Welcome to Surp4ss! (remote password reset). 


Surp4ss! is our self-service remote-friendly password reset and Active Directory write-back tool. This is a quick user guide explaining the experience of working with and managing Surp4ss! 


As an admin, you will have been provided with the login URL and credentials to access our portal. These are the tasks that can be carried out there:


Choosing challenge response questions

      

One of the self service reset options is password reset via answering challenge response questions. These have to be chosen by the administrator. A minimum of five questions need to be selected. A user will be asked to answer three of these when using this reset feature.


They can be selected under Features / User Identification / Questions

        

       

Simply choose the ones which you require and then press save. 


Please note that the questions are hard coded and cannot be changed. If you need to modify any of them, then you can do so, however if users have already set an answer to that question then you won't be able to modify it. These will be highlighted by a lighter shade box - for example 'What was your childhood nickname?' in this screenshot:


Clearing a user's challenge response answers


If you need to clear the questions that a user has set then you can do so by navigating to Identities / Cloud vault and then searching for your user. Once you find it select them and go to the 'User Identification' tab. From here you can clear the answered questions. 


Please note that there is no option to clear the recovery email address or mobile number. You can contact the IAM Cloud support team to clear these.





Setting password policies 


A limited number of password policies can be applied to the resets done with Surp4ss!. Please note currently we're unable to detect policies from AD and resets done using our portal will override policies that are set in AD. 


You can set these by navigating to Features / Password Services and then selecting the options which you require. The default requirements are - password must be at least seven characters long and meet complexity requirements including the use of three of four character types: uppercase, lowercase, numeric, and non-alphanumeric. 





By default no password policies will be applied to resets. In order to activate the ones that you've selected click on the 'Target Editing' tab and select the classification name. Select 'Tick all applications' and the hit save. These will be applied to future password resets but the options can take up to 24 hours to apply. 





Experience of an end-user


Using known password reset (KPR)


Surp4ss! is a browser based service. To use it your users will navigate to a URL in your domain namespace. If you're only using KPR then users will see the screen below. Once their email address has been entered then they'll be able to enter their current AD password and then choose a new one. This will write back to AD in around one minute.



If you're using self service password reset (SSPR) and KPR, then you you'll see the option to use KPR as per the below screenshot:




Using self-service password reset (SSPR)


Self service reset can be done in three ways. By answering challenge response questions or by using a reset code sent to either a recovery email address or mobile device. 


The options will be configured by IAM Cloud as part of the setup process. The only client side task is to choose the challenge response questions.


Users will need to set these options up before they can be used. They can do so by selecting 'I want to set up or manage my password reset options' and following the on screen prompts:



The recovery email and SMS options will require a verification code to be entered, this will be sent to the email address or mobile number. Once they've entered the options and pressed submit, they'll be securely stored in our database and available for use. The option will be 'I have forgotten my password and want to reset it'



They can then follow the on screen prompts to go through the reset process. As with KPR this will write back to AD in around 1 minute.


If you run into any issues or require any further information then please contact us at support@iamcloud.com