Features of Mailscan for Exchange and Escan/english/escan22/eScan Management Console/Policies/Features Help/Administrator Password: Difference between pages

From eScan Wiki
(Difference between pages)
Jump to navigation Jump to search
No edit summary
 
imported>TechContent
No edit summary
 
Line 1: Line 1:
{| class="wikitable" border="0"
<h3 style='color:#007FFF;font-size:20.0pt;font-family:"Open Sans"'>Administrator Password</h3>
 
<p style='font-size:11.0pt;font-family:"Open Sans"'>Administrator Password lets you create and change password for administrative login of eScan protection center and Two-Factor Authentication.</p>
{| id="mp-topbanner" style="width:100%; background:#fcfcfc; margin-top:1.2em; border:1px solid #ccc;"
<h4 style='color:#007FFF;font-size:18.0pt;font-family:"Open Sans"'><b>eScan Password</b></h4>  
| style="width:56%; color:#000;" |
<p style='font-size:11.0pt;font-family:"Open Sans"'>It also lets you keep the password as blank, wherein you can login to eScan protection center without entering any password for read-only access.<br>There is also an option to set a uninstall password. An uninstallation password prevents personnel from uninstalling eScan client from their endpoint. Upon selecting Uninstall option, eScan asks them for uninstall password. To set an uninstall password, select check box Use separate uninstall password.</p>
{| style="width:280px; border:none; background:none;"
<h4 style='color:#007FFF;font-size:18.0pt;font-family:"Open Sans"'><b>Two-Factor Authentication</b></h4>  
| [[Image:Escan_wikipedia.jpg|left|<!--We add confidence to computing-->]]
<p style='font-size:11.0pt;font-family:"Open Sans"'>Your default system authentication (login/password) is Single-Factor Authentication which is considered insecure as it may put your organization's data at high risk of compromise. The Two-Factor Authentication, also more commonly known as 2FA, adds an extra layer of protection to your basic system logon. The 2FA feature requires personnel to enter an additional passcode after entering the system login password. So, even if an unauthorized person knows your system credentials, the 2FA feature secures a system against unauthorized logons.<br>
|}
With the 2FA feature enabled, the system will be protected with basic system login and eScan 2FA. After entering the system credentials, eScan Authentication screen (as shown below) will appear. The personnel will have to enter the 2FA passcode to access the system. A maximum of three attempts are allowed to enter the correct passcode. If the 2FA login fails, the personnel will have to wait for 30 seconds to log in again.</p>
|width="1000pt" style="width:11%; font-size:95%;" white-space:nowrap;|
<p style='font-size:11.0pt;font-family:"Open Sans"'>To enable the Two-Factor Authentication feature, follow the steps given below:</p>
&nbsp;<B><p>&nbsp;&nbsp;General</p></B>
<li style='font-size:11.0pt;font-family:"Open Sans"'>In the eScan web console, go to Managed Computers. </li>
* [[Main Page|<font color="blue">Home</font>]]
<li style='font-size:11.0pt;font-family:"Open Sans"'>Click on Policy Templates > New Template.</li><br>
* [[Marketing|<font color="blue">Marketing</font>]]
<table class="MsoNormalTable" style="width: 502.1pt; background: #DBE5F1; border-collapse: collapse; border: none;" border="1" width="616" cellspacing="0" cellpadding="0">
* [[Events|<font color="blue">Events</font>]]
<tr>
* [[Marketing/Advertisement|<font color="blue">Advertisement</font>]]
<td style="width: 39.9pt; border: solid windowtext 1.0pt; padding: 0in 5.4pt 0in 5.4pt;" width="53">
* [[Escan/english/Security_Awareness|<font color="blue">Security Awareness</font>]]
<p style="font-size: 11.0pt; font-family: 'Open Sans';"><strong>NOTE</strong></p></td>
