Citrix XenApp and XenDesktop Two Factor Authentication
What are we doing and why are we doing it?We develop SMS2, a two factor authentication product for Citrix XenApp and XenDesktop.
In today’s high-tech, mobile and portable world, securing your sensitive data is an absolute must. Two factor authentication secures your existing remote access platforms by ensuring people who try to login have both their password and physical possession of a secure token.
This additional check helps protects your business from unauthorised access and data loss, school children from cyberbullying, and helps to meet your legal obligations under the
Data Protection Act.
SMS2 is a simple low cost enterprise grade security solution. Using SMS2 you can deploy two factor authentication in a single day and without any special software on employee computers.
Why this is important to you. Remote access based only on passwords is not enough any more.
Many passwords are simple and can be guessed, passwords are often reused - someone who knows your facebook password may in-fact then have access to your work login, passwords are shared with other people, are written down, saved other people's computers, etc, etc.
Historically passwords were not a major issue for most companies because you needed physical access to an office computer before you could login, and you could be seen using that computer while you did whatever evil deed was planned. Today this is a major issue, any computer in the world can attempt a remote login and you are relying on the password choices of every user as your only layer of protection.
The question arrises as to what exactly is protecting your company's data? Is this just a collection of passwords each member of staff has set? What sensitive data is stored on your computers? What would happen if that data was lost or shared around? Is your protection suitable?
Why should you talk to us?Securing your systems to only allow a remote login if the user also has a physical security token is a simple solution, but it is also quite a costly one as you need to purchase a physical token for every remote user (and this will need to be replaced if it gets lost or damaged).
SMS2 works using mobile phone text messages, so you don't need to purchase lots of tokens.
We keep a record (on your systems) of each user's mobile phone number. After a user has correctly entered their password we automatically send their phone a constantly changing security code, and request that security code before we let them complete the normal Citrix remote login process.
From the user's viewpoint this is the only change, a simple request for an instantly delivered code.
This change proves the person trying to login not only has your password but also physical possession of your mobile phone. You have dramatically increased the security of your systems quickly, easily, and with very minimal outlay.
Where to we go from here? We are taking on trial sites to run software and act as case studies.
If you would like a free deployment then please let us know.