Quantcast
Channel: Support Portal
Viewing all 2881 articles
Browse latest View live

Re : New Technician from Domain?

$
0
0
Thanks for your answer.
I updated our build to 5325 through Service Pack Installation and cleared the browser history.

The issue remains...
What rights does the Serviceaccount need to declare someone a technician?

Thanks in advance.

GINA

$
0
0
Good morning,

I am trying to test GINA access to ADSSP. I have tried installing it on 3 different machines, and cannot see it in the logon screen. Am I missing a step? I've copied the ADSelfServicePlusClientSoftware.msi file to the OS and installed it, with no errors. Still I'm not seeing anything. Thanks.

Cannot change font for "Sign in" Box

$
0
0
I have set the font for everything to Arial but I cannot seem to make it work that the "Sign in" Box shows anything than times new roman. Which file do I have to alter to set Arial?
With the developer tools of the browser I see that there is:

<style>
 .fntFamily{font-family: times new roman,times,serif;}
 .fntSize{font-size:12px;}
 .common-textcolor{color:#e2001a !important;}
 .common-bgcolor{background:#e2001a !important;}
 .common-bordercolor{border-color:#e2001a !important;}
 .adsfntFamily{font-family: times new roman,times,serif;}
 .adsfntSize{font-size:12px;}
</style>

but which file is it?

I want to go live with this product, but my marketing department will go nuts with this..

SelfService App XML?

$
0
0
Hi,

We are pushing out iPads to a number of mobile users and want to have the AD Self Service Mobile App installed on each device through our MDM application catalog.  In addition we want to make sure the app is deployed pre-configured with the server settings already set so there is no user setup required.  

Is that do-able?  XML config possibly?

Best Regards,
Brian Mansfield

Solved: Users locked out of Gmail after failed password reset

$
0
0
/long rant incoming

We rolled out AD SSPlus to our campus(about 16k total users) and all seemed to be going well for the most part.  However, we started getting calls that some users were unable to get into their email accounts AFTER they tried to reset their password, but they were able to log in to any site that used Active Directory authentication.

This was very strange to hear and I will explain why.

We use Google Business for our email, and we utilize Google Apps Password Synchronizer (GAPS) in our Active Directory environment.  For those not familiar with it, GAPS monitors active directory for any password changes, and then replicates those changes to Google.  This way if a user does a password reset, or a password change to their AD account, that change will also apply to their email login with Google.

So what we discovered was that if a users attempts to "RESET" their password to the same password they already had, they would get an error in Self Service Plus that they were violating the password history rules and that the password reset was unsuccessful.   This is something we wanted to happen.

Here is the issue though:

Once the user received that error message, their email account password with google was actually changed to who knows what, but their AD account password was not changed at all.  So the users were able to use all services that relied on AD authentication, but would not be able to log into their gmail accounts unless they called the help desk, and one of the Administrators performed another password reset with AD Users and Groups.

Now, we obviously realize that if the student simply selected "Change Password" in SSPlus, this would not have been an issue.  We also realized that if the user selected "Reset" password, and used a totally different password, they would not have had an issue either.

That being said, I was not able to find any option any where in the documentation of AD Self Service plus that stated that on a failed password reset, that it would temporarily change any password in AD to anything for any amount of time, yet this is what appears to have happened(at least for a second or two), and we were able to replicate it.

So in my testing, I determined that although my AD user account password would remain unchanged after a failed password reset, and I would still be able to log in to all AD authenticated services, I would see that a password change was successful using the automated Google Apps Password Synchronization tool, but we had no idea what the password was actually changed to, so I would then be unable to get into my email.

This was clear in the Google logs.  It was evident that there was indeed a successful password change occurred and it matched the time stamp of the SSPlus audit logs for the failed user attempt.

So I started digging around the AD SSPlus logs and ultimately found the following line in the serverOut log:

"[13:30:58:653]|[02-16-2017]|[com.adventnet.sym.adsm.common.webclient.accounts.Result]|[INFO]|[86]: Reset with tempPwd is trueisUserCantCP false|"

What caught my eye was the line "Reset with tempPwd is true"

I knew that my google password WAS indeed being changed to something other than what I was typing, and I also knew that my AD access would still work, so clearly something was causing GAPS to change my password for Google.

So I started doing manual resets with my Domain Admin account and started watching the log files for GAPS and I noticed a couple of things.  