|width="1000pt" style="width:11%; font-size:95%; white-space:nowrap;" |
<td style="width: 422.2pt; border: solid windowtext 1.0pt; border-left: none; padding: 0in 5.4pt 0in 5.4pt;" valign="top" width="563">
&nbsp;<B><p>&nbsp;&nbsp;Knowledgebase</p></B>
<p style="font-size: 11.0pt; font-family: 'Open Sans';">You can enable the 2FA feature for existing Policy Templates by selecting a Policy Template and clicking Properties. Then, follow the steps given below.</p></td></tr></table><br>
* [[Technical Info|<font color="blue">Technical Information</font>]]
<li style='font-size:11.0pt;font-family:"Open Sans"'>Select Administrator Password check box and then click on Edit.</li>
* [[Beta Testing|<font color="blue">Beta Testing</font>]]
<li style='font-size:11.0pt;font-family:"Open Sans"'>Click on Two-Factor Authentication tab.<br>Following window appears.</li>
* [[Release Candidate|<font color="blue">Release Candidate</font>]]
<li style='font-size:11.0pt;font-family:"Open Sans"'>Select the check box Enable Two-Factor Authentication.<br>The Two-Factor Authentication feature gets enabled.</li><br>
* [[User Guide|<font color="blue">User Guides</font>]]
<p style='font-size:11.0pt;font-family:"Open Sans"'><b>Login Scenarios</b> <br>The 2FA feature can be used for following all login scenarios: </p>
* [[Escan/english/Technologies|<font color="blue">Technologies</font>]]
<p style='font-size:11.0pt;font-family:"Open Sans"'><b>RDP</b> <br>RDP stands for Remote Desktop Protocol. Whenever someone takes remote connection of a client's system, the personnel will have to enter system login credentials and 2FA passcode to access the system. </p>
|width="1000pt" style="width:11%; font-size:95%;white-space:nowrap;" |
<p style='font-size:11.0pt;font-family:"Open Sans"'><b>Safe Mode</b> <br> After a system is booted in Safe Mode, the personnel will have to enter system login credentials and 2FA passcode to access the system.</p>
&nbsp;<B><p>&nbsp;&nbsp;Support</p></B>
<p style='font-size:11.0pt;font-family:"Open Sans"'><b>Local Logon</b> <br> Whenever a system is powered on or restarted, the personnel will have to enter system login credentials and 2FA passcode to access the system.</p>
* [[EMail|<font color="blue">eMail</font>]]
<p style='font-size:11.0pt;font-family:"Open Sans"'><b>Unlock</b> <br> Whenever a system is unlocked, the personnel will have to enter login credentials and 2FA passcode to access the system.</p>
* [[Online Chat|<font color="blue">Online Chat</font>]]
<p style='font-size:11.0pt;font-family:"Open Sans"'><b>Password Types</b> <br> If the policy is applied to a group, the 2FA passcode will be same for all group members. <br>
* [[Telephonic Support|<font color="blue">Telephone</font>]]
The 2FA passcode can also be set for specific computer(s).<br>
* [[Remote Support|<font color="blue">Remote Support</font>]]
You can use following all password types to log in:</p>
* [[Forums|<font color="blue">Forums</font>]]
<p style='font-size:11.0pt;font-family:"Open Sans"'><b>Use eScan Administrator Password</b> <br>You can use the existing eScan Administrator password for 2FA login. This password can be set in eScan Password tab besides the Two-Factor Authentication tab. </p>
|}
<p style='font-size:11.0pt;font-family:"Open Sans"'><b>Use Other Password</b> <br> You can set a new password which can be combination of uppercase, lowercase, numbers, and special characters.</p>
{| class="wikitable" border="0"  
<p style='font-size:11.0pt;font-family:"Open Sans"'><b>Use Online Two-Factor Authentication</b> <br>This option can be enabled for all users or for particular user according to the requirement. </p>
|}
<table class="MsoNormalTable" style="width: 502.1pt; background: #DBE5F1; border-collapse: collapse; border: none;" border="1" width="616" cellspacing="0" cellpadding="0">
 
