Imprivata OneSign 4.1
in Security appliances
Verdict
Pricey for SMBs but Imprivata's OneSign offers a smart SSO solution packed with security features
Review Date: 16 Nov 2009
Price when reviewed: £55 (£63 inc VAT)
Overall Rating

Features & Design

Value for Money

Performance

Single sign-on (SSO) is the holy grail of network administration as it can save so much time and improve security. With a single username and password, users can gain authenticated access to all applications and services without calls for lost or forgotten passwords.
Imprivata's OneSign provides complete SSO implemented as an appliance, supporting authentication client/server, web and legacy applications. An SSO agent installed locally on each client captures their authentication credentials, stores them on the appliance and proxies them when required.
Imprivata offers a choice of agents, with the standard version used on systems of a single user. The Workstation Agent is deployed to systems that have multiple users, while a third is used for Microsoft Terminal Services and Citrix MetaFrame environments and is installed on the server.
OneSign handles a range of authentication methods, including passwords, tokens and fingerprints. A new feature is Imprivata's Physical/Logical, which links network access to the physical presence of the user. You map a user's profile to their access card so they can only use a workstation and network resources if the building has registered their entry.
Enterprise reviews
Read all the latest business reviews in our dedicated Enterprise sectionAfter the wizard-based setup routine you can add users and security policies. The latter can be used to apply lockouts, the number of allowed login attempts and password strength. Policies can also issue challenges when an account has been inactive for a time, and an offline mode when a link to the OneSign server isn't available.
We used email to deploy the agent where users are advised of the download location on the appliance. The agent modifies the Windows login prompt and offers options for authentication methods. Next, you define applications and the APG (application profile generator) is used to learn this process where you load an application and drag a target from the APG onto its login screen. It presents a form with the relevant fields filled in and you can check that each field is correctly identified by clicking on it.
We used access to web mail clients to test this. After policy deployment, users were required to log in as normal, and the agent captured their details from the browser and stored them on the appliance. The next time they loaded the login screen their details were proxied and entered for them by the agent.
OneSign provides plenty of report tools to keep a close eye on enrolments, failed logins, lockouts and so on. You can also select users to be monitored, where notifications will be sent to you when they trigger specific events.
We found the enrolment process to be lengthy, but once completed it makes light work of the login process. For small user bases, the OneSign solution is expensive but it can pay back these costs with reduced administration and support for password management.
Author: Dave Mitchell
advertisement
- Windows 7 XP Mode now runs on all processors
- Intel claims new processors boost security
- Tiny domain names to be released in UK
- Google launches bolt-ons for web apps
- Microsoft warns users off 64-bit Office 2010
- Google to steal Office Web Apps' thunder?
- Network provider admits customers still don't trust the cloud
- Twitter earned Dell $9 million
- Amazon cloud "doesn't come down at Christmas"
- Microsoft: Oracle's fighting the "evolution of the industry"
- What's that eggy smell in the server room?
- How to change the default template in Word 2007
- Book review: Rework by Jason Fried and David Heinemeier Hansson
- Panorama parents deserve their file-sharing fine
- Google and BT offer free website service to British businesses
- Lords' last chance to protect broadband customers
- Extreme handwriting recognition on the Dell Latitude XT2
- 12 surprising things that Wolfram Alpha knows
- Nokia N900: phone or pocket computer?
- The sinister side of Spotify
- The Complete Guide to Office 2010
- The complete guide to Office 2010: Web Apps
- The complete guide to Office 2010: Word
- The complete guide to Office 2010: Excel
- The Complete Guide to Office 2010: The Big Changes
- My return to parallel processing
- 50 ways to work faster
- The ten rules of building a small business network
- What to look for when buying a business laptop
- How to start a low-risk web business
- The ease of hacking a WEP network
- Delving into the Norton 2010 line-up
- Banish your Wi-Fi woes
- How to commit Facebook suicide
- Which smartphone keyboard is the best?
- We can beat the botnets
- Paying for code doesn’t mean owning it
- Cracking the iSCSI conundrum
- The perfect open-source task scheduler
- Exploring Microsoft Office 2010 beta
advertisement







Printed from www.pcpro.co.uk