Pricing  Get Quote
 
 

How does ManageEngine ADSelfService Plus handle passwords?

ManageEngine ADSelfService Plus is an identity security solution with multi-factor authentication, single sign-on, and self-service password management capabilities.

This document explains how ADSelfService Plus handles passwords that were provided during self-service password management, domain configuration, integrations with other solutions, and database backup configuration.

Types of passwords handled by ADSelfService Plus:

  • Active Directory (AD) domain administrator and user passwords
  • Product admin passwords that are created by the admin or super admin who is deploying ADSelfService Plus in their environment
  • Passwords of users' enterprise application accounts linked for password synchronization
  • Super admin credentials provided during integration with ManageEngine ADManager Plus and API keys provided during integration with ManageEngine ServiceDesk Plus
  • Passwords securing ADSelfService Plus database backup files.
  • Mail server passwords provided during mail server configuration.

How are AD domain passwords handled by ADSelfService Plus?

Domain user passwords

ADSelfService Plus generally doesn't store end users' AD domain passwords anywhere. It connects to the domain controllers to verify the password during logins into the ADSelfService Plus portal.

To perform self-service password reset or password change, the solution only resets the users' passwords in AD.

However, it stores domain users' passwords with secure irreversible bcrypt hashing if the Number of old passwords to be restricted during password reset setting is enabled in the Password Policy Enforcer.

For features like Password Expiration Notification, only the expiration status of the password is checked in AD.

Domain administrator password

The domain administrator password used to configure a domain in ADSelfService Plus is stored in the database via reversible AES-256 encryption.

How are product admin passwords handled in ADSelfService Plus

Product admin passwords are stored in the database via irreversible bcrypt hashing.

How are enterprise application passwords handled during password synchronization?

ADSelfService Plus does not store enterprise application passwords for password synchronization. It only sends the reset or changed password to the target enterprise application to complete synchronization.

How are passwords handled during integration of ADSelfService Plus with other ManageEngine applications?

Both the super admin credentials entered to integrate with ADManager Plus and the API key provided to integrate with ServiceDesk Plus are securely stored using reversible AES-256 encryption.

How is the database backup file password handled?

The ADSelfService Plus database backup file could be encrypted using the default password or a admin-configured password. The password is stored in the database via reversible AES-256 encryption.

How is the mail server password handled?

The mail server password provided during mail server configuration is stored in the database via reversible AES-256 encryption.

For more information on password handling in ADSelfService Plus, contact support@adselfserviceplus.com.

Request for Support

Need further assistance? Fill this form, and we'll contact you rightaway.

  • Name
  •  
  • Business Email *
  •  
  • Phone *
  •  
  • Problem Description *
  •  
  • Country
  •  
  • By clicking 'Submit' you agree to processing of personal data according to the Privacy Policy.
Highlights of ADSelfService Plus

Password self-service

Allow Active Directory users to self-service their password resets and account unlock tasks, freeing them from lengthy help desk calls.

One identity with single sign-on

Get seamless one-click access to 100+ cloud applications. With enterprise single sign-on, users can access all their cloud applications using their Active Directory credentials.

Password and account expiry notification

Intimate Active Directory users of their impending password and account expiry via email and SMS notifications.

Password synchronization

Synchronize Windows Active Directory user passwords and account changes across multiple systems automatically, including Microsoft 365, Google Workspace, IBM iSeries, and more.

Password policy enforcer

Strong passwords resist various hacking threats. Enforce Active Directory users to adhere to compliant passwords by displaying password complexity requirements.

Directory self-update and corporate directory search

Enable Active Directory users to update their latest information themselves. Quick search features help admins scout for information using search keys like contact numbers.

ADSelfService Plus trusted by

Embark on a journey towards identity security and Zero Trust