<tr>
{| id="mp-topbanner" style="width:100%; background:#fcfcfc; margin-top:1.2em; border:1px solid #ccc;"
<td style="width: 39.9pt; border: solid windowtext 1.0pt; padding: 0in 5.4pt 0in 5.4pt;" width="53">
| style="width:15%; color:#000;" |
<p style="font-size: 11.0pt; font-family: 'Open Sans';"><strong>NOTE</strong></p></td>
{| style="width:100px; border:none; background:none;"
<td style="width: 422.2pt; border: solid windowtext 1.0pt; border-left: none; padding: 0in 5.4pt 0in 5.4pt;" valign="top" width="563">
| [[Image:Mailscan_write.JPG]]
<p style="font-size: 11.0pt; font-family: 'Open Sans';">Users can be added via Settings > Two-Factor Authentication > Users for 2FA option.</p></td></tr></table><br>
|}
<p style='font-size:11.0pt;font-family:"Open Sans"'>To use this feature, follow the steps given below:</p>
|style="text-align:left;"|'''·''' [[Escan/english/MailscanScan-Articles|<font size=1.5 color="blue" align="left">Articles</font>]]&nbsp;&nbsp;'''·''' [[Escan/english/MailScan-FAQ|<font size=1.5  color="blue">FAQ</font>]]&nbsp;&nbsp;'''·''' [[Escan/english/MailScan-Troubleshooting|<font size=1.5 color="blue">Troubleshooting</font>]]&nbsp;&nbsp;'''·''' [[User Guide|<font size=1.5 color="blue">User Guide</font>]]
<ol>
|style="text-align:right;"|&nbsp;&nbsp;'''·''' [[Technical Info|<font size=1.5 color="blue">Technical Information - Main Page</font>]]
<li style='font-size:11.0pt;font-family:"Open Sans"'>Install the Authenticator app from Play Store for Android devices or App Store for iOS devices.</li>
|}
<li style='font-size:11.0pt;font-family:"Open Sans"'>Open the Authenticator app and tap Scan a barcode.</li>
 
