DCSIMG
FIM 2010 R2 Web Based SSPR using OTP - Patrick Layani

Patrick Layani

Sharing my thoughts...

FIM 2010 R2 Web Based SSPR using OTP

FIM 2010 R2 will include the possibility to use Self-Service Password Reset using OTP (One Time Password)

The following demo will show

  1. How to include the OTP functionality to the SSPR workflow (and MPR update)
  2. Full registration process
  3. Full SSPR process

Now…

There are two kind of OTP activities

  1. One-Time Password Email Gate
  2. One-Time Password SMS Gate

image

These activities are OOB included in the R2 version but have to be first added and configured in the “Password Reset AuthN Workflow” Workflow as follow (I will use the “One-Time Password Email Gate” in this demo):

Workflow

Go to the “Activities” tab in “Password Reset AuthN Workflow” Workflow, click on “add Activity” and select the “One-Time Password Email Gate” activity

image

Configure the Activity parameters, and “save”

Remark: Look at the registration mode, where there is a possibility to allow user to enter a personal email during the registration step, or not… (will be shown later in this demo)

image

the updated workflow look like:

image

Management Policy Rule (MPR)

Update the “Administration: Administrators can read and update Users” MPR. Add the “One-Time Password Email Address” attribute to the “Target Resources”

Note: You can also add the attribute “One-Time Password SMS Gate” (needed for SMS OTP via mobile)

image

Registration Process

Welcome screen

image

Enter your current password

image

Enter your answers

image

Enter your personal mail address for Email OTP

image 

Done!

image

Self-Service Password Reset

Here’s the procedure of resetting a password with SSPR and OTP

domain\username screen

image

fill the correct answers entered in the registration process

image

Enter the OTP that has been sent to your personal email

image

image

Choose a new password

image

Done!

image

Comments

Web-based Self-Service Password Reset with FIM 2010 R2 | Dominik's Cloud Security Blog said:

Pingback from  Web-based Self-Service Password Reset with FIM 2010 R2 | Dominik's Cloud Security Blog

# December 9, 2011 10:40 AM
Leave a Comment

(required) 

(required) 

(optional)

(required) 


Enter the numbers above: