Multi-Factor Authentication for the IBM i
ARP-AUTH is a software only solution for -Multi-Factor Authentication (MFA) on the IBM i. MFA is an approach to authentication which requires the presentation of at least two of the three high assurance authentication factors:
Knowledge Factor (something only the user knows)
Possession Factor (something only the has)
Inherence Factor (something only the user is)
Traditionally solutions for MFA were cost prohibitive for IBM i users as solutions required expensive smart cards or tokens. With ARP-AUTH you can now use smart phones or tablets as the possession factor in MFA and unlike cards or tokens, it is highly assured and you can use phones or tablets to trigger hacker alerts.
ARP-AUTH is built upon Arpeggio cloud connector platform and supports using cloud based Cisco Duo or Twilio's Authy platform. ARP-AUTH has a fully configurable security panel for defining the rules of how MFA will behave on your system. The configuration rules include when to require MFA (e.g. after hours, for privileged user profiles, users outside the network, etc.) as well as the number of phone numbers to attach to users and the method for communicating PINs (push, text or voice message).
When you attempt to log in you will receive a push message to accept or reject the login or you will receive a PIN. To complete the MFA process you either accept the pushed message on your trusted device or enter the PIN that was sent. Unlike other vendors, ARP-AUTH allows you to truly use your smartphone or tablet as a SMART SECURITY DEVICE because when you receive an unwanted push message or a PIN when someone is trying to log in as you, you can reject or reply via your smartphone and an intruder shutdown process can commence. ARP-AUTH will actually treat push rejections and replies to PINs and pushed approval requests as a signal and you have options for shutting down the potential hacker including blocking IP addresses, disabling profiles and sending alerts to security teams.
ARP-AUTH offers an out of the box solution for MFA using standard login access to the IBM i. ARP-AUTH is the only product offering MFA support for Navigator for i. And the integration with ARP-SFTP Server makes ARP-AUTH the only solution providing MFA protection for SFTP and FTP server access on the IBM i. There are also API examples included to help you implement MFA security on accessing your own applications.
Another unique feature built into ARP-AUTH is secure profiling swapping. Secure profile swapping allows a user to temporarily borrow the permission levels of another user. This solves an issue many organization face of addressing employee's being out when important processes need to be executed and historically users would share login credentials. With Secure Profile Swapping a workflow rule can be entered with time windows permitting the permission borrowing and anytime a user swaps permissions secure logs are generated and retained and even emailed to security staff.
ARP-AUTH has a profile analyzer that serves as a tool for targeting MFA implementations based on security settings in user profiles and it can also be used as a reporting tool during security audits.
See for yourself and download a trial of ARP-AUTH.