Today, Microsoft validated and released a Microsoft ISV Gold Certification for the latest SMS PASSCODE Version 6 product. At the same time, we released our latest SMS PASSCODE 6.2SP1 that includes the following:
Enhanced SMS PASSCODE Password Reset Module infrastructure
Building on this new popular feature, SMS PASSCODE Version 6.2 SP1 delivers further security enhancements to the Password Reset Web Site and the back-end infrastructure when published for these remote access users. Historically, the two components have resided on the same server, but in SP1, we have separated the two enabling only the Password Reset Web Site to reside in a DMZ and the rest of the Password Reset infrastructure to reside behind the firewall provides better security and flexibility. Specifically, this means that SP1 delivers, a redesign of the Password Reset module splitting it into two components: the Password Reset Web Site and the Password Reset Backend Service.
You may now install both components on the same server, if you wish the same infrastructure as previously, or alternatively install them on separate servers. E.g. you may install the Password Reset Web Site in a DMZ, while installing the Password Reset Backend Service on the LAN side. This will provide better protection of the password reset mechanism, in case the DMZ is compromised.
Remote Desktop Web protection / Windows Server 2012
SMS PASSCODE supports protection of Microsoft Remote Desktop environments on both Windows Server 2008 (x86/x64), Windows Server 2008 R2 and Windows Server 2012. This is supported both directly on the RD Session Hosts via SMS PASSCODE Windows Logon Protection or on the RD Web/RD Gateway access level via SMS PASSCODE IIS Web Site Protection. Starting from Windows Server 2012, the RD Gateway infrastrucure has been redesigned which requires Windows Server 2012 to have protection on each Remote Desktop Session host with the SMS PASSCODE Windows Logon Protection component. Please consult the SMS PASSCODE Administrator’s Guide for more details. SP1 includes modifications to accommodate for this configuration change.