Educause Security Discussion mailing list archives

Re: Self service password reset tools


From: "Gallese, Brady T." <gallese () SUSQU EDU>
Date: Thu, 31 Mar 2011 13:31:35 +0000

All,

Over winter break, we installed Web Active Directory's People Password.  
(http://www.webactivedirectory.com/products/peoplepassword/).  We only use it for students at this time, but it has 
been working well, and was easy to deploy.  Students can now unlock their own account, reset their password if they 
forgot it, or reset the pw if it expired.  You can pre-populate the questions/answers with data you already have - 
pulled from internal data / your ERP (we used last 4 of SSN and DOB), or choose to do an enrollment process where 
students choose their own questions/answers.  Additionally, it can send out e–mails to students warning them that their 
passwords will expire or have expired.  We demo'd/eval'd a few products and found this one to have the features we 
needed, for the right price.

Thanks,
Brady

________________________________
Brady Gallese ‘07
Technical Services Helpdesk Engineer
Office of Information Technology
Susquehanna University
514 University Avenue
Selinsgrove, PA 17870-1164
570.372.4470
gallese () susqu edu<applewebdata://5BD5F98F-7401-4C6B-B009-FB2AB94B6195/gallese () susqu edu>
[cid:915AF944-DA9C-4C2C-A508-9F10F24A2243]

From: Dan Han/HSC/VCU <s2dhan () VCU EDU<mailto:s2dhan () VCU EDU>>
Reply-To: The EDUCAUSE Security Constituent Group Listserv <SECURITY () LISTSERV EDUCAUSE EDU<mailto:SECURITY () 
LISTSERV EDUCAUSE EDU>>
Date: Wed, 30 Mar 2011 17:11:23 -0400
To: <SECURITY () LISTSERV EDUCAUSE EDU<mailto:SECURITY () LISTSERV EDUCAUSE EDU>>
Subject: [SECURITY] Self service password reset tools

Dear list,

I wanted to see if anyone is using self service password reset tools in your organization, I am particularly interested 
in implementations for enterprise directory structures, whether if it is AD, Novell, Open Directory, or others. If 
possible, please share your experience of the tool used. Further, I am interested to find out how are you verifying the 
identity of the person performing a password reset. Thank you in advance for your help.

Best regards,

Dan Han
Information Security Officer
Virginia Commonwealth University


Current thread: