MFA for Endpoints
Hi I'm trying to configure MFA for endpoints. What I want to achieve is a second authentication factor during logon to workstation- Microsoft Authenticator. Everything working for unlock/reset password- logon Acceptance on Microsoft Authenticator is required,
ADSelf Service SentinelOne Reboot Problem
I am having a problem with SentinelOne rebooting the server when a use tries to reset their password with ADSelfService. Of course each vendor is blaming each other. Has anyone been able to get this fixed? I am on build 6000 and upgrading to 6002 now. SentinelOne version 4.0.4.81 Windows Server 2016
How to customize user login page
I would like to customize the User Login Page as seen in the screen shot below. I'm trying to follow the instruction for Customize User Logon Page. Located at the following address: https://www.manageengine.com/products/self-service-password/help/admin-guide/Admin/Customize-User-Logon-Page.html#FIELD Though when I get to the following section. Enabling the User Logon Box: I don't see where the Pre Defined Elements in my version of the software. See below. I'm using ADSelfService Plus Standard
How To Customize User Login Page (Updating Post From 5 Months Ago)
(Sorry as this is a reply to a post from 5 months ago, and not sure if my reply will get read, so i'm reposting here with the hope Manage Engine will respond) I just updated to the latest 6009 version and I still don't see a way to customize the user
Vulnerability
Hi, we use ME DC with Vulnerability assessment. Which has flagged up that the Apache TomCat needs updating, we are now on version 6009 how do we fix this issue? Thanks Darren
Multiple users with same email
Hi, We need to restrict users to not register or add the same email or mobile phone that another user already have. 3 Years ago in another topic, you say that is in the product roadmap to add this feature, but this don't happend. Acoording to the helpdesk answer, is users responsability not using duplicate emails or mobile phones, this approach is wrong, you say that the weakest link have the security in theirs hands. This solution don´t resolve the problem that someone impersonate a user and recover
Script Error
We are having the following problem when we use the application on a 2008 SP2 server I attach the image so you can see detail I tried several addresses at the time of installation but the result is the same
***SOLVED*** - Cant enroll after upgrade
We are running v5.8 build 5801. If a user is already enrolled in the system everything seems to work fine. I have a new user that is not enrolled in the system and when we get to the login page we click the "User Registration" link on the left hand side of the screen and we get a message that says "Please login here" above the sign in screen. If the user then tries to login using the sign-in screen he gets an error stating he does not have permission to do so and to contact the administrator. How
ADSelfService not sending the complete certificate chain (CA root and CA intermediate).
Hello, Our ADSelfService Plus is configured to use SSL certificate. To achieve that we enabled the HTTPS option under the Connection settings, and put the pkcs12 certificate in ADSelfService Plus that it is linked in server.xml like the following <Connector name="SSL" sendReasonPhrase="true" relaxedQueryChars="\" port="443" minSpareThreads="25" maxThreads="150" maxSpareThreads="75" enableLookups="false" disableUploadTimeout="true" connectionTimeout="20000" acceptCount="100" secure="true" scheme="https"
GINA Client: Certificate Error
Hi folks, we use the AD Self Service Plus software in our company. We've installed the GINA client on all hosts (Laptops, Desktops...). Also we have a firewall from CheckPoint. We manage the internet access from our users with an Active Directory group. CheckPoint use this group to check which user can access the internet. And here is the problem: The GINA client comes as ANONYMOUS user and does not have any rights to access the internet. The GINA client tries to connect to some external sites. We
SMS Account Setup Verification not allowing option for Country Code
In previous versions of SelfService the country code is required for SMS (text) to function. We onboarded our first new employee today since the upgrade to 6000 (6002) and he is being prompted for his phone number. There is a + sign at the beginning, but there is no option to enter a 1 (USA). He can only enter 10 digits for the number and it fails to send the text. We have validated SMS works through the admin interface. How do we correct this?
Dual Login Prompt when accessing Self Service
Since the upgrade to ver 6000, we now get a double pop up each time we attempt to access Self Service. If we cancel, we can log in fine. If we log in using the dialog box, we have to log in a second time to gain access.
