Secure and Simplify Password Resets with Duo and FastPass SSPR
Streamline password management, enhance security, and reduce help desk workload with FastPass SSPR backed by Duo verification.
The Challenge
In today's dynamic work environment, especially with increased work-from-home setups, help desks face a surge in password reset requests. This burden not only impacts productivity but also poses potential security risks when user verification isn’t robust.
The Solution
Empower Users with FastPass SSPR and Duo Verification
FastPass SSPR combined with Duo makes self-service password resets simple and secure. With just a familiar Duo push notification, users can verify their identity and reset passwords without contacting the help desk.
Key Benefits
- Intuitive for Duo Users: Seamless verification through familiar Duo authentication.
- Versatile Verification Options: Options for Push, SMS, TOTP, callbacks, and more.
- No Enrollment Required: Duo-verified users can start immediately.
Enhanced Security for All Users
For those without Duo, FastPass supports alternative multi-factor authentication (MFA) methods. This ensures comprehensive security coverage across various departments and locations.
Advanced Help Desk Support FastPass Identity Verification Manager (IVM)
For those cases where users still contact the help desk, FastPass IVM provides a secure verification process, preventing social engineering attempts and ensuring robust compliance and audit logging.
How It Works
FastPass, integrated with Duo's API (Auth 2), presents verification options dynamically based on user group and location. Factors include:
- Duo Push
- TOTP
- SMS
- Call back
Flexible Configurations:
Configure verification based on network access (e.g., LAN or remote).
What our customers are saying about us
The biggest businesses in different industries trust FastPassCorp
Implementing FastPass SSPR with Duo integration has been transformative for our organization.
What used to be hundreds of daily password reset requests has now dropped significantly, freeing up our help desk to focus on more critical tasks. The seamless Duo authentication has made it easy for employees to reset their passwords independently, reducing frustration and boosting productivity across teams.
The combination of Duo and FastPass SSPR has dramatically improved our security posture. We no longer worry about social engineering attacks targeting our help desk.
The straightforward self-service process empowers users while ensuring compliance with our stringent security policies. The result is a more secure, efficient, and cost-effective solution that has paid off almost immediately.
Ready to boost productivity and enhance security?
Contact us today for a tailored solution!
Frequently Asked Questions
Yes, we offer a POC at no product cost. Contact us for details.
Pricing starts at less than 40 cents/month/user for midsize organizations. Contact us for a custom quote.
No - not for all users. If you have the users cellphone numbers, FastPass can use the number from AD or in other ways uploaded to FastPass. Answers from otrher systems to some simple questions can be uploaded too. Remember however, that the value of the verification process depends on the fact that ONLY THE USER knows the answers!
Absolutely. FastPass can reset local PC passwords for remote users, provided their PC is connected to the Internet. The method used can vary based on your specific setup. A common solution involves utilizing your company's VPN connection.
For more detailed information and additional methods, please visit our dedicated page on FastPassCorp's website:FastPass Password Manager
Two ideas. One: Let users formulate their own questions – it is then more likely that they can remember the answer. Two: Formulate questions where the user can find the answer instead of remember it. As examples: What is the number on your private key to your house? Give the four digits on your favorite credit card position 5-8.
For more suggestions on good questions in general read the: Best practices guide to self-service of passwords
FastPass supports more than 30 different languages. You can per user group configure which language to use. In addition, FastPass automatically adapts to the choice of language in the browser.
FastPass offers versatile authentication solutions tailored to group membership, such as those in Active Directory or Entra ID (Azure AD), and based on network location. For instance, employees accessing from the internal network may require Multi-Factor Authentication (MFA), while those connecting from external networks need additional Manager Approval for secure verification.
This flexibility allows for creating robust password reset processes for different user groups. Discover more about integrating Manager Approval in password self-service here.
Functionally you can configure the same solution for the users in both situations. We recommend that your IT-strategy should decide whether to go for in-house or cloud. The FastPass Cloud solution has however access to more operational data than the on-premise version, so the dashboards and reporting with the cloud offer more.
For AD-only implementations we see it done within a timeframe of 1-2 weeks. For complex installations with IBM mainframes and SAP we see that it might take up to 3 months. With FastPass Cloud the technical part is even shorter.
FastPass employs multiple layers of security to ensure the integrity of password resets. Key steps include:
IP Address Verification: Restricts access based on IP addresses.
Client-Specific Access: Limits portal access to authorized PC clients.
