Chat now with support
Chat with Support

Password Manager 5.14.3 - Administration Guide

About Password Manager Getting started Password Manager architecture
Password Manager components and third-party applications Typical deployment scenarios Password Manager in a perimeter network Management Policy overview Password policy overview Secure Password Extension overview reCAPTCHA overview User enrollment process overview Questions and Answers policy overview Password change and reset process overview Data replication Phone-based authentication service overview
Management policies
Checklist: Configuring Password Manager Understanding Management Policies Adding or cloning a new Management Policy Configuring access to the Administration Site Configuring access to the Password Manager Self-Service Site Configuring access to the Helpdesk Site Configuring Questions and Answers policy Workflow overview Custom workflows Custom activities Password Manager Self-Service Site workflows Helpdesk workflows Notification activities User enforcement rules
General Settings
General Settings overview Search and logon options Importing and exporting configuration settings Outgoing mail servers Diagnostic logging Scheduled tasks Web Interface customization Instance reinitialization Realm Instances Domain Connections Extensibility features RADIUS Two-Factor Authentication Internal Feedback Customizing help link URL Password Manager components and third-party applications Unregistering users from Password Manager Bulk Force Password Reset Fido2 key management Working with Redistributable Secret Management account Email templates
Upgrading Password Manager Administrative Templates Secure Password Extension Password Policies Enable 2FA for administrators and helpdesk users Reporting Password Manager integration Accounts used in Password Manager Open communication ports for Password Manager Customization options overview Glossary

Introducing Secure Password Extension

Secure Password Extension is an application that provides one-click access to the complete functionality of the Self-Service Site from the Windows logon screen. Secure Password Extension also provides dialogs displayed on end-user computers, these dialogs notify users who must create or update their Questions and Answers profiles with Password Manager. Secure Password Extension is included on the installation CD and is deployed through Group Policy. For information on how to deploy and configure Secure Password Extension on end-user workstations in the managed domain, see Deploying and configuring Secure Password Extension.

Secure Password Extension supports the authentication model in the following systems

  • Windows 8.1

  • Windows 10

On workstations running windows 8.1 and 10, Secure Password Extension adds an icon under the Sign-in options to the user tile of the windows logon screen. By clicking these buttons and links, users can open the Self-Service Site.

When users connect to the Self-Service Site from the Windows logon screen, anonymous access is enabled and the functionality of Microsoft Internet Explorer is restricted, thereby preventing the actions that may pose a security threat. Once users open the Self-Service Site search page from the Windows logon screen, they cannot access any other Web site, or open a new browser window or a context menu.

Understanding how Secure Password Extension works

This section explains how Secure Password Extension locates the Self-Service Site and launches notification dialogs on end-user computers that remind users to create or update their Q&A profiles.

Locating Self-Service Site

By default, Secure Password Extension uses a URL from a service connection point to locate the Self-Service Site. You can also override the default URL published in the service connection point by specifying a different URL in the General Settings of the Administration Site or by specifying a different URL in the supplied administrative template and applying the template to selected users.

For more information, see:

Obtaining Self-Service Site URL from service connection point

Every Password Manager instance publishes its service connection points in Active Directory. Secure Password Extension uses service connection points to automatically locate the Self-Service Site.

Service connection points are objects in Active Directory that hold information about services. Services can publish information about their existence by creating service connection points in Active Directory. Client applications use this information to find and connect to instances of the service. When an instance of Password Manager is installed, the Password Manager Service publishes its service connection points in Active Directory. To locate the server where the Self-Service Site is deployed, Secure Password Extension uses the service connection points published by Password Manager Service instances in Active Directory.

  1. Password Manager instance publishes a service connection point in Active Directory.

  2. Secure Password Extension locates the service connection point.

  3. Secure Password Extension obtains the necessary data from the service connection point (URL path to the Self-Service Site).

  4. Secure Password Extension opens the Self-Service Site.

Related Documents

The document was helpful.

Select Rating

I easily found the information I needed.

Select Rating