Windows Logon 2FA - Prevent on Locked screen
I've got Windows Logon MFA working on a few test machines but comes up every time the computer is locked. Is it possible to have Logon MFA only appear during account login and not for unlocking the PC?
Cannot choose options from self-service
Since the upgrade to build 6000, the self-service dropdowns no longer work. They show the text "ads.common.text.select_empty", and clicking on the dropdown provides no options, when there are really a couple dozen. Below is what I see:
How to import multi security questions & answers data from CSV file in one stage
Hi, I have multi security question and answers that want to import from single CSV file in one stage. This is not mentioned in the sample CSV file. What should I do?
How to enlarge ADSelfService Plus font size
Hi, How to enlarge ADSelfService Plus font size? The default font size is very small. Version: 5.8.16
SMS verification is not plain text in AD-SSP
Hi, SMS verification is not plain text in AD-SSP 5.8.16 and I see in mobile as below message: <div style="direction: rtl;">Dear user<br></div><div style="direction: rtl;"><br></div><div style="direction: rtl;">verification code:</div><div>87233859<br></div><div><br></div> Please fix it in next release. Thanks for helping
Where is SMS log file
I have problem in send SMS. Now I want to see log for send SMS .Where is SMS log file?
"Customize User Logon Page" link on the 'Logon Settings' has disappeared after upgrade to 5815
I am unable now to see the "Customize User Logon Page" link on the Admin page. We were running 5708, i upgraded to 5800 then 5815. At this point the Customize User Logon Page disappeared. Is it somewhere else, or did I miss something in the upgrade? How can I recover this, as i need to amend the User logon page. Thanks
"Customize User Logon Page" link on the 'Logon Settings' has disappeared after upgrade to 5815
I am unable now to see the "Customize User Logon Page" link on the Admin page. We were running 5708, i upgraded to 5800 then 5815. At this point the Customize User Logon Page disappeared. Is it somewhere else, or did I miss something in the upgrade? How can I recover this, as i need to amend the User logon page.
Upgrade failed: JRE version should be 7 to proceed
Unable to install upate (Build 5703 to 5708) I always get the error "JRE version should be 7 to proceed. Please start and stop the product once and then try again" How can I complet the update?
Adselfservice plus send me this error "The account service configured on application was expired"
Adselfservice plus send me this error "The account service configured on application was expired". Review the logs Server_out the key for error is [SYSERR]|[INFO]|[87]: javax.security.auth.login.LoginException: adssp.login.common.error.pwd_expired
ADSelfService Plus - service starts then stops
Hi- I installed ADSelfService Plus build 5811 on Windows Server 2012 R2 (a domain controller), and configured a policy for password expiration reminder emails. i followed the instructions to configure it to run as a service (using a domain account which has log on as a service right on this DC), then rebooted. It now shows in Windows Services list, but the service cannot start. Error is "The ManageEngine ADSelfService Plus service on Local Computer started and then stopped. Some services stopped
Gina not work on windows server 2008 or 2012
Hi everybody. We install ADSlefService on a server and Gina on all windows 10 (our clients) and other severs (2008 & 2012 & 2016). Gina is loading and working well on all windows 10 (show 2FA methods and accept tokens successfully) But Gina is not working on none of our servers: >after enter username and password on login page, Gina App box is loading as images i attached bellow one by one (1 then 2 and then 3). we turn off firewall and antivirus and also turn off "IE enhanced security" but nothing
Off Site Log In Error
We have several laptops running ADSelfService Plus client. When they are off site they receive this error: "Could not connect to the ADSelfService Plus server or Domain Controller configured in ADSelfService Plus is Down. Please contact your administrator" These are domain computers that can successfully log in on site. We have had some success recommending users connect to their home wireless at the log in screen, but for several users, even when they connect to their home wireless at the log in
New Install ADSSP - Sorry,the page you requested was not found. Back | Sign Out
I have a brand new install of ADSSP. There is nothing else installed on the server. I have managed to get it to load, and install it as a service. When i try to load the console on the server or remotely the page authorization.do shows the error Sorry,the page you requested was not found. Back | Sign Out. Most of the fixes i have seen for this related to builds from 6+ years ago and I am not sure if the steps still work, But if they do, i added 8443 as an SSL handler and it gave me a protocol error.
