Add-on: Hitachi ID Login Manager -- Reducing Signon Frequency
Hitachi ID Login Manager is a component of Hitachi ID Management Suite which is automatically enabled for every Hitachi ID Password Manager (formerly P-Synch) licensee.
Overview:
Login Manager is an enterprise single sign-on solution. It eases the burden of authentication on users by automatically inserting login IDs and passwords into application login prompts.
Login Manager leverages password synchronization instead of stored passwords, so interoperates well with mobile devices and other endpoints where no SSO client is installed. Login Manager does not require scripting or a password vault, so has a much lower total cost of ownership (TCO) than alternatives.
Operation:
Login Manager automatically fills in application login IDs and passwords on behalf of users, streamlining the application sign-on process for users.
Login Manager works as follows:
- When users sign into their workstations, Login Manager acquires their
network login ID and password from the Windows login process.
- Login Manager may (optionally) acquire additional login IDs (but not
passwords) from the user's Active Directory profile.
- Login Manager monitors the Windows desktop for newly launched
applications:
- It detects when the user types one of his known login IDs or his
Windows password into an application dialog box, HTML form
or mainframe terminal session. When this happens, the location
of the matching input fields is stored on a local configuration file.
- Whenever Login Manager detects an application displaying a previously configured input prompt, it automatically fills in the appropriate login ID or the current Windows password.
- It detects when the user types one of his known login IDs or his
Windows password into an application dialog box, HTML form
or mainframe terminal session. When this happens, the location
of the matching input fields is stored on a local configuration file.
The net impact of Login Manager is that login prompts for applications with well-known IDs and passwords that authenticate to AD or are synchronized with AD are automatically filled in. This is done without:
- Interfering with user access to applications from devices not equipped with the SSO software, such as their smart phones.
- Having to deploy a secure location in which to store application credentials.
- Writing scripts.
Login Manager is installed as a simple, self-contained MSI package. It does not require a schema extension to Active Directory.
Benefits:
The main benefit of Login Manager is reducing the number of times that users must type their credentials.
Login Manager is built to leverage Password Manager, which has its own benefits: stronger passwords, regular password changes and robust user authentication business processes.