Captcha Integration: Adds an extra layer of security against automated attacks.
Active Directory Checks: Ensures users are enabled, active, and belong to the correct groups.
User Locking Mechanism: Locks user accounts after several failed authentication attempts to prevent unauthorized access.
Session Monitoring: Tracks and manages session activities, including IP address changes.
Internal State Engine: Continuously monitors user operations for any suspicious activities.
Each of these steps plays a crucial role in safeguarding the password reset process, maintaining high security.
Absolutely, FastPass is fully compliant with FIPS (Federal Information Security Management) 140-2 standards, starting from version 4.0 onwards. We utilize a 256-bit AES algorithm for encryption and a PBKDF algorithm for hashing. This compliance extends across all FastPass components, from the Windows Client to the Server and Domain Controller parts, ensuring robust security throughout the system.
Indeed, FastPass's cloud operations are proudly certified with Cyber Essentials Plus, affirming our commitment to robust cybersecurity practices.
To ensure the highest security standards, FastPass conducts weekly vulnerability scans, as well as additional scans following any significant changes in the IT environment. This comprehensive scanning includes all production systems, applications, and servers. Upon detecting new vulnerabilities, we classify them based on the severity of impact and the likelihood of exploitation. This systematic approach allows us to effectively manage and mitigate potential risks in our cloud infrastructure.
To combat social engineering attacks, FastPass SSPR has robust security protocols in place. When a user answers Challenge Response questions, FastPass monitors the number of incorrect attempts. By default, a user's account is locked after three unsuccessful attempts. This lock can be lifted either through intervention by the Service Desk or by the user completing a re-enrollment process. This measure significantly reduces the risk of unauthorized access through social engineering tactics.
FastPass offers versatile integration capabilities with various MFA providers, employing different technologies to ensure seamless and secure authentication. For instance, with Okta, we utilize their API for integration. In other cases, we might use SAML (Security Assertion Markup Language) or RADIUS (Remote Authentication Dial-In User Service) integrations, depending on the specific requirements. This flexibility allows FastPass to adapt to a wide range of MFA systems, enhancing overall security. For detailed information on integrating FastPass with your preferred MFA provider, please contact us.
Absolutely. FastPass prioritizes data security, especially during data transit. One of our fundamental security measures is the mandatory use of SSL (Secure Sockets Layer) certificates for all communications. This ensures that any data exchanged between users and FastPass is encrypted, significantly enhancing security and protecting against data interception or unauthorized access during transmission. For Cloud operation TLS 1.2 is used.
Yes, FastPass ensures that all sensitive data is encrypted when stored in our database. This includes any data at rest within the FastPass system, providing an added layer of security against unauthorized access. For specific details on the types of data that are read, stored, and require write access within Active Directory and Entra ID, we recommend consulting the respective documentation. This information will give you a comprehensive understanding of our data handling practices and the security measures in place to protect your data at all times.
FastPass offers two secure methods for connecting to Active Directory:
- LDAPS Connection: Utilizes port 636, enabling secure communication over an encrypted channel.
- Standard Ports: Connects using standard ports 389 and 445, offering an alternative method for integration with AD.
These options ensure flexible and secure integration with your Active Directory environment, catering to different network and security configurations.
For optimal operation of FastPass, certain delegated rights in Active Directory are recommended for the privileged account:
- Reset Password: Allows password management.
- Write Permissions: Specifically for 'LockOutTime' and 'PwdLastSet' attributes, enabling effective account management.
- Read-Only Access: Limited to specific fields for general operational needs.
For a comprehensive understanding of these permissions and their setup, we encourage reviewing our 'Delegating Permissions in Active Directory' document for detailed guidance.
With FastPass a POC can be up and running within a day. With additional target systems (SAP/Oracle etc.) expect to add some more days.
FastPass easily integrates with any ITSM system. (e.g. Remedy, Microfocus Service Request Center Software, Service Now, Wendia POB).
FastPass V4 has been penetration tested by Backbone Security.com Inc. - 811 Ann St. Stroudsburg PA 18360
FastPass's Self-Service PC Client is fully compatible with Windows 10 and Windows 11, while legacy support is available for Windows 7 in older versions of the software.
For Bring Your Own Device (BYOD) scenarios and browser use, our client features a responsive design that adapts seamlessly to a wide range of devices, ensuring a smooth user experience across different platforms.
