?
Solved

Self service password reset

Posted on 2010-11-08
9
Medium Priority
?
2,675 Views
Last Modified: 2013-04-22

We are currently looking at options for self service password resets.    We have a mixed environment {macs, linux ,windows, etc) and use AD 2008R2 for authentication.
   Our current product does a decent job of password resets, but is quite expensive to license.    We will have over 70-100,000 users that will use this.

Some of the features that are needed.
     -User should be able to reset password from any web browser.  If they do not know their password, they should be able to reset their password via challenge/response
    -if the product is able to send verification codes via sms that would be a bonus.
    -ad attribute updates would also be a bonus
    -We also need a web based helpdesk feature.  Meaning, our helpdesk staff should be able to reset passwords of accounts.  A number of staff members use machines on non windows machines
    -decent logging/reporting/collection of all events.

I looked at a number of products but have not found many that fit this criteria {that didn't cost (150k)   It would be preferred for this to run under IIS, but other options could work as well.

Does anyone know of any options that meet this list?  {Gee..I'm not asking too much :) }     Any information would be appreciated.
 

0
Comment
Question by:fertigj
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
9 Comments
 
LVL 27

Assisted Solution

by:KenMcF
KenMcF earned 750 total points
ID: 34089671
Take a look at rDirectory, the next version will support multiple browsers. Right now it only supports IE.
http://www.namescape.com/Products/rDirectory.aspx

Also Take a look at Courion

http://www.courion.com/products/PasswordCourier.html
0
 
LVL 57

Accepted Solution

by:
Mike Kline earned 750 total points
ID: 34089685
Microsoft makes Forefront Identity manager which can provide this feature and more.   Video here   http://technet.microsoft.com/en-us/edge/self-service-password-reset-with-fim-demo.aspx

Namescape also makes a product (haven't tested it myself).  They have a video up also

http://www.youtube.com/watch?v=TxBMSUMnKjQ
http://www.namescape.com/Solutions/SolutionsPasswordManagement.aspx


Thanks
Mike
0
 
LVL 1

Author Comment

by:fertigj
ID: 34089725
It is really important that all browsers {or ie/firefox/opera/safari} are supported.   That said the product does look interesting.   I'll have to keep an eye on this.    

I have also read decent reviews on Courion,  my only issue is the pricepoint.   A lot of decent products are pricing themselves out of consideration.     It is hard to justify a large expense for a single service  {even something as important as this}
0
Problems using Powershell and Active Directory?

Managing Active Directory does not always have to be complicated.  If you are spending more time trying instead of doing, then it's time to look at something else. For nearly 20 years, AD admins around the world have used one tool for day-to-day AD management: Hyena. Discover why

 
LVL 27

Expert Comment

by:KenMcF
ID: 34089862
I was incorrect about the browser support with namscape. It is their rDirectory product that only supports IE.

Cross-Browser Support
End-users can use Internet Explorer, Safari, or FireFox to access myPasswordto reset their Windows password, accounts, create Password Reset Profiles, or change their passwords.

http://www.namescape.com/Products/myPasswordSelfServiceReset/Features.aspx
0
 
LVL 1

Author Comment

by:fertigj
ID: 34089880
I'll have to take a closer look at this product.   This does look interesting.
0
 
LVL 1

Author Closing Comment

by:fertigj
ID: 34183473
Was hoping for open source/free..but can't fault the answers.  Just the question :)
0
 
LVL 5

Expert Comment

by:FirstSentinel
ID: 34634626
Open Source you say?.......

HERE IT IS!!!!!  

   VA TEch Self Service
0
 
LVL 22

Expert Comment

by:Joseph Moody
ID: 39102185
We were looking for a free way of doing this as well. Our final solution used PowerShell to provide a password reset service.

It isn't as pretty as a GUI based option but our users can now reset their passwords by texting from their cell.

http://deployhappiness.com/reset-user-passwords-with-ad-self-service-portal/
0

Featured Post

Free Backup Tool for VMware and Hyper-V

Restore full virtual machine or individual guest files from 19 common file systems directly from the backup file. Schedule VM backups with PowerShell scripts. Set desired time, lean back and let the script to notify you via email upon completion.  

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Had a business requirement to store the mobile number in an environmental variable. This is just a quick article on how this was done.
This process allows computer passwords to be managed and secured without using LAPS. This is an improvement on an existing process, enhanced to store password encrypted, instead of clear-text files within SQL
This tutorial will walk an individual through the process of configuring their Windows Server 2012 domain controller to synchronize its time with a trusted, external resource. Use Google, Bing, or other preferred search engine to locate trusted NTP …
Microsoft Active Directory, the widely used IT infrastructure, is known for its high risk of credential theft. The best way to test your Active Directory’s vulnerabilities to pass-the-ticket, pass-the-hash, privilege escalation, and malware attacks …
Suggested Courses

777 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question