Cybersecuity - Features

Kaspersky Endpoint Security 11.10.0 Adds Support for Third-Party Credential Providers

Author Quest Lab Team
• November 19, 2024
Kaspersky Endpoint Security with SSO Integration

Endpoint security is a critical component of modern IT infrastructure, ensuring devices connected to a network are protected against cyber threats. With advancements in cybersecurity, solutions like Kaspersky Endpoint Security have become essential for safeguarding business environments. The latest version, Kaspersky Endpoint Security 11.10.0, brings exciting new features, including support for third-party credential providers. This update promises enhanced flexibility, improved user experience, and robust security measures.

Before delving into the specifics of this update, let’s explore what endpoint security entails. Endpoint security solutions protect devices such as desktops, laptops, and servers from malicious activities. These tools are vital for defending endpoints that act as entry points for cyberattacks, enabling organizations to prevent breaches, detect intrusions, and respond to threats effectively.

What’s New in Kaspersky Endpoint Security 11.10.0?

The highlight of version 11.10.0 is the integration of third-party credential provider support. This feature broadens compatibility and streamlines the authentication process for organizations leveraging external identity management solutions. By supporting Single Sign-On (SSO) technology and wrapping third-party credential providers, Kaspersky Endpoint Security simplifies user authentication while maintaining strict security standards.

SSO allows users to authenticate once and gain access to multiple systems without repeatedly entering credentials. This technology not only enhances convenience but also reduces password fatigue—a common issue that leads to weak security practices. By integrating third-party credential providers, Kaspersky Endpoint Security ensures seamless compatibility with existing authentication mechanisms.

Benefits of Single Sign-On Technology

The addition of SSO support in Kaspersky Endpoint Security introduces several benefits:

  • Improved User Experience: Users only need to authenticate once, reducing login complexity and saving time.
  • Enhanced Security: Centralized authentication minimizes the risk of compromised credentials.
  • Streamlined IT Management: Administrators can enforce consistent password policies across all endpoints.

Enabling Single Sign-On in Kaspersky Endpoint Security

Configuring SSO in Kaspersky Endpoint Security is a straightforward process. The steps differ slightly depending on whether you use the Administration Console or the Web Console:

Using the Administration Console

  • Open the Kaspersky Security Center Administration Console.
  • Navigate to the Managed devices folder and select the relevant administration group.
  • Access the Policies tab and open the properties of the desired policy.
  • Go to Data Encryption → Common encryption settings.
  • In the Password settings block, enable the Use Single Sign-On (SSO) technology checkbox.
  • If required, enable the Wrap third-party credential providers checkbox.

Using the Web Console

  • Log into the Web Console and navigate to Devices → Policies & Profiles.
  • Select the desired Kaspersky Endpoint Security policy.
  • In the Application settings tab, go to Data Encryption → Full Disk Encryption.
  • Enable the Use Single Sign-On (SSO) technology checkbox.
  • Optionally, enable the Wrap third-party credential providers checkbox.

How SSO Enhances Productivity and Security

By consolidating authentication processes, SSO eliminates the need for multiple logins, fostering a smoother workflow. This is particularly beneficial in enterprise environments where users frequently switch between applications and systems. Additionally, SSO enhances security by reducing the reliance on weak or reused passwords—a significant vulnerability in traditional authentication methods.

"The emergence of SSO technology marks a pivotal advancement in cybersecurity, balancing convenience with stringent protection."

Integration with Third-Party Credential Providers

Kaspersky Endpoint Security 11.10.0 enhances its authentication flexibility by adding support for third-party credential providers. One of the key supported providers is ADSelfService Plus, a widely used solution for identity management. This integration allows users to leverage their existing corporate authentication systems while benefiting from Kaspersky's security protocols.

The inclusion of third-party credential providers brings significant improvements in user convenience and administrative control. It enables users to authenticate with their Windows accounts while also utilizing third-party systems for access to corporate services. Moreover, these providers empower users to independently reset their passwords, thereby reducing IT support burdens.

How Third-Party Credential Providers Work with Kaspersky

When working with third-party credential providers, Kaspersky Endpoint Security intercepts the user’s password before the operating system fully loads. This process ensures that the user only needs to authenticate once during the Windows login process, after which the third-party credential provider takes over for access to additional services.

One of the key features enabled by third-party providers is the ability for users to reset their own passwords. In this case, Kaspersky Endpoint Security will automatically update the password for the Authentication Agent to match the changes made by the third-party service. This seamless integration helps maintain synchronized credentials across various systems.

Potential Limitations with Unsupported Providers

However, there are limitations when using third-party credential providers that are not officially supported by Kaspersky Endpoint Security. If users choose a third-party credential provider that Kaspersky does not support, they may encounter issues with Single Sign-On (SSO) functionality. Specifically, the Authentication Agent will not be able to synchronize passwords with the Windows account. As a result, the user will need to authenticate twice: once during the Authentication Agent interface and again before the operating system loads.

In such scenarios, users will be presented with two profile options at the Windows login screen: one for the in-system credential provider and another for the third-party provider. Although both profiles appear with identical icons, selecting the third-party option prevents the synchronization of passwords with the Windows account, leading to a more complex authentication process.

Balancing Third-Party and Native Authentication Systems

Choosing between the in-system credential provider and a third-party one involves trade-offs in functionality. If users opt for the in-system provider, Kaspersky will successfully synchronize the password with the Windows account, ensuring a smooth and unified authentication experience. However, they lose the ability to leverage the third-party system for corporate service authentication, which may limit the utility of this option in environments where external identity management is crucial.

In contrast, selecting the third-party provider enables the use of external identity management systems, which may offer advanced features like self-service password resets, multi-factor authentication, and integration with other enterprise applications. However, the trade-off is that the Authentication Agent cannot synchronize passwords with the Windows account, requiring the user to authenticate twice in certain scenarios.

Best Practices for Using Third-Party Credential Providers

To maximize the effectiveness of third-party credential providers while minimizing potential issues, organizations should follow these best practices:

  • Ensure the third-party provider is compatible with Kaspersky Endpoint Security to avoid synchronization issues.
  • Regularly update both the third-party provider and Kaspersky Endpoint Security to ensure the latest features and security patches are in place.
  • Educate users on the benefits of using a third-party credential provider and the implications of selecting the in-system option.
  • Implement multi-factor authentication (MFA) in conjunction with third-party providers to further enhance security.

By adhering to these practices, organizations can achieve a seamless and secure authentication experience while leveraging the full potential of third-party credential providers in conjunction with Kaspersky Endpoint Security.

Conclusion

Kaspersky Endpoint Security 11.10.0 sets a new benchmark in endpoint protection by integrating support for third-party credential providers and SSO technology. This update not only simplifies authentication processes but also reinforces security measures, making it an indispensable tool for modern businesses. As cyber threats continue to evolve, adopting solutions like Kaspersky Endpoint Security ensures your organization remains one step ahead.

Author

Quest Lab Writer Team

This article was made live by Quest Lab Team of writers and expertise in field of searching and exploring rich technological content on Cybersecurity and its future with its impact on the modern world