Self Service Reset Password Management

Self Service Reset Password Managment
Solution for Windows 2003 & 2008 Active Directory

Problem/Solutions

Problem:

  • High call volumes to the helpdesk for password resets
    • Use of highly skilled IT staff resetting Active Directory user password
  • Security risks - outside individuals requesting a password reset attempting to access the network
    • You would like to enforce stronger password requirements but do not have an easy way to enforce your restrictions
  • End-user downtime – loss of productivity while waiting for IT staff to reset passwords

 

Solution:

Self Service Password Reset Management:

SSRPM is based on the principle that the end-user can reset his/her own password, without the involvement of the helpdesk, by simply answering a series of challenge questions (i.e. “What is the name of your best friend?”).

Reset Password


How it works:

  1. The SSRPM User Client Software

Based on a GPO on an OU/domain, a small piece of software needs to be installed on every workstation in the corresponding OU/domain. This software communicates with the central SSRPM service to allow end-users to reset their passwords and adds an extra "Forgot my password" to the standard Windows logon dialog.

When the end-user logs on, the software will check with the central SSRPM Service to see if the user has already enrolled into SSRPM. If not, the user will be asked automatically to enroll. The end-user is allowed to skip the enrollment. If the end-user hits the button “Forgot my password” and the end-user has enrolled, the software will retrieve the set of questions and answers from the central service and the end-user can start the process of resetting his/her password. The final password reset is performed by the central SSRPM Service.

After the reset, the end-user can log in immediately using the logon dialog.

  1. SSRPM Service

The central SSRPM service stores all the answers in the SSRPM database (as an MD5 encrypted irreversible hash value) and processes the reset password requests. The service is installed during the installation process of Self Service Reset Password Management. For a successful installation, the service must have access to a Windows Domain Controller. The service is managed by the SSRPM Admin Console.

  1. SSRPM Admin Console

The SSRPM Admin Console is operated by the sys admin and the helpdesk. It guides the sys admin through the installation of the central SSRPM service. The admin console also assists in the enrollment process of end-users and in monitoring service events (for instance: password resets or end-user enrollments) during normal operation through the SSRPM Dashboard and several overviews.

Reset Password
ADDITIONAL INFORMATION

 

Reset Password
VIDEOS

YouTube