Hitachi ID Password Manager Features
(1) Hitachi ID Password Manager (formerly P-Synch) streamlines the management of authentication factors using:
- Transparent password synchronization:
(2)When users change their password natively on a system where a password synchronization trigger has been installed, the new password is subjected to an extra password policy and, if accepted, is changed both locally and on other systems where the user has accounts.
Password Manager includes password synchronization triggers for Windows server or Active Directory (32-bit, 64-bit), Sun LDAP, IBM LDAP, Oracle Internet Directory, Unix (various), z/OS and iSeries (AS/400).
Using a familiar and mandatory password change process guarantees 100% user adoption.
- Web-based password synchronization:
(3)Users can change some or all of their passwords using a Password Manager web interface. The password policy is clearly explained on-screen and enforced interactively.
Using an interactive web page to change passwords has educational benefits but requires user awareness and cooperation.
- Self-service password reset:
(4)Users who have forgotten a password or triggered an intruder lockout can sign into Password Manager using another authentication factor and resolve their own problem. Non-password authentication options include security questions, voice biometrics, smart cards, hardware tokens and random PINs sent to a user's mobile phone using SMS.
Access to self-service is available from a PC web browser, from the Windows login screen, using a telephone or using the mini web browser on a smart phone.
- Many built-in connectors:
Password Manager ships with built-in integrations for over 100 systems and applications. That means that it can manage passwords, PINs, smart cards and other authentication factors on most servers, directories, network devices, databases and applications without customization.
- Token and smart card PIN reset:
(5)Users with a token who have forgotten their PIN or need an emergency pass code can access self-service PIN reset with a web UI or using a telephone. Users with a smart card can also reset their own PIN using an ActiveX control embedded in a web browser -- launched from their Windows desktop or login screen.
- Self-service unlock of a computer with full disk encryption:
(6)Users with full disk encryption software on their PC, who have forgotten the password that unlocks their computer, can unlock their hard disk using a self-service process accessed via telephone.
- Enterprise single sign-on:
(7)Hitachi ID Login Manager client software can be installed on Windows PCs to capture login IDs and passwords from the Windows login screen and automatically insert these same credentials into application login prompts. This eliminates the need for users to repeatedly type their login ID and password into applications whose credentials are consolidated or synchronized with Windows / Active Directory.
- Assisted password reset:
(8)Authorized IT support staff can sign into a Password Manager web user interface to look up a caller's profile, authenticate the caller by keying in answers to security questions and reset one or more passwords. A ticket is then automatically submitted to the help desk incident management system.
- Password policy enforcement:
(9)Password Manager normally enforces a global password policy to supplement the various policies enforced on each system and application. This policy ensures that passwords accepted by Password Manager will work on every system.
The built-in policy engine includes over 50 built-in rules regarding length, mixed-case, digits, dictionary words and more. Regular expressions and plug-ins enable organizations to define new rules. Password history is infinite by default.
- Password change notification / early warning:
Password Manager can invite users to change their passwords with a web UI before they expire. These invitations can be sent via e-mail or launched in a web browser when users sign into their PCs. Users can even be forced to change passwords by launching a kiosk-mode web browser at login time.
Read more:
- Password Management:
A flow chart connecting password management problems to Hitachi ID Password Manager features. - Password Synchronization:
Mechanisms used to synchronize passwords. - Self-Service Password Reset:
Users who forgot their password or triggered a lockout can reset and re-enable their own passwords. - RSA SecurID Token Management:
Self-service and assisted administration of RSA SecurID tokens - Smart Card PIN Reset:
Self-service smart card PIN reset, accessible from a web browser or PC login prompt. - Unlock PC with Full Disk Encryption:
Self-service key recovery for users whose PC is protected with full disk encryption software and who forgot their PC unlock password. - Single sign-on:
Automatically populate login IDs and passwords into application login prompts. - Assisted Password Reset:
Users who forgot their password or triggered a lockout can call the help desk and get rapid service. - Password Policy Enforcement:
Enforcement of password complexity policy, password aging and password history across the enterprise. - Password Expiration:
Early detection and user notification of upcoming password expiration. - Automated User Enrollment:
Automated user identification, prompting users to register and self-service input of user profile data. - Telephone Access to Self Service:
Users can access self-service password reset, PIN reset and hard disk key recovery.