1, There were far less log entries when I used my elevated account to reset my test accounts password.
2. There seemed to be two duplicated function sets when doing the same password reset, but with AD SSPlus

So I suspect that AD SSPlus is actually making a quick change in AD, and then possible reversing that change when a user tries to reset to the same password, but for some reason, GAPS is only being triggered the first time?, thus the reason it actually changes the gmail password at all.

I opened a ticket on the matter and spoke with Prashaanth via online chat.  He was very quick to ask if I had selected the "Enforce Active Directory password history settings during password reset" option under Configuration-> Policy Configuration -> Advanced -> Reset and unlock .  

I did indeed have that option selected.  He told me to uncheck it and test again, and all was good in the world as far as users being locked out of their google accounts, so kudos to him, but this leaves me with some questions.

1: Why is there any change being made at all that GAPS would be acting on to change the google account password?

2: If AD SSPlus is indeed using a temp password during resets, how come GAPS is not seeing the second change so that the account would stay in sync?

3: If there are settings somewhere that uses a temp password at all during a password reset, where are they and why can't I find them.

4: If we are forced to uncheck "Enforce Active Directory password history settings during password reset" in order to avoid this situation in the future, how are we supposed to prevent the users from simply using password resets to keep using the same password over and over again.

5: Even if we modify our group policy settings to limit the password history(currently at 5), it appears as though it is totally irrelevant if they just reset to the same password, versus a previously used password.

6: What do we need to do to ensure that our users can not abuse the password reset function like this, and that they get an error when they try, but they do not get locked out of their google account, thus prompting a call into the help desk.

7: If you are still reading this far, Kudos to you!!!




Blank display - ADSELFservice plus client software

$
0
0
Whenever user trying to reset / unlock password we will get blank display

Port no and URL is correct, same has been tested at other site its working

what could causing this issue.

ManageEngine AD Seminars - Coming to the UK in February & March (Edinburgh & London)

$
0
0
Just a quick heads up to all the UK based users of ManageEngine AD Tools.  

Seminars are scheduled to take place in Edinburgh & London (27th February & 2nd March)

These seminars will be an opportunity to...
  • Learn about the next-gen AD management trends and techniques 
  • Know how to configure and monitor the critical security setting of your AD environment 
  • Know about constructing email alerts, to be notified about changes to key security settings 
  • Consult with our AD experts. Discuss your Active Directory challenges with them
For further details about the event or to register to attend please follow the link below.


Hope to see you at one of the events!

set3 Solutions 

Windows 10 with GINA installed, can't login as 'Other User"

$
0
0

I have a problem where if I install ADSSP GINA onto a Windows 10 machine and try to login as "Other User", that as soon as I enter a single character (no matter what it is), the logon screen immediately resets and  goes back to the splash screen with the time.  If I uninstall ADSSP from the machine, everything works normally and I can use "Other user" to log in as anyone.

Is there a known fix for this?  We are on build 5318.


Re : Windows 10 with GINA installed, can't login as 'Other User"

$
0
0
Hi Steve,

The 'Other User' login issue was already fixed in build 5315, so it should not reoccur. Possibly it could be an issue with the older client version and I would request you to upgrade ADSelfService Plus to the latest build 5325 and reinstall the client to fix this.

Regards,

ADSelfService Plus Team

Toll Free: +1-888-720-9500

Direct: +1-408-916-9890

Email: support@adselfserviceplus.com

Self Service Password Management Solution

Re : Blank display - ADSELFservice plus client software

$
0
0

Hi Saravanan,


Please check with the parameter called PROTOCOL="HTTP" or PROTOCOL="HTTPS" because when using the https port number without specifying the PROTOCOL as HTTPS it won't work.


Regards,

ADSelfService Plus Team

Toll Free: +1-888-720-9500

Direct: +1-408-916-9890

Email: support@adselfserviceplus.com

Self Service Password Management Solution

Re : New Technician from Domain?

$
0
0
Hi Dave,

There are no specific rights required for this. You could just log in as a default 'admin' to ADSelfService Plus then choose the technician. I would request you to contact our support team (support@adselfserviceplus.com) for further support.


Re : GINA

$
0
0
Hi Chris,

Please uninstall and reinstall the client by executing the ADSelfServicePlusClientSoftware.msi through administrator command prompt.

Regards,

ADSelfService Plus Team

Toll Free: +1-888-720-9500

Direct: +1-408-916-9890

Email: support@adselfserviceplus.com

Self Service Password Management Solution

Notification emails are only sent after logging into the console

$
0
0

Hello,

We are having issues with the Notification emails not being sent according to the schedule.

