One password across all applications
Synchronize passwords from Windows / AD / Azure AD to your SAP applications
Create seamless synchronization to enable more security for your users
When a Windows/AD password is changed FastPass synchronizes the password to all the user’s SAP instances.
- The password is updated within 10 seconds at the target system
- The user can have different user-ids for Windows and SAP
- The user can have multiple SAP accounts to be synchronized
- FastPass can handle many SAP instances simultaneously (more than 100)
- Fast and easy implementation with our assistance
- The Windows password is intercepted at the domain controllers to be forwarded to FastPass in encrypted format
Single-Sign On (SSO) is a great solution for many organizations where you want to ease the life of users.
But for many organizations password synchronization will give users the same ease with log-ins, when they only have ONE password.
With FastPass SAP password synchronization you can have synchronization for a low operating cost and a fast implementation. FastPass will cover all your SAP instances!
Easy to use self-service portal for all instances
Supports all SAP variations, and an unlimited number of SAP instances
Synchronize AD passwords to SAP passwords
SAP Password Reset Tool Pricing
FastPass SSPR and Synchronization is an enterprise product for cloud and on-premises competitively priced, based on the number of user-ids and functionality
- Easy to use self-service portal for all instances
- Supports all SAP variations, and an unlimited number of SAP instances
- Functionality as FastPass Enterprise
- Synchronize AD passwords to SAP passwords
Contact FastPassCorp to discuss solutions to your situation
Frequently Asked Questions
The fundamental requirement for FastPass Sync for SAP is a single Virtual Windows server (versions 2019-2022). Additionally, FastPass Interceptor needs to be installed on all Domain Controllers to facilitate Windows password interception. For each SAP instance, a dedicated service account is necessary, along with the installation of a small ABAP program. These components ensure seamless integration and functionality of FastPass Sync with your SAP system.
FastPass supports a wide range of SAP versions, encompassing both ABAP and Java-based systems. This includes major versions like HANA, ERP (ECC), NetWeaver, S/4 HANA, CRM, SCM, SRM, and Solution Manager. Additionally, it supports various business software modules such as ADP, SAC, ABAP, AFS, BW, BI, and others like FICO, GRC, EHDM, HRMS, IDT, IBP, KW, IBP, PS, PP and SD and more. If your specific SAP version isn't listed, please contact us, as we likely support it as well.
The cost would be per user and this covers unlimited number of SAP instances. For a subscription model the cost is only around 20-30 cents per month per user.
The servers are only active when a password change occur. The load on the servers depend on number of SAP instances and number of password changes. It will in general not be noticed, but if many users simultaneously change password, we can expect some bit of load on the FastPass servers (max of xx users / 10 seconds).
In most cases, password synchronization with SAP through FastPass is completed in under 15 seconds. This duration can vary depending on factors like hardware specifications, the number of users, and the number of target systems. During peak times, such as Monday mornings following a holiday break, synchronization may take slightly longer, typically ranging from 30 seconds to 1 minute, due to higher system loads.
We offer monitoring and operational standards for the ongoing operation of FastPass Sync.
Yes we do. FastPass Sync can also support:
IBM X, IBM Z, Oracle, Microsoft SQL, LDAP, Google, eDirectory
Completely aligning the password policies between Active Directory and SAP is not always feasible due to certain inherent differences. For instance, Active Directory and SAP may have different definitions for special characters, and some SAP systems require passwords to start with a letter. However, with FastPass Password Filter, these discrepancies can be effectively managed, ensuring smoother operation. For FastPass Sync customers, this filter is provided free of charge.
Yes, FastPass has a user mapping engine for that exact purpose. Usually this is the case, either for some or all users. Sometimes we can make the mapping manually using Active Directory data, a different field, email address, UPN name or parts of the SAMAccountname. In other cases we get data from an Identity System and in yet other cases we get data from SAP and map on e.g. Email address. Contact us to find the right solution.
Can The FastPass Sync engine is built for load, spawning out multiple threads to handle load. We have customers with over 95 target systems(typically this is having FastPass handling the whole landscape, Sandbox, Development, Test, QA and Production).
By default FastPass will unlock the account, but only if the account is locked because of too many failed password attempts.
Yes, the password set by FastPass will be productive.
Yes, FastPass is compatible with Secure Network Communications (SNC) Client Encryption, ensuring it can function effectively in environments with SNC enabled for enhanced network security.
FastPass is equipped with a resilient retry system for such scenarios. By default, it will attempt to retry the synchronization process 10 times, with a 2-minute interval between each attempt. These retry settings are adjustable to better suit your specific environment. Moreover, in instances where the SAP system experiences an extended downtime, FastPass provides an option to manually trigger a synchronization for a chosen time interval. However, this feature needs to be enabled, as it involves data deletion considerations.
FastPass is designed for robustness and stability, ensuring that a downtime in one SAP system does not halt or significantly slow down the overall synchronization process. Instead, only the synchronization with the affected SAP system will be subject to retries as outlined previously. This ensures that the synchronization with other systems continues unaffected.
