Enterprise Single Sign-On
Enterprise Single Sign-On (Enterprise SSO) implements the Single Sign-On approach for legacy applications that do not support SSO mechanisms. The system stores the user passwords for all applications that require credentials centrally and substitutes them into screen forms automatically when the application requires it.
Enterprise SSO relieves employees of memorizing passwords and keeping them secret, entering passwords manually from the keyboard, and changing passwords periodically according to password security policies.
For this purpose, the Enterprise SSO agent is installed on the user workstation. It tracks the start of applications and intercepts authentication forms when they appear on the screen. The agent also includes extensions for popular browsers (Internet Explorer, Google Chrome, Mozilla Firefox), which allows working with web applications.
Install and configure Enterprise SSO
Add and configure integrated applications
Where it can be used
The Enterprise SSO technology can be applied to any type of application (Windows, Java, Web, .NET) regardless of the architecture: single-tier, two-tier, three-tier, thick client, thin client, terminal applications.
Authentication technologies
Enterprise SSO supports the following authentication technologies:
- TOTP and HOTP one-time passwords
- one-time codes sent by SMS and email
- one-time codes and push notifications in the Axidian Key mobile application
- smart cards and USB tokens
How Enterprise SSO integrates with target systems
Enterprise SSO can be configured to work with an application without interfering with the server or the client part of that application. Support for a new application implies creating a special template in the XML format, implemented in the internal script-type language of Enterprise SSO. The language allows you to specify which application forms a reaction must be defined for. The reaction of Enterprise SSO may include repeated strong user authentication, filling in fields with registration data (such as the login and password), and activating the required controls (such as clicking the login button).
Password change in the target application
To minimize information security risks, most information systems support the ability to require the user to change the password value immediately after the first login to the system, or after the specified password lifetime expires. Enterprise SSO handles this situation and allows blocking the user access to the password change window automatically (transparently for the user), generating a new value, filling in the New value and Confirmation form fields, and clicking OK. After receiving a notification from the target system about the successful password change, the Enterprise SSO agent saves the new value in the Axidian Access database. From that moment, neither the user nor the administrator knows the new password value and therefore cannot log in to the target system bypassing Enterprise SSO.
The ability to handle the password change situation appears only if the ESSO application template supports a reaction to this type of window.
Terminal environment support
Enterprise SSO is adapted to work in a terminal environment, allowing employees to avoid the explicit use of their passwords when working with an application inside a terminal session. For this, the Enterprise SSO agent must be installed on the terminal server.
In some situations, when accessing especially critical applications, an employee may be required to go through an additional authentication procedure. If the technology implies the use of external equipment connected to the employee PC (such as a fingerprint scanner), communication occurs between the Enterprise SSO agent of the terminal server and the equipment. Enterprise SSO communicates over the Microsoft RDP or Citrix ICA protocols. This means that no additional software installation is required on the employee PC, except for the driver and the set of run-time libraries required for the equipment to work.