laptop-img

TecSSPR: Self-Service Password Recovery

For Okta users with the freedom to reset their password from lock screen. 
Supports Okta Verify, and more as recovery factors.

You forgot, you retrieve. 

What is TecSSPR?

In most organizations, the largest volume of help desk calls is for resetting passwords. The traditional approach for password recovery is time consuming and less secure. “Tecnics Self Service Password Recovery” (TecSSPR) allows users to recover passwords on the login/lock screen of their Desktops (Windows 10 or MAC). Users do not have to reach out to help desk or be dependent upon the other traditional methods for password recovery.

TecSSPR is a Windows Credential Provider developed on top of Okta's MFA & Policy framework and extends the recovery factors available in Okta to provide other factors like Okta Verify, Yubikey etc. as MFA options.

Features

Supported Factors

Currently, all Okta customers wanting to recover their password will have to navigate to the Okta login page and click on the “Forgot password?” link. The default password recovery factors presented by Okta are SMS, Email and Voice. A lot of Okta customers require other factors like Okta Verify, Duo, Google Authenticator, Yubikey etc., for self service password recovery.

TecSSPR addresses this requirement and provides additional factors configured in Okta for password recovery including:

  • Okta verify
  • Voice
  • Duo
  • Google Authenticator
  • Security Question
  • Yubikey
  • SMS
  • Email
  • OnPrem MFA
  • RSA Secure ID

Password Recovery without the Help-Desk

In most organizations, the traditional approach for password recovery is to call help desk or create a ticket. This process is time consuming and is non-productive for both the user and the help desk team. It also lacks proper policy and compliance. TecSSPR allows the user to reset their password from the Windows login screen after entering the second factor for authentication configured in Okta. This allows the organization to enforce all password policies configured in the Okta tenant. The process to recover the password is very user friendly, secure and fast thereby increasing productivity, improving the user experience and reducing the help desk costs.

Recover Password in a secure & auditable manner

In the traditional approach for password recovery, most of the time the help desk team delivers the password to the user in less secure methods.

TecSSPR allows the user to reset their password from the Windows login screen after entering the second factor for authentication configured in Okta. This allows the organization to enforce all password policies configured in the Okta tenant.

Technical Architecture

Windows operating systems does TecSSPR support?

TecSSPR supports following operating systems

  • Windows
  • MAC
Which Windows versions does TecSSPR support?
  • Windows 11
  • Windows 10
Which version of MAC does TecSSPR support
  • Mojave
  • Catalina
  • Big Sur
  • Monterey
What is the Hardware/Software requirements for deploying TecSSPR?
  • Desktops with Windows 10 / MAC for deploying TecSSPR Credential Provider
  • One or more Windows servers (Windows server 2008 R2 or later, including Server 2016 and Windows Server 2019 ) in your network to deploy TecSSPR web site in IIS. These servers must be on at all times and have a continuous connection to the Internet so that they can communicate with Okta cloud.
  • The server can be a physical or virtual server
  • The server should have at least 2 CPUs and a minimum of 8 GB RAM
Which factors does TecSSPR support?
  • Okta Verify
  • SMS
  • Voice
  • Email
  • Duo
  • Google Authenticator
  • Yubikey
  • Security Question
  • OnPrem MFA
  • RSA Secure ID
Does TecSSPR support English and non-English versions of Windows10 operating system?

TecSSPR is currently supported on the English and Spanish version of Windows10 operating system. If there is a specific language requirement for a customer, we may provide support through PS engagement.

How do I install TecSSPR?

TecSSPR supports silent installation or installation via GPO.

What do Okta users need to use TecSSPR ?

TecSSPR is developed on Okta's MFA framework and leverages on the policies and factors (Okta Verify) configured in Okta. The only requirements from end user perspective are, access to a Desktop with TecSSPR Windows Credential Provider installed and at least 1 recovery factor configured in Okta.

Are offline scenarios supported by TecSSPR?

TecSSPR is developed on top of Okta's Password Recovery Framework and requires Okta to enforce all policies. Offline mode is currently not supported.