digital Landscape In 2024
Trends In Paid Search: Navigating The Digital Landscape In 2024Trends In Paid Search: Navigating The Digital Landscape In 2024
Trends In Paid Search: Navigating The Digital Landscape In 2024
 
5 Public speaking tips from TED - Visualized summary
5 Public speaking tips from TED - Visualized summary5 Public speaking tips from TED - Visualized summary
5 Public speaking tips from TED - Visualized summary
 
ChatGPT and the Future of Work - Clark Boyd
ChatGPT and the Future of Work - Clark Boyd ChatGPT and the Future of Work - Clark Boyd
ChatGPT and the Future of Work - Clark Boyd
 
Getting into the tech field. what next
Getting into the tech field. what next Getting into the tech field. what next
Getting into the tech field. what next
 
Google's Just Not That Into You: Understanding Core Updates & Search Intent
Google's Just Not That Into You: Understanding Core Updates & Search IntentGoogle's Just Not That Into You: Understanding Core Updates & Search Intent
Google's Just Not That Into You: Understanding Core Updates & Search Intent
 
How to have difficult conversations
How to have difficult conversations How to have difficult conversations
How to have difficult conversations
 
Introduction to Data Science
Introduction to Data ScienceIntroduction to Data Science
Introduction to Data Science
 
Time Management & Productivity - Best Practices
Time Management & Productivity -  Best PracticesTime Management & Productivity -  Best Practices
Time Management & Productivity - Best Practices
 
The six step guide to practical project management
The six step guide to practical project managementThe six step guide to practical project management
The six step guide to practical project management
 
Beginners Guide to TikTok for Search - Rachel Pearson - We are Tilt __ Bright...
Beginners Guide to TikTok for Search - Rachel Pearson - We are Tilt __ Bright...Beginners Guide to TikTok for Search - Rachel Pearson - We are Tilt __ Bright...
Beginners Guide to TikTok for Search - Rachel Pearson - We are Tilt __ Bright...
 

Password Reset Process

  • 1. ADSelfService Plus Password Reset Process © 2009 ManageEngine, ALL RIGHTS RESERVED The information provided in this document is proprietary and copyrighted under applicable laws. None of this information can be reproduced or disseminated through any means. OBJECTIVE: To explain briefly the basic methodology of the password reset process of ADSelfService Plus. INTRODUCTION: ADSelfService Plus is a self-service password reset application, which empowers you – the domain’s end user – with capabilities to reset passwords/ unlock accounts all by yourself. Extending its capabilities, ADSelfService Plus also enables you to enter your personal information into Active Directory. THE SAFE AND SECURE PASSWORD RESET METHOD OF ADSELFSERVICE PLUS ADSelfService Plus adopts a three-pronged approach to facilitate a password reset: • First, it enrolls and formulates identification criteria for you, in case you are permitted (by system administrators) to reset passwords through it (Enrollment Process). • Second, it uses these criteria to establish your identity when you request for password reset. (Verification Process) • Third, it calls for the service of a Windows API to change the password for you. (Password Reset Process) Given below is the detailed description of these three processes: 1. ENROLLMENT & IDENTITY CRITERIA FORMULATION: A password reset software’s aim is to help you, in case, you should forget your password – a basic identity criteria for a domain user. Thus it is imperative for such software to define identification criteria that could be easily remembered and reproduced. To address this issue, ADSelfService Plus has defined a set of questions – called Security Questions – that elicit a very personal and unique response. Since it is personal information, you can remember it easily and others cannot guess it. ADSelfService Plus also allows you to define your own questions, enhancing security even better. But the number of questions you can define is entirely at a system administrator's discretion. It is mandatory that you answer all the necessary questions and complete enrollment, failing which you will not be able to use the product. These answers are stored in the product's inbuilt database and referenced to establish your identity, whenever you request a password reset. Storing answers to Security Questions: Since they are used to establish the identity of a user, the answers are stored in an encrypted format in the database to avoid any identity theft. This encryption is achieved through a one-way hash algorithm, meaning the encrypted answer cannot be traced back to its original form.
  • 2. 2. VERIFICATION PROCESS: It begins right at Enrollment Process. When you attempt to enroll, ADSelf Service first verifies whether you are a legitimate member of a domain or not. If yes, you are allowed to enroll, else denied access and presented with an alert “Invalid Login Name/Password”. The domain level check is performed only during enrollment and once you get enrolled, ADSelfService Plus will always look into the enrollment list to locate you whenever you request a password reset. If you are recognized as an enrolled user, ADSelfService asks the Questions that were selected by/ defined by/ imposed on you during Enrollment. If you answer all the questions correctly, you are allowed to reset the password, else denied access and prompted to enter correct answers. [Users not enrolled will be prompted to enroll before continuing to use the software] Verifying answers to Security Questions: An ordinary compare-and-verify is not possible here, as the secret answers entered during Enrollment are stored in an encrypted format using a one-way algorithm. Therefore it is necessary that the answers submitted for verification also be encrypted by the same one-way algorithm and compared with the ones in the database, something similar to comparing fingerprints. This ensures maximum password security, to the extent that not even the administrator or product could retrieve user entered passwords! 3. PASSWORD RESET PROCESS: Once your identity is established through the processes mentioned above, ADSelfService Plus calls for the Windows API responsible for password reset and passes your new password to it. Acting much like a relay, this function deposits the new password directly into Active Directory. Neither this function nor any component of ADSelfService Plus has any provision to store/cache/reproduce the password. Though a password reset product, ADSelfService Plus is completely sealed off from passwords that it handles, making it a safe and secure password reset software. ADVANTAGES OF ADSELFSERVICE PASSWORD RESET APPROACH 1. Wider range of secret Q&A that elicits unique answers from users and therefore stand as reliable user identification criteria. 2. Since the secret answers are encoded through a one-way (or irreversible) hash algorithm, not even the administrator or the software can retrieve them. 3. It is impossible to retrieve any user's password through ADSelfService Plus, as it does not store/ cache/reproduce user passwords intrinsically or anywhere other than the Active Directory database. ---END---