AGAT

Categories
Microsoft Lync Skype for Business SkypeShield Uncategorized

New IP filter verifies that only corporate devices can connect to Skype for Business

SkypeShield has added a new strong authentication solution, which enables the ability to limit access to the organization’s Skype for Business (Lync) server only to corporate devices, adding another layer of security to the authentication process.

This is done, by using an innovative IP Filter  (IPF), which was developed by SkypeShield, following specific customer requests. SkypeShield’s IPF can be implemented at the registration process or during the ongoing usage of Skype for Business.

Registration filtering enables control on the devices that can complete the registration process and filtering on the ongoing controls from which location connection is allowed.

By using our IPF, registration can be limited to a specific IP range that is accessible only from within the corporate network, thus blocking attempts to register a device without being able to join the corporate network.

SkypeShield’s IP Filter is an ideal solution for organizations that limit the connection to a specific network by using certificate or Mobile device Management (MDM) solutions. This allows verifying, for example, that only devices with an installed MDM can use Skype for Business.

Applying the IPF for the Skype for Business usage can be transformed into geo-location protection by limiting the connection to specific countries based on IP range.

Categories
Microsoft Lync Mobile Security Skype for Business SkypeShield Smart card for authentication Two Factor Authentication Uncategorized

New security solution protects smart card login of Skype for Business mobile users

A growing number of organizations around the world, such as financial institutions and governments, are providing their workers with a smart card device to strengthen the identity authentication process. These organizations are facing a problem while implementing Skype for Business (Lync) mobile authentication requiring the user to enter his or her Active Directory (AD) credentials.

In such organizations, users do not have Active Directory credentials as they use the smart card for authentication instead. This in turn may cause a problem, as Microsoft Skype for Business requires Active Directory (AD) credentials to connect from handheld devices.

To solve this problem, SkypeShield has developed a new security solution for smart card authentication enabling mobile Skype for Business authentication for organizations with a network policy that requires their workers to use smart card login.

SkypeShield’s innovative solution addresses this challenge by applying the authentication process in two separate steps:

• The user creates dedicated Skype for Business credentials from a self-service registration web site after using his/her smart card for authentication to the site from a PC.

• The user then needs to connect his/her mobile device within a limited time frame by entering the dedicated Skype for Business credentials on the mobile device.

SkypeShield’s new solution also addresses account lockout protection and Two Factor Authentication (TFA) for external Skype for Business clients.

“We were approached by customers who couldn’t find a good solution for smart card authentication,” said Guy Eldan, CEO of AGAT Software, which developed SkypeShield. “Our simple and easy-to-implement security solution allows organizations to continue maintaining the smart card authentication policy enabling mobile users connect to the corporate network from outside network without using Active Directory credentials.”

Categories
LyncShield Microsoft Lync Uncategorized

New enterprise solution secures external access for Lync from laptop and desktop

LyncShield has added new security features protecting the users of external devices who wish to use Microsoft Lync from outside the organization.

Following the addition of the new features, users can now safely connect to Lync servers from smartphones, tablets, laptops, desktop PCs and any other external device outside the organization. The advanced security solution prevents unauthorized devices from penetrating the corporate network and protects the Active Directory (AD).

“Following the introduction of our solutions for secure mobile Lync connectivity, customers asked us to develop a similar solution for external devices,” said Guy Eldan, CEO of AGAT Software Solutions, which developed LyncShield. “We are now offering the ideal security suit for any organization looking to allow its workers to connect to its Lync client, regardless of where they are and which device they are using.”

The latest release offers an identical security solution for both mobile and external devices in terms of functionality and user experience, allowing hydride deployment to be securely deployed.

LyncShield now offers the following enterprise security features:

  • Active Directory credentials protection – defining dedicated credentials that are different from the Active Directory credentials to minimize damage and risk in case of a stolen or lost device, or if the credentials are hacked.
  • Two factor authentication – by matching the device and user, the organization can limit users to using only corporate devices or specific devices that meet the company’s security requirements.
  • Account lockout protection – preventing account lockout for organizations that wish to safely connect computers from outside the corporate network to their Lync edge access control server.
  • Reverse proxy Lync publishing – scalable, event-driven and secure reverse proxy alternative for Microsoft Forefront Threat Management Gateway (TMG) to publish Lync.