Hi everyone,
We are excited to introduce a new set of access management capabilities in Identity360, designed to help you verify users and devices based on context and extend authentication controls across endpoints, applications, and remote access points.
From protecting unmanaged devices and enforcing endpoint MFA to enabling phishing-resistant, passwordless authentication, these updates give you more ways to apply the right level of verification wherever users access organizational resources.
Platform-agnostic access security: Protect user and device access independent of the underlying infrastructure, giving organizations the flexibility to secure resources across different environments.
Conditional access policies: Evaluate access attempts using contextual conditions such as the user, device, department, role, IP address, geolocation, business hours, and device operating system, and apply access requirements accordingly.
Endpoint MFA: Enforce multi-factor authentication (MFA) for Windows, macOS, and Linux login and unlock, RDP and SSH access, and privilege elevation through UAC and sudo.
Unmanaged device protection: Enroll devices directly into Identity360 without requiring a separate directory or domain controller and extend authentication and access policies to bring your own device (BYOD), workgroup, and non-domain-joined machines.
MFA for cloud applications: Apply a preferred combination of MFA factors and conditions to a set of SSO-enabled applications, so the same user can face different requirements for different apps.
MFA for VPN, Wi-Fi, and remote access points: Extend MFA to VPNs, RDWeb, RADIUS-based applications, and Wi-Fi to verify users at remote access points.
MFA for Outlook on the Web (OWA): Secure employees' OWA mailboxes, which house crucial internal data, with an additional MFA verification step instead of a password alone.
MFA for sensitive portal actions: Require additional MFA verification before users perform high-impact actions such as deleting users, groups, or directories, or bulk-disenrolling enrolled user data.
Offline MFA: Protect devices with limited or no network connectivity through the IDSecurity Agent, with single-use Emergency Access Codes available when a user's configured MFA method is unavailable.
Passwordless authentication: Enable passwordless sign-ins to workgroup machines using secure methods like FIDO2 passkeys and PIV and CAC smart cards.
Phishing-resistant authenticators: Support FIDO2 passkeys and smart cards that resist phishing and credential theft, in line with NIST and CISA guidance.
Help desk-assisted emergency access: Enforce access policies on protected machines while letting users obtain a one-time emergency access, so an unavailable authenticator doesn't require an exception to policy.
MFA frequency control: Specify how often users must complete MFA to periodically verify their identity and reduce the risk of unauthorized session access.
Active Directory synchronization: Import users directly from Active Directory and centrally manage their access from the Identity360 portal.
Identity360 now offers edition-based pricing, making it easier to choose an edition based on the capabilities your organization needs. Explore the pricing to find the right edition for your organization.
Ready to explore the latest capabilities? Log in to Identity360 and get started.
Don’t have an account? Sign up now for a free, 30-day trial.
For assistance, reach out to us:
Email: identity360-support@manageengine.com
Direct: +1-840-200-1274
Cheers,