New self service page
is there any way to hide the user profile picture for all users as well as the manager and reports to fields. We do not use profile pictures and people will just complain that it is blank. We also use the those fields for technical things so they do not always show what users expect.
New Installation
Hi! We're trying to implement ADSelfService Plus for the first time. We're having a heck of a time using the product. We have had very inconsistent results. I'm curious if anyone else has had difficulty getting the product running? Would you be able to provide any insights? Does anyone know of a way to get level 3 support with the product? Any help/comments/suggestions would be appreciated! Thanks, Scott
New Login Screen
Since updating I've noticed the admin login page has changed from "https://domain/adminLogin.cc" to "https://domain/authorization.do" and includes a new login page. However, our normal users are still redirected to "https://domain/showLogin.cc" and are using the old login page. Is there anyway to update the normal user login page to look like the new admin page?
Cannot start ADSelfService Plus service
The ManageEngine ADselfService Plus service terminated with the following service-specific error: %%4294967295
Updating SSL cert on ADSelfService Plus proxy server
Hello, I followed the instructions on updating our SSL cert for the ADSelfService Plus and used the SSL cert tool to generate the CSR and send it to GoDaddy to receive our cert bundle from them and then install it on the server and it works fine internally. However, we use a proxy server for external access and the SSL cert is expired on that now. How do we go about installing the SSL cert on the proxy? Do we use the same cert? How do we treiteve the private key to install it? Thanks!
Reset password email wrong address
I've had ADSS+ on one of my servers for a while and just now noticed that the verification code email does not have the right address when I want to reset a password. It actually shows the ip address of the local server instead of the domain. Should be : https://example.com/accounts/SecureLink?otherstuffhere Actually get : http://192.168.1.22/thesamestuffhere I cannot seem to figure out where I would need to change that, the options in the administration panel don't show any settings for this email
Unable to start ADSelfService Plus service
Error 'The ManageEngine ADselfService Plus service terminated with the following service-specific error: %%4294967295'
ADSSP not starting on it's own
I have ADSSP installed as a service but suddenly the application won't run unless you manually start ADSSP on the server. If I backup the database, and reinstall, will the backup restore any customizations I've made? Thanks!
Enrollment Issue - Testing Enrollment removes that users from enrollment
So here's a high level description. I am testing ADSelf Service Plus for my company. We would love to use it if we can get it working with mac and windows, but that has been unsuccessful. We installed the server on a test machine and the client on a mac to begin mac testing. I saved a single policy that applies to all OU's. Then I use the quick enrollment to import a csv of my account along with some near by coworkers. The import says it is successful. I check the reports section to see all accounts
Want to see all technicians on dashboard
Hi, Currently, if a technician has less than two jobs, they show as 'Other' on the dashboard. Is there a way to see all technicians all the time? See piccy. Thanks.
ADSSP Password Dictionary
Has anyone added words to the default dictionary for password complexity rules? If so is there anything special that needs to be done or is it a case of just appending the extra words to the end of the file? Thanks in advance Tony
Password Reminder Notification has sending errors
I send email password expiration warnings every morning. Recently I have been getting error "432 4.3.2 STOREDRV.Storage; mailbox server is too busy; STOREDRV.Submisson.Exception:StorageTransientException.MapiExceptionRpcServerTooBusy; Failed to process message due to a transient exception with message Cannot open mailbox." randomly in my report. Has anyone else ran into this? I am using Office365 to send notification. Thanks,
iOS/Android App Logon To Option & Push Notification Pop Up
In our environment we have 3 Domains configured and we have our users enter the Domain and Username in the following format when using AD Self Service Plus Domain\Username. No issue there but, on the iOS App it shows the Logon to option where as in the Android App it does not. Any particular reason why? Is there a way to make it standard for both? (see screenshots below) We would like the Logon To option to be hidden from the mobile app as well, as we have disabled the "Show 'Log on to' option
Self Service Portal session expires while resetting the password
Hello everyone, Greetings!!! While resetting the password the portal session expires if the password is not matching the complexity. I have already enabled this option "Allow users to retry reset without going through ID verification again". But still it fails and shows the attached error, users have to relogin for trying again. Any help will be greatly appreciated. Thanks, Kottees
Next Page