ADSelfService Plus

Self-service password recovery, MFA, SSO and password synchronisation for workforce identities.

For Active Directory, Entra ID and hybrid application estates needing self-service access recovery and authentication.

Restore account access and simplify application sign-ins

Forgotten passwords and locked accounts can interrupt work and create routine recovery requests. Separate sign-ins for connected applications and passwords that fall out of sync add further friction for users.

ADSelfService Plus lets users reset passwords, change passwords and unlock Active Directory, Entra ID and cloud accounts through self-service. It combines these functions with MFA, SSO and real-time password synchronisation, so users can restore access and use connected applications with fewer separate sign-ins.

Where ADSelfService Plus is used

The product is suited to workforce identity tasks such as account recovery, password changes and account unlocks across Active Directory, Entra ID and cloud accounts. It also applies MFA to machine access, enterprise applications, VPNs, OWA and RDP.

For connected enterprise applications, it provides IdP- and SP-initiated SSO for SAML-, OAuth- and OIDC-based applications and synchronises password resets and changes. Password expiry notifications and fine-grained password policies support the ongoing management of password-based access.

Fits within these solutions

Self-Service Password Reset
Single Sign-On
Multi-Factor Authentication
Password Policy Management
Conditional Access & Risk Policies
Password Management

Suitable environments

ADSelfService Plus applies to Active Directory, Entra ID and cloud accounts, hybrid enterprise applications, and Windows, macOS and Linux machines. Login-screen password reset, conditional access and cached credential updates are Professional edition features.

Benefits

Faster Access Recovery

Users can restore account access through password reset or account unlock without routine helpdesk involvement.

Fewer Sign-Ins

SSO gives users access to connected enterprise applications with fewer separate sign-ins.

Consistent Password Changes

Real-time synchronisation keeps password changes aligned across connected applications and machines.

Additional Sign-In Assurance

MFA adds identity verification for access to supported endpoints, applications and remote access services.

Timely Password Reminders

Scheduled notifications remind users about approaching password expiry by email, SMS or push notification.

Capabilities

Password Self-Service

Enables users to reset and change passwords, and unlock Active Directory, Entra ID and cloud accounts.

Multi-Factor Authentication

Enforces MFA for endpoints, applications, VPNs, OWA and RDP.

Authentication Methods

Supports FIDO passkeys, biometrics, YubiKey and smart cards as authentication methods.

Enterprise Single Sign-On

Provides IdP- and SP-initiated SSO for SAML-, OAuth- and OIDC-based enterprise applications.

Password Synchronisation

Synchronises password resets and changes across enterprise applications and machines in real time.

Password Policy Notifications

Applies fine-grained password policies and sends scheduled password expiry notifications.

Common Use Cases

Account Recovery

Use self-service password reset and account unlock for Active Directory, Entra ID and cloud accounts.

Endpoint and Remote MFA

Apply MFA to endpoints, VPNs, OWA and RDP alongside enterprise applications.

Application Federation

Provide SSO for enterprise applications that use SAML, OAuth or OIDC.

Password Change Propagation

Synchronise user password resets and changes across connected applications and machines.

Password Expiry Management

Notify users of scheduled password expiry dates through email, SMS and push notification.

Part of (depending on licence)

Resources

How would you like to proceed?