多因素身份验证(MFA)有助于减少攻击面,并通过要求更高级别的身份保证来保护您的组织。在这个数字不安全的世界中,使用全面的企业MFA解决方案可以提高您组织的安全性。可以为网络中的所有用户和所有系统启用MFA,包括云和本地应用程序和端点。利用ManageEngine ADSelfService Plus在您的组织中有效且毫不费力地部署Active Directory多因素身份验证。
在这种混合工作文化中,ADSelfService Plus通过本地Active Directory的自适应MFA,对服务器和工作站的本地和远程登录尝试都提供了强大的保护。
ADSelfService Plus的企业MFA从暴力、密码喷雾和字典攻击等成功攻击中窃取的凭据,由于强大的身份验证器(如生物识别和Yubikey)而变得无能为力。
ManageEngine MFA设置可帮助您的组织遵守合规性规定的监管规范,如PCI DSS、NIST SP 800-63B和HIPAA。
让我们考虑一个尝试登录其Windows、macOS或Linux机器的用户。以下是启动登录过程时ADSelfService Plus的MFA的工作原理:
MFA通过实施除用户名和密码身份验证方法之外的多种身份验证方法来帮助保护用户对资源的访问。当MFA解决方案到位时,黑客对窃取的密码没有任何用处,因为他们必须通过其他身份验证因素才能访问资源。
ADSelfService Plus' enterprise MFA capability secures cloud application access through SSO; endpoint logons, like VPNs, OWA, Windows, Linux, and macOS; and self-service activities like password reset, account unlock, and password change. It supports 19 different MFA authentication factors from which admins can choose their preferred factors to present to their users.
ADSelfService Plus simplifies MFA configuration for admins by providing an enriched, user-friendly console. It enables you to set up different MFA flows for different groups or departments in your organization, i.e., you can configure specific methods of MFA for privileged accounts in your Active Directory. You can choose the number of authenticators that users must verify with for each activity, like self-service, application logons, and endpoint logons. ADSelfService Plus also makes the MFA enrollment process seamless for both users and admins.
ADSelfService Plus offers conditional access policies that help you fine-tune the access rules for IT resources, such as applications and endpoints, based on a user's location, IP address, time of access, and device used. You can preconfigure rules based on these factors and, depending on these rules, users are given MFA methods to verify their identities with.