Absolutely, FastPass is fully compliant with FIPS (Federal Information Security Management) 140-2 standards, starting from version 4.0 onwards. We utilize a 256-bit AES algorithm for encryption and a PBKDF algorithm for hashing. This compliance extends across all FastPass components, from the Windows Client to the Server and Domain Controller parts, ensuring robust security throughout the system.
Indeed, FastPass's cloud operations are proudly certified with Cyber Essentials Plus, affirming our commitment to robust cybersecurity practices.
Yes, FastPass provides the functionality to automatically delete user data and restrict access as needed. This is achieved by FastPass regularly checking the source user repository. User data can be set to be automatically deleted under certain conditions, such as if the user account is deleted or disabled, is no longer a member of a group authorized to use FastPass, or becomes a member of a group specifically designated for deletion. This ensures that user data management aligns with the current status and permissions within the organization. Please note that the users history actions are kept in the Audit log.
Absolutely, FastPass includes a customizable list of prohibited passwords to help enhance security. We provide a top list of commonly used weak passwords that we recommend you utilize as a starting point. Additionally, it's a good practice to expand this list by adding specific terms related to your company, such as the company name, product names, and other relevant terms. This approach helps ensure users avoid common and potentially vulnerable passwords, thereby strengthening overall password security.
Yes, FastPass features a comprehensive and detailed audit log that meticulously records every action. This includes not only user activities but also all operations conducted within the Help Desk tool and the Admin interface. This extensive logging capability ensures thorough tracking and accountability for all interactions within the FastPass system, providing an essential tool for security and administrative oversight.
All personnel supporting FastPass cloud are as a minimum are BPSS checked and are annually trained on Data Protection and personal data best practice. They are also required to sign NDAs and the Information Security Policy and Data Protection policy. These policies are aligned with ISO 27001 / EU GDPR. Read more about GDPR and Service Desk here: https://www.fastpasscorp.com/why-fastpass/insights/idc-gdpr-password-reset/
Absolutely. FastPass prioritizes data security, especially during data transit. One of our fundamental security measures is the mandatory use of SSL (Secure Sockets Layer) certificates for all communications. This ensures that any data exchanged between users and FastPass is encrypted, significantly enhancing security and protecting against data interception or unauthorized access during transmission. For Cloud operation TLS 1.2 is used.
Yes, FastPass ensures that all sensitive data is encrypted when stored in our database. This includes any data at rest within the FastPass system, providing an added layer of security against unauthorized access. For specific details on the types of data that are read, stored, and require write access within Active Directory and Entra ID, we recommend consulting the respective documentation. This information will give you a comprehensive understanding of our data handling practices and the security measures in place to protect your data at all times.
Yes, FastPass is fully compatible with LSA Protection. The FastPass Interceptor and Password Filter components are signed by Microsoft, ensuring compliance and functionality with LSA Protection enabled. Adhering to the Microsoft Security Development Lifecycle (SDL), FastPass integrates seamlessly with the Local Security Authority Server Service (LSASS), allowing for safe and secure password synchronization in environments where LSA Protection is applied.
FastPass does not support direct password synchronization from Entra ID (Azure AD) to other systems. This is because password synchronization requires identical hashing methods, a process currently specific to Microsoft's synchronization between Entra ID and Active Directory. However, FastPass offers alternative password management solutions, such as the Selective Password feature, where users can set passwords for one or more systems via the FastPass web portal.
FastPass ensures regular updates for optimal performance and security. For the server components, such as the SSPR backend and IVM, we typically release a major version upgrade once a year. Additionally, we provide 2-3 smaller updates annually, focusing on introducing new features and addressing bug fixes. It's important to note that the Windows Client, along with the Password Interceptor and Filter components, are designed to be backward compatible with the latest two major versions. This compatibility feature offers flexibility and ease during the upgrade process, ensuring a smooth transition for users and IT administrators.
FastPass adopts a version-based approach for our End-of-Life policy, focusing on Major and Minor releases. We offer support for the current Major release and the last officially released Major version. For instance, as of now, we support versions 3.6 and 4.0. This means that if you encounter any issues with version 3.6, our support team will assist you, including making necessary fixes to facilitate upgrades. However, we do not provide the same level of support for versions that are two Major releases behind the current one. To ensure continuous support, we recommend upgrading at least once every year, aligning with our Major version release cycle.
FastPass V4 - Secure Enterprise Passwords
FastPass V4 brings comprehensive password protection to secure organizations. Making passwords complex, avoiding the use of dictionary passwords and popular phrases as part of the password, changing the password regularly, and protecting the password processes will make your organization unattractive to hackers.
DOWNLOAD FASTPASS SYNC FAQ
"The number of forgotten passwords per involved user per year has dropped from 1.6 to 0.3. This is an improvement of 83%!"
Receive an individual and specific overview of FastPass pricing
Get in touch with us today by filling up the form and our team will get back to you as soon as possible.