| Home / Windows Security / OWA 2-factor Authentication |
digWin is a community news sharing site for Microsoft Techies. Share interesting news/links and rate them!
OWA 2-factor Authentication
posted by Vikram (1) 4 months ago (digWin.com)
I'm looking for a phone-based 2-factor Authentication solution for OWA. Anyone have any ideas?
Microsoft news, tips and tricks search
Post voted by 2 digWinners
Featured Links
-
Free Download Trial: SharePoint Migration, Backup and Recovery Software
DocAve: Enterprise, full-fidelity backup & recovery software for SharePoint provides essential protection & management tools, and allows for a data migration from Exchange Public Folders in to SharePoint 2007 & 2003.
User
Sponsor
Anti spam filter for mail servers
Anti spam, anti phishing and email management software for Exchange/SMTP/Lotus. Download a FREE trial!
Anti spam, anti phishing and email management software for Exchange/SMTP/Lotus. Download a FREE trial!
Featured
Categories
Upcoming NEW
- How to properly specify the SQL instance during the App-V 4.5 Management Server installation
- Configuring IPsec NAP (Network Address Protection) - Part 1: Certificates
- Microsoft Windows Vista Home Premium Edition
- Microsoft Windows Vista Business Edition
- Microsoft Windows Vista Home Basic Edition
- Certifyme 642-372 Dumps
- Certifyme 646-590 Dumps
- Vista Editions: Microsoft Windows Vista Starter Edition
- Certifyme 642-356 Dumps
- Certifyme 642-511 Dumps
- Certifyme 642-651 Dumps
- Certifyme 642-586 Dumps
- HP0-490 Exam
- Certifyme 646-588 Dumps
- Certifyme 642-577 Dumps
- Certifyme 646-102 Dumps
- Certifyme 642-652 Dumps
- Certifyme 646-011 Dumps
- Certifyme 642-176 Dumps
- Certifyme 646-203 Dumps
Recent comments
- Dell Optiplex 755's and Windows XP installation by Brad Schwarz
- HP0-490 Exam by cheungshe (0)
- HP0-461 Exam by cheungshe (0)
- HP0-460 Exam by cheungshe (0)
- HP0-450 Exam by cheungshe (0)
- Free upload iTunes M4P music to MySpace by Anonymous user
- Replica Handbags,bag,shopping,new Products by Anonymous user
- Christmas promotions handbag by lisude (0)
- testpassport offecr the latest HP0-417 Exam Braindumps Q&A by killtest (1)
- testpassport offecr the latest HP0-409 Exam Braindumps Q&A by killtest (1)



There are some options. Interestingly, there is nothing special and new technically about them. The main advancement is the ubiquity of wireless phones. When you think about it, It wouldn' have been necessary to 2-factor Authentication with desktop computing. With people on the go, it would be necessary to assume there is a networked device in the hands of every user. This hasn't been true until this very moment in history.
I use PhoneFactor for Logmein and it's also available for OWA. It works like a charm and haven't had any issues. I wish people would get over having another physical device to carry.
peace
Our company uses phone factor for logmein and it works pretty good since majority of our workforce is mobile.
I know this a bit of a PhoneFactor love fest, but the solution does have some major benefits over over two-factor authentication solutions.
Over sms-passcodes 1) PhoneFactor does not require a mobile device, it can be used on a landline 2) PhoneFactor is easier to intergrate with multiple secure enterprise solutions. 3) People can press a button to authenticate far easier than having to be skilled in opening and reading a text message (think older generations)
Over security tokens 1) People place a lot more primary value in their phones than a security token. Less lost IT equipment. Less hassle for IT departments. 2) Easier to install, scale and integrate.
Also you really get a wow-factor as well with this solution. Is that a advantage, maybe not in pure business terms. But with ease of use, peace of mind and value this software provides it's just the icing on the cake.
Okay, the other cool thing about using a phone is that it is potentially ubiquitous, making virtually any potential user a candidate for 2-factor authentication. Suddenly consumer web-based apps can require 2-factor authentication because there is what appears to be an infinitely scalable solution.
Yes, web-based can be some much more secure using a solution like this. What is more, I think people, will more and more access there applications and data online.
Which really means all your stuff will be online and accessible from any computer. So really cool, I can be anywhere and boot up my computer from any terminal and get all my stuff, GREAT.
With that power comes great risk. You don't want other people to get it. Like having the whole world on your doorstep with a wonky lock.
PhoneFactor will make that door like fortress. Meaning you sleep better at night.
Scalability. Anything with a token isn't really scalable. You can provide them for your corporate travel and work-at-home corps. But you can't provide them for everybody. You'd go crazy. A secure web-based solution, for example. What if financial services such as PayPal required 2-factor someday? No way you'd distribute tokens. But, you might require (or make available), a solution like PhoneFactor, because management of the solution could scale, perhaps infinitely.
I just thought of a potential flaw with PhoneFactor. What if someone changes your phone number to theirs? How secure is the facility to change the phone number?