This website uses cookies. By clicking Accept, you consent to the use of cookies. Click Here to learn more about how we use cookies.
Accept
Reject
  • RSA.com
  • Home
  • Advisories
    • SecurID
    • SecurID Governance & Lifecycle
  • Documentation
    • SecurID
      • Authentication Agents
        • API / SDK
        • Apache Web Server
        • Citrix StoreFront
        • IIS Web Server
        • MFA Agent for macOS
        • MFA Agent for Windows
        • Microsoft AD FS
        • Microsoft Windows
        • PAM
      • Authentication Engine
      • Authentication Manager
      • Cloud Authentication Service
      • Hardware Appliance
        Component Updates
      • Hardware Tokens
      • Integrations
      • SecurID App
      • SecurID Authenticator for macOS
      • SecurID SDK
      • Software Tokens
        • Android
        • iOS
        • macOS
        • Token Converter
        • Windows
    • SecurID Governance & Lifecycle
    • Technology Partners
  • Downloads
    • SecurID
      • Authentication Agents
        • API / SDK
        • Apache Web Server
        • Citrix StoreFront
        • IIS Web Server
        • MFA Agent for macOS
        • MFA Agent for Windows
        • Microsoft AD FS
        • Microsoft Windows
        • PAM
      • Authentication Engine
      • Authentication Manager
      • Cloud Authentication Service
      • Hardware Appliance
        Component Updates
      • Hardware Tokens
      • Integrations
      • SecurID Authenticator for macOS
      • Software Tokens
        • Android
        • iOS
        • macOS
        • Token Converter
        • Windows
    • SecurID Governance & Lifecycle
  • Community
    • SecurID
      • Blog
      • Discussions
      • Events
      • Idea Exchange
      • Knowledge Base
    • SecurID Governance & Lifecycle
      • Blog
      • Discussions
      • Events
      • Idea Exchange
      • Knowledge Base
  • Support
    • Case Portal
      • Create New Case
      • View My Cases
      • View My Team's Cases
    • Community Support
      • Getting Started
      • News & Announcements
      • Ideas & Suggestions
      • Community Support Articles
      • Community Support Forum
    • Product Life Cycle
    • Support Information
    • General Security Advisories
  • Education
    • Blog
    • Browse Courses
      • SecurID
      • SecurID Governance & Lifecycle
    • Certification Program
    • New Product Readiness
    • Student Resources
Sign In Register Now
cancel
Turn on suggestions
Auto-suggest helps you quickly narrow down your search results by suggesting possible matches as you type.
Showing results for 
Search instead for 
Did you mean: 
Announcements

SecurID® Community Blog

Subscribe to the official SecurID Community blog for information about new product features, industry insights, best practices and more.
  • SecurID Community
  • :
  • Products
  • :
  • SecurID
  • :
  • Blogs
  • :
  • Stronger, Simpler and Better – 3 Reasons on choosing SecurID® for Passwordless Windows log-in

Stronger, Simpler and Better – 3 Reasons on choosing SecurID® for Passwordless Windows log-in

NandiniV
Occasional Contributor NandiniV Occasional Contributor
Occasional Contributor
1 0 943
  • Subscribe to RSS Feed
  • Mark as New
  • Mark as Read
  • Bookmark
  • Subscribe
  • Email to a Friend
  • Printer Friendly Page
  • Report Inappropriate Content
‎2021-04-29 10:05 AM

There’s been a lot of hype around passwordless. For all good reasons. First, Organizations still face password problems. The amount of time Information Technology (IT) teams spend to manage users’ login credentials that include usernames and passwords has been increasing over the last few years. Second, although organizations are spending a tremendous amount of time on password management, they still pose a security risk. Because passwords are just not secure. Cyberattacks are on the rise and 85% of them are related to compromised or stolen credentials. And what about the user experience? Lack of convenience leading to sub-optimal user behavior while managing the passwords finally leaving them frustrated.

The year 2020 saw a major shift in the remote workforce. As the initial move was taken in make-shift fashion to quickly embrace the unprecedented, this has albeit accelerated the digital transformation initiatives for organizations. Today enterprises are looking for ways to enable their workforce for permanent remote working by providing a secure means to log in to their workstations. An option that is not only frictionless but also boosts productivity.

SecurID has been on the forefront in offering passwordless authentication solution when it first introduced the support for Web authentication using FIDO2 (Fast Identity Online). FIDO2 being an open authentication standard strives to eliminate passwords by leveraging standard asymmetric cryptographic techniques and makes it convenient and compatible across platforms and devices without changing the security profile.

With the latest release of SecurID (MFA Agent 2.1 for Microsoft Windows),SecurID is  excited to extend the passwordless sign-in experience to Windows 10 laptops and desktops. A solution that provides multifactor authentication (MFA) to workstation logins leveraging the FIDO2 as a hardware authenticator meets the high assurance levels required for proving compliance, without impacting user convenience.    

