FAQ
Service Basics
What kind of solution is SHIELD ID?
Key
Centralized management of organizational accounts and authentication**Zero Trust-based IdP (Identity Provider)**This is a solution.
SHIELD ID provides the following features:
- Support for both cloud and on-premises environments
- SSO (Single Sign-On), MFA (Multi-Factor Authentication), Provisioning, Account Lifecycle Management
What should be prepared before introducing SHIELD ID?
The main preparations are as follows:
| Preparation Items | Explanation |
|---|---|
| Securing Administrator Privileges | Administrator account required for the linked target system |
| Network and Firewall Configuration | Procedures for Secure Communication |
| Establishing an Authentication Policy | Conditional Access Policy, MFA Settings |
Authentication Method
What authentication methods does SHIELD ID support?
SHIELD ID basically supports the following authentication methods.
Security365 Certification
Use Security365 ID and your own passwordis an authentication method.
- Used when a manually registered user logs in
- Password reset available if needed
CSP Certification (Cloud Service Provider)
Cloud service accounts already in use by organizations such as Microsoft365 and GoogleThis is the method of logging in.
ID registered with Security365 and CSP accountThe ID must matchAuthentication is possible.
How are account and password policies managed?
Administrators can set policies such as password length, combination rules, change cycles, and reuse prohibition through the Security365 management center console.
| Policy Item | Setting Scope |
|---|---|
| minimum length | 8 ~ 13 characters |
| Change Cycle | 30 ~ 180 days |
| Automatic Logout | Unused time (1 ~ 12 hours) 기준 |
| Multiple Access Control | Automatic termination of existing sessions when accessing from a different IP of the same account |
Users can check their last access records (IP, time) upon logging in, which can enhance security awareness.
Personnel Linkage
Can I check the user group path on the log page after the personnel linkage?
SHIELD ID is integrated with Microsoft Entra ID or SCI Server, throughFunction to check the user's affiliated group path on the log pageprovides.
Through this, administrators can intuitively understand the user's organizational location (department, team, etc.) during log analysis.
Where can I check the synchronized group path?
log page'sDepartment ColumnYou can check it at.
Search Function:
You can also search logs based on the user's group path.
Example: Hong Gil-dong's group affiliation path is소프트캠프/영업부문/영업1팀in case
소프트캠프,영업부문,영업1팀No matter what you search for, Hong Gildong's log is retrieved.
Is any action required for group path synchronization?
After changing the integration settings, the firstOne-time manual synchronizationis needed.
Synchronization must be completed for the group path information to be reflected in the logs.
What should you be careful about when setting the group path?
- Setting the Reference Group: If the reference group is set incorrectly, some users may not be able to see their group paths.
- Microsoft Group Synchronization: In designated group synchronization, user data outside of the selected group is not included.
- SCI Server: The top-level group is automatically set, so no separate selection is required.
Passwordless
Which browsers support passwordless FIDO2 authentication for registration?
- **Registration is recommended to be done using the Microsoft Edge browser.**does.
When using Chrome browser
When registering in the Chrome browser, there are cases where it is saved in Google Password Manager and cannot be used in the SHIELD ID authentication process.
What should I do if I lost my authentication device or cannot use it?
On the login screen다른 방법으로 로그인You can log in using the password method by clicking.
The device reset (initialization) feature will be provided through an update in the future.
The passwordless registration window appears every time. Why is that?
If you have not registered an authentication device yet, a window will appear after logging in to check whether to register for Passwordless each time.
Solution:
오늘 하루 보지 않기If you check it, the corresponding popup can be hidden for a day.
I keep failing at passwordless authentication. What should I do?
Try the following steps:
- Retry according to the provided instructions
다른 방법으로 로그인Click to change the authentication method and attempt authentication.- Check if the authentication device is properly connected and active.
Does passwordless authentication support mobile environments?
- It is possible, but there may be some limitations depending on browser compatibility (Safari, Chrome, etc.).