<li style='font-size:11.0pt;font-family:"Open Sans"'>Select the check box Use Online Two-Factor Authentication.</li>
{| class="wikitable" border="0"
<li style='font-size:11.0pt;font-family:"Open Sans"'>Go to Managed Computers and below the top right corner, click on code for 2FA.<br>A QR code appears.</li>
|}
<li style='font-size:11.0pt;font-family:"Open Sans"'>Scan the onscreen QR code via the Authenticator app.<br>
 
A Time-based One-Time Password (TOTP) appears on smart device.</li>
*'''"Real-Time" Scanning:-'''MailScan captures all the data with the help of its MailScan Exchange Connector integrated with Exchange, performs virus, content scanning and blocks Spam mails and then delivers the content to the mail server, thereby providing security on a "Real-Time" basis. 
<li style='font-size:11.0pt;font-family:"Open Sans"'>Forward this TOTP to personnel for login.</li></ol>
*'''Virus Scanning:-'''MailScan has its' own inbuilt Anti-Virus, 'eScan', which is integrated with the software in DLL format.Virus infected attachments are disinfected and sent to their destination. Non removable virus infected attachments, are either deleted or quarantined. If MailScan detects a Word or Excel attachment that contains an infected macro, it removes the virus from the attachment.Clean Macros are not removed from the document.
<h4 style='color:#007FFF;font-size:18.0pt;font-family:"Open Sans"'><b>Advanced Setting</b></h4>
*In case of any virus infection, appropriate warning messages, with the Virus Name, Action taken and e-mail details, are sent to the e-mail Sender, the Recipient and the Mail-Server Administrator.
<p style='font-size:11.0pt;font-family:"Open Sans"'>Clicking Advanced Setting displays Advance setting.</p>
*'''Content Scanning.:-'''All incoming and outgoing messages are scanned for abusive words and/or phrases, which are pre-defined by the Security Policy Administrator of MailScan. If such words occur, warning messages can optionally be sent to the Administrator, the sender and the recipient.
<p style='font-size:11.0pt;font-family:"Open Sans"'><b>Enable Automatic Download (1 = Enable/0 = Disable)</b> <br> It lets you Enable/Disable Automatic download of Antivirus signature updates.</p>
*Global Content-Control policies (pre-defined words and phrases) are dynamically updated from the Internet at regular intervals, along with normal Anti-Virus and Policy updates.
<p style='font-size:11.0pt;font-family:"Open Sans"'><b>Enable Manual Download (1 = Enable/0 = Disable)</b> <br>It lets you Enable/Disable Manual download of Antivirus signature updates </p>
*'''Automatic Updates.:-'''MailScan has self-learning and automatic detection capabilities that recognize the Internet connectivity. When MailScan detects an Internet connection, it automatically connects to MicroWorld's FTP server to check for and download Updates. With this feature (that works on dedicated as well as dial-up lines), all MailScan users across the world receive updates on a regular basis. Both Attachment filter rules and AntiVirus Updates are downloaded.
<p style='font-size:11.0pt;font-family:"Open Sans"'><b>Enable Alternate Download (1 = Enable/0 = Disable)</b> <br>It lets you Enable/Disable download of signatures from eScan (Internet) if eScan Server is not reachable. </p>
*Automatic updates can be via FTP or HTTP. Proxy and Firewall (Passive FTP) support is provided. Broken FTP Updates can be resumed from breakpoint.  
<p style='font-size:11.0pt;font-family:"Open Sans"'><b>Set Alternate Download Interval (In Hours)</b> <br>It lets you define time interval to check for updates from eScan (Internet) and download it on managed computers. </p>
*'''Customized Messages:-'''Customized Virus Warning, Content Warning and Reserved Attachments Warning can be sent to the Administrator, the sender and the recipient.
<p style='font-size:11.0pt;font-family:"Open Sans"'><b>Disable download from Internet for Update Agents (1 = Enable/0 = Disable)</b> <br>Selecting this option lets you disable Update Agents from downloading the virus signature from internet. </p>
*Warning messages can be in text or HTML. They can be in English or any other language.  
<p style='font-size:11.0pt;font-family:"Open Sans"'><b>Stop Auto change for download from Internet for Update Agents (1 = Enable/0 = Disable)</b> <br> This option is used when an Update Agent didn't find the primary server to download virus signature, then it tries to get virus signature from internet, so to stop Update Agent from downloading from internet this option is to be set to 1(one).</p>
*'''Forcibly Scan HTML Messages:-'''It forcibly scans HTML messages (not having attachments), to prevent script viruses (like Bubble-boy) from entering your network.
<p style='font-size:11.0pt;font-family:"Open Sans"'><b>Enable Download of Anti-Spam update first on clients (1 = Enable/0 = Disable)</b> <br>Normally while updating a system for virus signatures, we first download the anti-virus signature and then anti-spam signature. This option lets you first download Anti-spam updates on clients. </p>
*'''Malicious Attachments Deletion:-'''Provides an option to forcibly delete known malicious attachments (Trojans and worms) at the gateway level itself. This list is dynamically updated from the Internet at regular intervals, along with normal Anti-Virus and Policy updates.
<p style='font-size:11.0pt;font-family:"Open Sans"'><b>No password for pause protection</b> <br>Selecting this option lets you pause the eScan protection without entering password. </p>
*'''Heuristic Scanning:-'''MailScan's heuristics scanning feature ensures that 90% of unknown viruses are automatically detected, much before the world even gets to know about these viruses. Unknown virus infected files display suspicious behavior. Such files and attachments are detected by MailScan's heuristics engine and are quarantined to a safe directory.
*'''Easy and convenient Administration:-'''MailScan provides a very easy and convenient way of administrating Rule-Sets and Security Policies. Users can install MailScan and use the default settings. All threats, updates, security policies and rule-sets are "automatically updated" from the Internet, without any user-intervention.
*'''Get Up-to-date names of Viruses via e-mail:-'''Whenever MailScan automatically downloads updates, the administrator is informed by e-mail about the time and date of update, number of files downloaded and also a list of viruses that the update cleans. Virus policy updates are done on a daily basis.
*'''Extensive Logs:-'''Every action of MailScan is properly logged. The administrator can control size of Log files and create backups of old Log Files.  
*'''The most important USPs offered by MailScan are that:-'''
**No port settings or changes need to be done inside Microsoft Exchange Server.
**Dedicated gateway machine not needed for using MailScan. MailScan works along with MS Exchange on the same machine.
**Unlike other products, you will NOT lose any of the SMTP functionality's given by MS Exchange.
**Content-Administration.
**MailScan for Exchange will work only with Exchange 2000/2003/2007 for Microsoft Exchange 5.5 and below we recommend MailScan for SMTP.
 
 
 
 
 
Return to [[MailScan for Exchange 2000/2003/2007]]

Latest revision as of 10:55, 1 December 2021

Administrator Password

Administrator Password lets you create and change password for administrative login of eScan protection center and Two-Factor Authentication.

eScan Password

It also lets you keep the password as blank, wherein you can login to eScan protection center without entering any password for read-only access.
There is also an option to set a uninstall password. An uninstallation password prevents personnel from uninstalling eScan client from their endpoint. Upon selecting Uninstall option, eScan asks them for uninstall password. To set an uninstall password, select check box Use separate uninstall password.