The Notification emails are only sent after logging into the console.

We tried installing the service, but the service fails to start.  "Some services stop automatically if they are not in use by other services or programs."

Suggestions?

Thanks

Ron

Re : GINA

Unlock or reset password generate 2 verification codes or secure link via email

$
0
0
When using the latest version 5.3.5325, if I unlock account or reset password using email verification or sms verification, it will send out 2 emails or 2 sms. Only 1 of the verification code is valid while the other already expired. Why does it generate 2 verification codes or secure link?

Did you know - How to configure custom SMS provider in ADSelfService Plus?

$
0
0
ADSelfService Plus lets you use any one of the following methods to send an SMS:
  • GSM modem
  • Clickatell (built-in support)
  • Custom SMS gateway

Configuring custom SMS gateway:
You can configure a custom SMS gateway to send notifications and verification codes via SMS. ADSelfService Plus also extends support to both HTTP and SMTP-based SMS gateways.


HTTP-based SMS gateway:
  • Login to ADSelfService Plus with administrator credentials.
  • Navigate to Admin-> Product Settings -> Server Settings.
  • Select SMS Settings tab.
  • Select Custom from the SMS provider drop-down menu.
  • Select HTTP from the Send SMS via drop-down menu.
  • Choose your HTTP method (Post or Get).
  • Enter the URL of your SMS gateway provider.
  • Specify the HTTP GET parameters and the HTTP POST payloads required by the SMS provider to accept your requests.
  • Note: Separate the HTTP parameters by an ampersand (&) sign.
    • Example format: userName=xxx&password=yyy&mobileNumber=%mobNo%&message=%message%.
    • xxx = API authentication username
    • yyy = API authentication password
    • %mobNo% = User's mobile number
    • %message% =  SMS content
  • Enter the responses that you get from your SMS provider regarding the SMS delivery status.
  • Click Advanced Settings.
  • Enter the HTTP request headers.
  • Note: Each header value should be in a separate line.
  • Choose Convert Message into Unicode option to send SMS in Unicode format.
  • Click Save.

SMTP-based SMS gateway:
  • Login to ADSelfService Plus with administrator credentials.
  • Navigate to Admin-> Product Settings -> Server Settings.
  • Select SMS Settings tab.
  • Select Custom from the SMS provider drop-down menu.
  • Select SMTP from the Send SMS via drop-down menu.
  • Enter the email ID from which you want to send the SMS in the From Address field.
  • Enter the %mobNo% macro followed by the email of your provider in the To Address field. Example: %mobNo%@clickatell.com. Refer your SMS provider to know the exact values.
  • Enter the details required in the Subject and Content field.  Please refer your SMS provider's documentation to know the exact macros to be included in these fields. Normally, it would be either %mobNo% or %message%.
  • Click SMTP Server Settings.
  • Note: Fill in the SMTP server settings only when your custom SMS provider requires a dedicated SMTP gateway. Else, leave the fields blank and your default mail settings will be used.
  • Enter the name or IP address of your SMTP server.
  • Enter the port number.
  • Input the username and password of your SMTP server.
  • Select either TLS or SSL as your connection security.
  • Click Save.

HTTP/HTTPS

$
0
0
Hello,
I have a problem. ADSSP work behind Barracuda Load Balancer. Barracuda configured as HTTPS redirect from 80 to 8888. When i click "Cancel" in ADSSP I go to http://mylink.com. How I can change default ADSSP link to HTTPS://...?
Regards,
Anton

GINA\Mac VPN Client configuration different on PC and Mac

$
0
0
Have a question about GINA\Mac client configuration: ** Enter the location where the VPN client is installed on the users' machines. **

We'd like to use the GINA\Mac client on both PCs and Macs in our environment in order to updated cached credentials via Cisco AnyConnect. The path of the VPN client application will obviously be different on our PCs than our Macs. Will the 'VPN Client Location' field accept multiple locations separated by comma? Should we generate and maintain two separate build\configurations of GINA clients? 

Thanks

How to change sample Name

$
0
0
Hi,
      May I change screen sample name in ADSelf Service 


Re : How to change answers to security questions?

$
0
0
Found it and it worked for me ...

Click "Configuration" tab --> Self-Service --> Policy Configuration.
**Click "Multi-factor Authentication" **
Click "Advanced" icon
Disable "Hide "Enrollment" tab from end-users page once they enrolled"
Viewing all 2881 articles
Browse latest View live