Protectimus DSPA - 2FA Solution for Active Directory
di PROTECTIMUS LIMITED
Protectimus Dynamic Strong Password Authentication - MFA solution for Active Directory, LDAP, DBMS
The Protectimus DSPA (Dynamic Strong Password Authentication) software allows integration of the Protectimus two-factor authentication solution with Microsoft Active Directory or any other user directory (AD/LDAP, DBMS). Once integrated, dynamic one-time passwords (OTP) will be required for access to all services connected to this directory, such as Winlogon, RDP, ADFS, OWA, and others.
Protectimus DSPA continuously updates users' passwords in the directory with time-based one-time passwords (TOTP). The administrator defines the password rotation interval, which must be a multiple of 30 seconds.
From the user's perspective, authentication is simple: users enter the current OTP generated by the Protectimus SMART authenticator app or delivered via the Protectimus BOT chatbot. The OTP serves as the user's current directory password and changes automatically according to the configured rotation interval.
Protectimus DSPA (Dynamic Strong Password Authentication) Advantages:
1. Scheduled password changes:
The Protectimus DSPA component regularly updates users' passwords in Active Directory. The administrator specifies the password rotation interval, which must be a multiple of 30 seconds. Passwords are synchronized with one-time passwords generated by the Protectimus MFA platform, ensuring that credentials remain dynamic and continuously changing.
2. On-premise platform:
The Protectimus DSPA component for Active Directory security and the Protectimus two-factor authentication platform are installed on the client's premises. You can manage all the data and processes yourself to ensure the maximum level of infrastructure security. The Protectimus on-premise platform is designed for multidomain environments and offers cluster, replication, and backup features.
3. Hassle-free administration:
Unlike traditional MFA solutions, Protectimus DSPA frees administrators from the need to install additional software on client machines and update it periodically. After integrating the Protectimus DSPA component with Active Directory, dynamic OTP-based passwords are automatically enforced across all services connected to the directory, including Winlogon, RDP, OWA, ADFS, and others.
What problems does Protectimus DSPA solve?
1. Existing MFA solutions protect only part of the infrastructure:
Many standard MFA solutions add two-factor authentication exclusively to endpoints. This leaves a vulnerability where hackers can potentially attack your infrastructure by bypassing two-factor authentication and directly accessing your user directory. For example, it's possible to access Active Directory via the Windows command line, and having knowledge of a user's login and password is enough to perform actions on their behalf. By implementing Protectimus DSPA, you can ensure that no one gains access to AD, LDAP, or user accounts in your database without a valid OTP-based dynamic password, regardless of how the authentication request is initiated.
2. Administrators need to install and support 2FA plugins on multiple platforms:
To configure two-factor authentication for all employees and the various services a company utilizes, administrators are often required to implement multiple 2FA plugins for different platforms and install additional software on each client machine. Furthermore, all this software needs constant updates. However, by integrating the Protectimus DSPA component with Active Directory, dynamic OTP-based passwords become mandatory for all services connected to the directory, including Winlogon, RDP, ADFS, OWA, and others.