In here, you can set up a configuration which will lock out of ADSelfService Plus any user account that fails to answer security questions in suspiciously quick succession.
Now, a question arises: A password self-service solution is to help users who have locked themselves out of computers? What good is it if the solution itself starts locking out users and denying service?
Answer: Imagine a dictionary attack program being used by a hacker haranguing ADSelfService Plus with 300,000 combinations of passwords per second! If there is not a lockout mechanism at guard, then the hacker, who knows (or guessed) a valid username in your domain, has all the time and chance on earth to crack the account’s answer. Thus it is imperative to put a lockout mechanism to use, just in case.
Well, it depends on your organization.
Low security: Lockout Threshold – Either not defined or more than 10 attempts | Lockout Duration – 0 (no lockout period).
Medium Security: Lockout Threshold – 5 attempts | Lockout Duration – 30 minutes
High Security: Lockout Threshold – 5 or less attempts | Lockout Duration – as long as the admin wants!
We need to relax this to an extent that suits a self-service solution. Again, from the feedback from several clients, the best figures appear to be:
Chances are very bleak for a dictionary attack software to get it right in 5 attempts!
Enabling these features sends emails to the users, whenever they reset or change their passwords, or unlock their locked-down accounts.
As a best practice, it is advisable to always leave this feature on.
Reason : While a user knows already that he is using ADSelfService Plus for password reset and the software itself informs him about the status of the operation, sending a notification to his email could serve as an alert to him should someone unintended resets his password. This is just like credit card companies or banks inform you about the usage whenever you swipe the card
Before users can reset their passwords or unlock their accounts, ADSelfService Plus requires them to CAPTCHA-verify. It helps to confirm only humans and not any automated hacking software is accessing the solution.
Enabling this feature disables CAPTCHA verification on those pages.
Advantage | Disadvantage |
---|---|
Feature is capable of keeping automated hacking software from hacking in or carrying out denial-of-service attacks. |
Users might be irritated when they are not able to understand the distorted image and reproduce it. |
Our Recommendation: Never leave it on! Majority of users never feel any discomfort with CAPTCHA verification.
Enabling this feature removes “Personalize” tab from the end-user’s portal
Feature: Automatically Reset Domain Users’ Passwords When They Expire
Feature: Automatically Unlock Locked-Down Accounts in the Domain
As the self-explanatory names suggest, these features scan the network for an expired password or locked-down account and offer solution.
Custom made for certain schools and widely used by several educational institutes, this feature set is a welcome convenience in places where there is an incident of mass account lockdown or password expiry.
We leave it to you to decide whether to use this feature or not. If you think such an arrangement would not work well for you, then do not enable this feature. On the other hand, you are convinced with the explanation given below and consider this feature to be helpful you can use it as recommended.
How this feature works: This is actually a scheduler which you can configure to run a scan on your domain as frequently as you desire. During its sweep, should the scheduler detect any locked down account or an account with expired password, it would unlock or reset the password.
Well, this is only a convenience. And for us, this is also a selling point! Certain schools and colleges request us for this feature
Our Recommendation: Never enable them if not needed for your environment.
Q&A Settings
Always display Security Questions one by one. Never give them all at once.
Answer Settings:
Always leave the following on:
Prevent a user from providing the same answer to multiple questions
Prevent a user from using any word of a question in his answers.
Verify security question(s) answers as case sensitive while RP/UA.
NEVER: Store Security Answers using reversible encryption.
Hide 'Confirm Answer' Box during reset / unlock operations. (debatable)
Never enable “Hide CAPTCHA”.
NOTIFICATIONS : Always enable them
RESET&UNLOCK : Unlock during password reset (debatable)
NEVER : Forget to prompt users to change password upon next logon if you have auto-reset their password.
Always set a session
Enable Pwd Strength Analyzer
Your request has been submitted to the ADSelfService Plus technical support team. Our technical support people will assist you at the earliest.
Copyright © 2021, ZOHO Corp. All Rights Reserved.