Admins usually enforce timely password changes and stringent password complexity policies to ensure organizational network security. However, these security measures can adversely affect user productivity when users forget their login passwords, causing frequent AD account lockouts.
ADSelfService Plus, a self-service account unlock tool, allows local and remote users to unlock their Windows AD and cloud accounts on their own.
Be it a locked-out Google Workspace account or an Active Directory account, ADSelfService Plus enables users to unlock their accounts, regardless of whether they're in the office, on the move, or at home.
Allow users to unlock accounts from their Windows, macOS, and Linux logon screens. Learn more
Empower users to unlock their accounts from their Android and iOS devices. Learn more
Grant users the ability to update their local cached credentials after unlocking their Active Directory accounts remotely. Learn more
Enable users to securely unlock their Active Directory and cloud accounts using a web browser.
ADSelfService Plus allows admins to initiate a preconfigured authentication workflow once users initiate account unlock. It comprises of 19 different authentication techniques, including biometrics and YubiKey, which can be utilized to authenticate users during self-service account unlock. ADSelfService Plus ensures the protection of confidential data. Sensitive business data being maintained by some users would be at risk if their accounts are cracked by a malicious hacker. ADSelfService Plus provides the option to enforce various authentication types for different types of users.
The following are some MFA methods that ADSelfService Plus supports to authenticate user identities:
These are some MFA methods that ADSelfService Plus supports to authenticate user identities:
For the complete list of supported authenticators, click here.
Fingerprint authentication
Microsoft Authenticator
TOTPs
Duo Security
Google Authenticator
YubiKey Authenticator
The conditional access policy offered by ADSelfService Plus enables admins to set context-based rules to step-up or step-down the authentication flow set for self-service account unlock. These authentication factors can be altered based on various factors such as the IP address, time of request, device used, and the geolocation of the user. In a scenario where an account unlock request is received from an untrusted IP address, the user can be asked to pass three different factors of identity verification, with the mandatory verification factor being a biometric factor.
ADSelfService Plus supports user directories including:
ADSelfService Plus analyzes user risk factors and ensures that users prove their identity via the enforced authenticators before allowing them to unlock their account. Admins can allow or restrict access based on a user's:
Admins can also enforce MFA methods to self-service account unlock actions based on users' domains, organizational units, or group memberships.
How much money could you save using a password reset and account unlock tool?
Calculate your ROI here.ADSelfService Plus requires users to complete enrollment before they can use the account unlock tool. To ensure 100% user enrollment, ADSelfService Plus enables IT admins to:
Users no longer have to depend on the help desk's availability to unlock their locked out accounts. This means user productivity is not affected by account lockouts.
Take the burden off IT admins by enabling users to unlock their own locked out account, saving IT admins time and effort.
ADSelfService Plus delivers benefits on the day it's installed by helping resolve workforce downtime issues and reducing incurred IT costs due to account lockouts..
Enable context-based MFA with 19 different authentication factors for endpoint and application logins.
Learn moreAllow users to access all enterprise applications with a single, secure authentication flow.
Learn moreEnhance remote work with cached credential updates, secure logins, and mobile password management.
Learn moreEstablish an efficient and secure IT environment through integration with SIEM, ITSM, and IAM tools.
Learn moreDelegate profile updates and group subscriptions to end users and monitor these self-service actions with approval workflows.
Learn moreCreate a Zero Trust environment with advanced identity verification techniques and render your networks impenetrable to threats.
Learn more