EDGE ACCESS CONTROL FOR SKYPE-FOR-BUSINESS

Protect external Skype for Business access by blocking failed login attempts at the Edge server before they can trigger Active Directory account lockouts.
Skype for Business Edge Access Control
Skype for Business Edge Access Control

Protect external desktop and laptop access before it reaches Active Directory

Skype for Business Edge Access Control helps organizations safely connect computers from outside the corporate network to their Skype for Business server.

External desktops and laptops can expose the organization to account lockout risk because authentication may require access to Active Directory.

SphereShield blocks failed attempts at the Edge server side before they reach Active Directory.

Prevent failed login attempts from reaching Active Directory.

Secure external computers connecting through Skype for Business Edge servers.

Force certificate-based authentication and reduce reliance on exposed credentials.

External computer Desktop or laptop access

SphereShield Edge control blocks failed attempts before Active Directory is reached

Active Directory Protected from lockout attacks
Allowed attempts within defined policy Allow
Too many failed attempts in a time window Block
Certificate authentication enforced 2FA
Authentication options
NTLM control
TLS-DSK certificate
Two factor process
Background

Connecting computers and mobile devices to Edge servers from outside the corporate network exposes the network to serious risks.

Mobile devices are often the main concern because they are less controlled, but desktops and laptops can also create risk when connecting to Skype for Business services.

These connections may require access to Active Directory, which can expose the organization to account lockout issues.

External computer access

Allow outside desktops and laptops to connect more safely to Skype for Business services.

Active Directory exposure

Reduce the risk of failed authentication attempts reaching Active Directory and triggering account lockout.

Edge-side enforcement

Apply protection at the Edge server side before traffic can create internal directory impact.

Account lockout

Account lockout may happen when a user changes the Active Directory password but does not update local computer settings.

It may also happen when a hacker obtains a username and repeatedly attempts to log in, even without knowing the correct password.

DDoS, DoS and brute force attacks can also make the network unavailable and cause significant business damage.

Password mismatch

Old saved settings can keep sending failed attempts after a user changes the Active Directory password.

Username abuse

An attacker can attempt repeated login attempts after obtaining only the username.

Attack traffic

DDoS, DoS and brute force attacks can lead to downtime across network systems.

Certificate authentication

Use certificate authentication to strengthen non-mobile access

Skype for Business Edge server supports both NTLM and certificate-based authentication, also known as TLS-DSK.

Certificate authentication helps organizations reduce the use of credentials passing through the web during NTLM authentication.

When certificate authentication is used, the Skype for Business client requests a certificate on the first authentication request using corporate credentials. After the certificate is set, it is used for ongoing authentication.

Initial credential use

The first authentication request uses the user's corporate credentials.

Certificate issued

After successful authentication, the client receives a certificate for ongoing access.

2FA process

Blocking NTLM and forcing certificate authentication creates a stronger two factor authentication process for external computers.

SphereShield solution

Block failed login attempts before Active Directory is affected

Skype for Business Edge Access Control eliminates account lockout threats by blocking failed attempts at the Edge server side before they reach Active Directory.

A block-failed login policy limits the number of failed attempts allowed within a defined period.

For certificate authentication, the solution can block NTLM and force certificate authentication to provide a two factor authentication process for desktops and laptops outside the corporate network.

Protect external access while reducing the risk that repeated failed logins can lock users out of core network systems.

Highlights

Prevent unauthorized devices from using corporate credentials.

Match the device and user for stronger access control.

Support two step strong verification.

Avoid connection by hackers or unauthorized users.

Block failed login attempts at the Edge server side.

Force certificate authentication and reduce NTLM exposure.

Secure Your Collaboration Environment

Protect Microsoft 365, Webex, Teams, OneDrive, SharePoint,
and Skype for Business with SphereShield’s policy-driven security, compliance, and governance controls.

Create your account