The 3 compelling reasons why you should start considering a passwordless solution for your workforce today with SecurID:

  1. Stronger: More than “Something you know”

FIDO2 security keys are better phishing resistant and prevent Man in the Middle (MitM) attacks. Windows login with FIDO2 security key as a strong form factor adds multiple layers of security like FIDO2 security key PIN, which is used to unlock the key itself and user presence tap on the key to make sure it is a human using the key and not a malware acting on behalf of the user.   Additionally, you can also configure other SecurID authentication methods (like Biometric/Push/Tokencode) as an additional authentication in addition to FIDO2  as part of sign-in.

  1. Better:  Designed for seamless experience “Anytime Anywhere”  

Once you are enrolled for FIDO2 passwordless authentication, all you need is your FIDO2 security key and you are good to go - whether online or offline. If you are off the network and traveling, passwordless authentication works the same way it did when you were online. Because the last thing we want you to worry about is carrying multiple devices or different authentication experiences while roaming. We understand that there can be situations when a user has misplaced or lost their FIDO2 security key – Worry not, we have you covered. With emergency access support, the user can gain secure and easy access to their Windows 10 workstations in those circumstances and can stay productive.

  1. Simpler: Path to P@$$w0rdless need not be complex

While we make a compelling case against passwords, you may be wondering how to go from password-laden infrastructure to a passwordless one. The transition is a journey and not an overnight switch. While you start thinking about your passwordless strategy, the following are the essential features of SecurID that you could consider and rely on.  

  • Go in phases: Before rolling out to the entire workforce, select subset of users (using challenge groups feature) where passwordless be a good fit and start piloting.
  • Flexible fallback options: SecurID allows you to configure other multifactor authentication methods that provide secure authentication mechanisms as fallback options when FIDO2 is not available.
  • Simple recovery flow: In addition to supporting FIDO2 in offline mode, the Agent presents various options for the user to either use fallback options or replace with a new key in case of stolen/lost keys. All nestled intuitively in the login flow.

To know more about FIDO2 passwordless authentication refer to the MFA 2.1 For Microsoft Windows Release Notes.

Other enhancements that should not go unnoticed include: 

Email Customization options

If you are the Admin and wish you had a way to customize the email template to add some useful information to assist users. Well, we hear you. SecurID Cloud Authentication Service already provides email templates to notify users on device registration, deletion and delivering emergency codes. The April month’s release expands the signature field of the template to include up to 2000 characters. You can use this field to include any additional instructions or global helpdesk contact info or anything that you think useful.

JIT user sync for Admin-led on-boarding

While SecurID offers a self-service portal, My Page, which end users frequently use to manage their authenticators, there are scenarios where Administrators choose not to enable the self-service portal for end-users and instead onboard users themselves.  This enhancement allows help-desk Administrators to search for a new user, who is not yet synchronized to the SecurID Cloud Authentication Service, and generate a one-time mobile registration code for them to register their Authenticator. It also allows Admin to add user's mobile number for SMS delivery if needed. This capability is also part of User detail APIs to help integrate with custom help-desk tools. Now, Administrators can expedite new user onboarding without any delays or requiring bulk-sync.

 Anomalous users data shown on the Risk dashboard is now available through Admin APIs

 With this enhancement, Identity, Security operations and Incident response teams can gain visibility into top anomalous users within their organization based on user's and peer's access patterns. Using this Cloud Administration Anomalous Users  API, anomalous user data can be made available to the external system for further analysis, which can help Administrators to investigate and remediate any potential access risks to their organizations.

To know all about the product updates and releases SecurID Product Release Notes.

Labels
  • Announcements
  • Features
Tags (8)
  • Tags:
  • Cloud Authentication Service
  • fido2
  • MFA Agent for Microsoft Windows
  • passwordless
  • remote workforce
  • SecurID
  • SecurID Access
  • Workstation log-in
1 Like
Share

You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.

  • Comment
Latest Articles
  • In the era of Hybrid Work – SecurID macOS Authenticator is here!
  • SecurID Cloud Authentication Service Transitions Identity Source Synchronization from Scheduled Sync...
  • SecurID JUNE Release Accelerates RSA Cloud First Strategy
  • Introducing the New SecurID™ App 3.0 for iOS® and Android™
  • Stronger, Simpler and Better – 3 Reasons on choosing SecurID® for Passwordless Windows log-in
  • Defense-in-Depth: RSA SecurID® Access in November 2020
  • Protect Stormshield VPN with RSA MFA
  • Optimize your Dynamic Workforce with RSA SecurID Access
  • Securing access to corporate endpoints is made easy with RSA MFA Agent 2.0.1 for Microsoft Windows
  • New RSA SecurID Access & Authentication Manager Training – Your commute hours have never been so pro...
Labels
  • Announcements 3
  • Features 1
  • Resources 1
  • Tutorials 27
  • Use Cases 3
  • Videos 93
Powered by Khoros
  • Blog
  • Events
  • Discussions
  • Idea Exchange
  • Knowledge Base
  • Case Portal
  • Community Support
  • Product Life Cycle
  • Support Information
  • Customer Success
  • About the Community
  • Terms & Conditions
  • Privacy Statement
  • Provide Feedback
  • Employee Login
© 2022 RSA Security LLC or its affiliates. All rights reserved.