Notifications can be setup to notify on unusual number of access from individual users having multiple failed attempts.
Installations with 100,000+ users in operation.
The FastPass solution is available for on-premise as well as for FastPass Cloud. Service Providers can operate their own multi-tenant cloud solution.
Yes, FastPass provides the functionality to automatically delete user data and restrict access as needed. This is achieved by FastPass regularly checking the source user repository. User data can be set to be automatically deleted under certain conditions, such as if the user account is deleted or disabled, is no longer a member of a group authorized to use FastPass, or becomes a member of a group specifically designated for deletion. This ensures that user data management aligns with the current status and permissions within the organization. Please note that the users history actions are kept in the Audit log.
Yes, FastPass incorporates a feature that leverages the breached password lists from e.g. Troy Hunt's website, Have I Been Pwned https://haveibeenpwned.com/. These lists are routinely updated on our support site. This feature enables FastPass to alert users and prevent the use of passwords that have been compromised in previous data breaches.
For best practises we recommend configuring FastPass to disallow passwords that appear more than 1000 times in breach incidents. While it's possible to ban all breached passwords, we find that setting a threshold, such as 1000 occurrences, strikes a balance between security and user convenience, preventing overly restrictive password requirements.
Absolutely, FastPass includes a customizable list of prohibited passwords to help enhance security. We provide a top list of commonly used weak passwords that we recommend you utilize as a starting point. Additionally, it's a good practice to expand this list by adding specific terms related to your company, such as the company name, product names, and other relevant terms. This approach helps ensure users avoid common and potentially vulnerable passwords, thereby strengthening overall password security.
Yes, FastPass features a comprehensive and detailed audit log that meticulously records every action. This includes not only user activities but also all operations conducted within the Help Desk tool and the Admin interface. This extensive logging capability ensures thorough tracking and accountability for all interactions within the FastPass system, providing an essential tool for security and administrative oversight.
All personnel supporting FastPass cloud are as a minimum are BPSS checked and are annually trained on Data Protection and personal data best practice. They are also required to sign NDAs and the Information Security Policy and Data Protection policy. These policies are aligned with ISO 27001 / EU GDPR. Read more about GDPR and Service Desk here: Make your Service Desk GDPR Compliant
To integrate FastPass with Entra ID (Azure AD), you need to create an Enterprise Application. This application facilitates the granting of access rights, ensuring FastPass has permissions only to the necessary data fields. This approach helps maintain data security by limiting access strictly to the required information for effective operation.
FastPass's SSPR system is designed with the concept of the Minimum Password Age policy in mind. This policy aims to prevent users from rapidly changing passwords to revert to an old one. By default, FastPass performs a password reset followed by setting the new password as chosen by the user, which may not directly consider the Minimum Password Age policy. However, FastPass includes built-in policies to control the frequency of password resets. We recommend configuring the system to allow up to two password resets per day. This setting is particularly helpful for scenarios where users might forget their newly created password, such as during a lunch break, ensuring they can efficiently manage their accounts without compromising security.
Yes, FastPass is designed for global accessibility, allowing users to connect from anywhere on the internet. However, we also prioritize security and offer a range of customizable access options. These include setting FastPass as an internal-only tool or restricting access to specific countries or through the client. We are committed to helping you find the ideal balance between ease of access and robust authentication methods. Contact us to have a discussion on the options at hand.
FastPass ensures regular updates for optimal performance and security. For the server components, such as the SSPR backend and IVM, we typically release a major version upgrade once a year. Additionally, we provide 2-3 smaller updates annually, focusing on introducing new features and addressing bug fixes. It's important to note that the Windows Client, along with the Password Interceptor and Filter components, are designed to be backward compatible with the latest two major versions. This compatibility feature offers flexibility and ease during the upgrade process, ensuring a smooth transition for users and IT administrators.
FastPass adopts a version-based approach for our End-of-Life policy, focusing on Major and Minor releases. We offer support for the current Major release and the last officially released Major version. For instance, as of now, we support versions 3.6 and 4.0. This means that if you encounter any issues with version 3.6, our support team will assist you, including making necessary fixes to facilitate upgrades. However, we do not provide the same level of support for versions that are two Major releases behind the current one. To ensure continuous support, we recommend upgrading at least once every year, aligning with our Major version release cycle.
Protect your Passwords today with FastPass
Get in touch with us today by filling up the form and our team will get back to you as soon as possible.