Two-Factor Authentication

Your default system authentication (login/password) is Single-Factor Authentication which is considered insecure as it may put your organization's data at high risk of compromise. The Two-Factor Authentication, also more commonly known as 2FA, adds an extra layer of protection to your basic system logon. The 2FA feature requires personnel to enter an additional passcode after entering the system login password. So, even if an unauthorized person knows your system credentials, the 2FA feature secures a system against unauthorized logons.
With the 2FA feature enabled, the system will be protected with basic system login and eScan 2FA. After entering the system credentials, eScan Authentication screen (as shown below) will appear. The personnel will have to enter the 2FA passcode to access the system. A maximum of three attempts are allowed to enter the correct passcode. If the 2FA login fails, the personnel will have to wait for 30 seconds to log in again.

To enable the Two-Factor Authentication feature, follow the steps given below:

  • In the eScan web console, go to Managed Computers.
  • Click on Policy Templates > New Template.

  • NOTE

    You can enable the 2FA feature for existing Policy Templates by selecting a Policy Template and clicking Properties. Then, follow the steps given below.


  • Select Administrator Password check box and then click on Edit.
  • Click on Two-Factor Authentication tab.
    Following window appears.
  • Select the check box Enable Two-Factor Authentication.
    The Two-Factor Authentication feature gets enabled.

  • Login Scenarios
    The 2FA feature can be used for following all login scenarios:

    RDP
    RDP stands for Remote Desktop Protocol. Whenever someone takes remote connection of a client's system, the personnel will have to enter system login credentials and 2FA passcode to access the system.

    Safe Mode
    After a system is booted in Safe Mode, the personnel will have to enter system login credentials and 2FA passcode to access the system.

    Local Logon
    Whenever a system is powered on or restarted, the personnel will have to enter system login credentials and 2FA passcode to access the system.

    Unlock
    Whenever a system is unlocked, the personnel will have to enter login credentials and 2FA passcode to access the system.

    Password Types
    If the policy is applied to a group, the 2FA passcode will be same for all group members.
    The 2FA passcode can also be set for specific computer(s).
    You can use following all password types to log in:

    Use eScan Administrator Password
    You can use the existing eScan Administrator password for 2FA login. This password can be set in eScan Password tab besides the Two-Factor Authentication tab.

    Use Other Password
    You can set a new password which can be combination of uppercase, lowercase, numbers, and special characters.

    Use Online Two-Factor Authentication
    This option can be enabled for all users or for particular user according to the requirement.

    NOTE

    Users can be added via Settings > Two-Factor Authentication > Users for 2FA option.


    To use this feature, follow the steps given below:

    1. Install the Authenticator app from Play Store for Android devices or App Store for iOS devices.
    2. Open the Authenticator app and tap Scan a barcode.
    3. Select the check box Use Online Two-Factor Authentication.
    4. Go to Managed Computers and below the top right corner, click on code for 2FA.
      A QR code appears.
    5. Scan the onscreen QR code via the Authenticator app.
      A Time-based One-Time Password (TOTP) appears on smart device.
    6. Forward this TOTP to personnel for login.

    Advanced Setting

    Clicking Advanced Setting displays Advance setting.

    Enable Automatic Download (1 = Enable/0 = Disable)
    It lets you Enable/Disable Automatic download of Antivirus signature updates.

    Enable Manual Download (1 = Enable/0 = Disable)
    It lets you Enable/Disable Manual download of Antivirus signature updates

    Enable Alternate Download (1 = Enable/0 = Disable)
    It lets you Enable/Disable download of signatures from eScan (Internet) if eScan Server is not reachable.

    Set Alternate Download Interval (In Hours)
    It lets you define time interval to check for updates from eScan (Internet) and download it on managed computers.

    Disable download from Internet for Update Agents (1 = Enable/0 = Disable)
    Selecting this option lets you disable Update Agents from downloading the virus signature from internet.

    Stop Auto change for download from Internet for Update Agents (1 = Enable/0 = Disable)
    This option is used when an Update Agent didn't find the primary server to download virus signature, then it tries to get virus signature from internet, so to stop Update Agent from downloading from internet this option is to be set to 1(one).

    Enable Download of Anti-Spam update first on clients (1 = Enable/0 = Disable)
    Normally while updating a system for virus signatures, we first download the anti-virus signature and then anti-spam signature. This option lets you first download Anti-spam updates on clients.

    No password for pause protection
    Selecting this option lets you pause the eScan protection without entering password.