Static password randomization
  • 10 Jan 2025
  • 1 Minute à lire
  • Sombre
    Lumière
  • PDF

Static password randomization

  • Sombre
    Lumière
  • PDF

The content is currently unavailable in French. You are viewing the default English version.
Résumé de l’article

If password randomization is enabled, OneSpan Authentication Server replaces the static Windows password with a randomly generated password for each logon, while adhering to strict formatting rules. Password randomization occurs transparently for the user, who only needs to enter the user ID and an OTP for authentication. The password is generated in the background.

Since the password is randomized for each authentication procedure, users are prevented from logging on to client workstations that do not have Digipass Authentication for Windows Logon installed.

After a successful authentication towards OneSpan Authentication Server, password randomization replaces the static password used to authenticate the Windows client to the Windows domain with a randomly-generated static password. This randomly-generated password is no longer known to the user, thereby forcing the user to use OTP authentication.

The randomly-generated password remains constant in the OneSpan Authentication Server user account record, and a corresponding attribute is added to trace randomization status.

Configuring password randomization requires the following:

  • LDAP or Windows back-end authentication towards Active Directory.
  • Password randomization is enabled in the effective policy.

If password randomization is enabled in OneSpan Authentication Server, the effective policy used by OneSpan Authentication Server must not apply password proxying for the changeBackendPassword SOAP command. Otherwise, this will lead to a user with a randomized password being able to change the password.


Cet article vous a-t-il été utile ?

Changing your password will log you out immediately. Use the new password to log back in.
First name must have atleast 2 characters. Numbers and special characters are not allowed.
Last name must have atleast 1 characters. Numbers and special characters are not allowed.
Enter a valid email
Enter a valid password
Your profile has been successfully updated.
ESC

Ozzy, facilitant la découverte de connaissances grâce à l’intelligence conversationnelle