SafeConsole Central USB Management
What is SafeConsole Central USB Management?
SafeConsole enforces full usb management control over an organizations SafeStick secure flash drives. With SafeConsole you can enable specific extended SafeStick features, configure password policies, remotely reset passwords, activate audit for compliance and much more. The SafeConsole server software is accessed through a standard web browser and can optionally reflect the corporate directory organizational unit structure. Each managed SafeStick securely connects over the web to the SafeConsole server for configuration updates set to the specific group it is assigned to.
Why Manage USB with SafeConsole?
- Instantly gain complete and granular control over all your SafeStick drives.
- Quickly enforce organization specific password, usage and storage policies.
- Remote password reset with a secure challenge-response procedure brings back the locked-down encrypted data that has been stored by the user.
- Feature rick with lots of productivity tools and 2-in-1 features such as a Certificate Carrier and portable applications delivery.
- Rapid deployment with an all-in-one installation that has the power to server 100.000+ SafeStick deployments. No extra licenses for databases or certificate management are needed and the server requirements are low (2GB RAM, Windows or Linux). It is optional to reflect an existing corporate directory within SafeConsole.
- Easy and flexible user self-service roll-out of SafeStick. Just plug and work.
How Can SafeConsole be Deployed?
SafeStick and SafeConsole can be deployed flexibly. Start the roll-out with SafeStick or SafeConsole, either way you will gain full management control once the full solution is in place. The deployment process of the full SafeStick and SafeConsole solution is completed when each unique SafeStick drive is registered to a specific user on the SafeConsole server.
1. User Accounts Authenticate to the SafeConsole Server
User accounts are connected to the SafeConsole server by setting a SafeStick-specific registry flag and deploying a certificate. This can be accomplished with a GPO in a larger organization.
2. Self-Service SafeStick Deployment
SafeStick drives are distributed within the organization. The user claims ownership of the SafeStick upon the insertion when the registry flag is first identified. Note that the claim can be made after using SafeStick for some time. The claim is a one-click procedure and this links the unique asset number that is embedded in each SafeStick drive to the specific user (in the reflected corporate directory when available). No preregistration of devices and user is needed. The deployment is a fully automatic and compliant process.
3. SafeStick Under Management Control - Ready To Use
Thhe configurations that are set in SafeConsole for the specific user accounts group (organizational unit) is automatically applied to the device. Users that have expired or insufficient settings and passwords are aligned with the selected settings. The configurations can be continuously updated inside and outside the corporate network and ownership can change during multiple device life-cycles.
SafeConsole Features and SafeStick Extended Features
SafeConsole brings to life the full power of SafeStick and puts in place the structure that enterprises and larger organizations need to manage USB.
Remote Password Reset - Get Access To Mission Critical Data In Seconds
If a user forgets the chosen password needed to access information stored on SafeStick a remote administrator can help the mobile worker to get back to business in a matter of minutes. No data is lost and the process is protected against social engineering directed against the helpdesk. The password reset is also important to recover data from devices that are to be issued to new users. There is also the possibility to activate self-service password management as part of the ZoneBuilder feature if support costs are a top priority.
Custom Password Policy
It is possible to configure multiple complex password policies within SafeConsole and assign them to different groups within the organization. There is also the option to set a limited life-span for the password based on the number of unlocks or days passed since the last password change.
Timer Lock Down
Centrally control the SafeStick Timer Lock and preset it to switch on after a configurable period of inactivity. If a user forgets an unlock SafeStick in a computer the device will automatically lock down in accordance with the set policy. This erases the threat from one of the most common data breach scenarios regarding portable storage.
Remote Status Management - Kill, Disable or Mark SafeStick as Lost
Under the SafeStick overview in SafeConsole an authorized administrator can kill rogue drives over the Internet. SafeStick can also be set to the statuses disabled and lost. Disabled devices can later be recovered with the Password Reset feature. Lost drives can be set to display a custom Return-To-Owner message. Lost drives that are later inserted into the assigned users local machine are automatically set as found to lower support costs. All transations are logged for audit purposes.
Secure Deliver of SafeConsole USB Management
Duringg the straight forward SafeConsole local server installation the organization enters or generates their key (the private digital certificate). This unique key locks the solution completely to the organization and enables authenticated management for administrators from trusted machines. Privacy is by this procedure guaranteed for the organization and the managed SafeStick drives as all communications are encrypted. The SafeConsole server software is available as a signed download to enable rapid deployments and even test installations.
|
|



|