This guide outlines recommended security practices for HRPro Employee Portal and HR Workspace hosted on Microsoft Internet Information Services (IIS). It covers Internet exposure, authentication, encrypted connections, server permissions and ongoing security management.
Use a layered approach: combine application security settings with appropriate network controls, secure server configuration and regular maintenance. The existing HRPro guidance recommends these controls together rather than relying on a single security feature.
Keep the core HRPro application server, SQL Server, and administrative interfaces on a private network. Do not expose SQL Server, Remote Desktop (RDP), IIS management, or other administrative services directly to the Internet.
Where external access is required:
Publish only the necessary Employee Portal or HR Workspace website through HTTPS.
Protect the public-facing website with appropriate firewall rules and, where practical, a web application firewall (WAF).
Use a VPN, private connectivity, or a controlled remote-access solution with MFA for server administration.
Separate the public-facing web server from the application and database servers where practical.
Restrict communication between servers to the services and ports required by the deployment.
Employee access and HR administrative access
Employee self-service access and HR administrative access should be assessed separately. As an additional deployment recommendation, keep HR Workspace private where external access is not required. If it must be accessible remotely, apply access controls appropriate to its administrative role rather than automatically publishing it alongside Employee Portal.
Enable two-step verification
HRPro provides email-based two-step verification. After entering their login credentials, users must enter a verification code sent to their registered email address.
For the Employee Portal, review the settings under Employee Portal Setup → General tab → Login panel. Where appropriate, select Enforce so that verification is required rather than left to individual users. HR Workspace also provides two-step verification through Personal Options.
Protect the email accounts used to receive verification codes with MFA as well. CISA recommends enabling MFA across email and remote-access services, not just the application being protected.
Use Microsoft or Google sign-in where appropriate
Employee Portal supports Sign in with Microsoft and Sign in with Google. These options allow users to authenticate through an external identity provider and can reduce reliance on separate portal passwords.
Do not assume that using an external sign-in button automatically guarantees MFA. Confirm that the relevant Microsoft or Google account policies require additional verification. Where supported by the identity provider, prefer phishing-resistant methods such as FIDO/WebAuthn security keys or passkeys.
Understand Active Directory authentication
Active Directory authentication allows employees to use their domain credentials to sign in. It centralises credential management, but a domain username and password alone do not constitute MFA. Additional verification must be enforced through the relevant identity or access solution.
Treat CAPTCHA as a supplementary control
CAPTCHA is a bot-mitigation measure, not an authentication factor. Traditional text-based CAPTCHA can be solved by modern automated tools and should not be relied on as the main protection against account compromise.
Use CAPTCHA alongside stronger controls such as two-step verification, account lockout, rate limiting and monitoring.
For accounts that use HRPro passwords:
Configure the available password policy settings to require sufficiently long passwords.
Encourage unique passwords that are not reused for other services.
Review account lockout settings and failed-login activity.
Disable access promptly when an employee leaves or no longer requires it.
Employee Portal provides password-policy settings and a documented lockout mechanism that locks an account for 15 minutes after five consecutive failed login attempts. Confirm the behaviour in your installed version before relying on it operationally.
Replace predictable initial passwords
As an additional deployment recommendation, do not leave predictable initial passwords in use.
Employee Portal sets the first six digits of an employee’s HKID as the default password. Review the initial password and onboarding arrangements before enabling access, particularly for an Internet-facing deployment. Require employees to replace predictable initial passwords before routine use.
Configure the website with a valid TLS certificate and an HTTPS binding in IIS. Employees and administrators should access the Employee Portal and HR Workspace through HTTPS so that browser-to-server traffic is encrypted.
Recommended deployment checks include:
Confirm that the certificate matches the hostname used by users.
Monitor certificate expiry and arrange renewal in advance.
Redirect ordinary HTTP requests to HTTPS where appropriate.
Check that login pages, downloads and externally generated links use HTTPS.
Test authentication and external sign-in after changing HTTPS or proxy settings.
These checks should be part of your deployment acceptance process rather than a one-time installation task.
Review the following settings in HRPro.config and EPortal.config, as applicable:
UseSecureCookies
SqlConnectionEncrypt
The current HRPro security guidance recommends enabling both settings. Coordinate any changes with your system administrator and verify application operation afterwards.
Validate SQL Server certificates
Encrypting a database connection and verifying the database server’s identity are separate controls.
For production deployments, use a SQL Server certificate that the application server trusts, and retain certificate validation. Setting TrustServerCertificate=True can encrypt the connection while bypassing certificate validation; it should not be treated as equivalent to a properly validated TLS connection.
Do not disable encryption or bypass certificate validation as a permanent workaround for connection errors. Instead, investigate the certificate’s trust chain, validity, and server-name matching.
Run each HRPro web application in an appropriately configured application pool. IIS application pool identities provide a separate identity for each pool and isolate processes between applications.
Recommended administrative controls include:
Use a dedicated, non-administrative application pool identity.
Grant only the file and folder permissions required by the application.
Limit write access to folders that genuinely need it.
Avoid broad permissions such as Full Control for Everyone.
Review IIS Request Filtering to control request sizes, file extensions, and HTTP methods where compatible with HRPro.
IIS Request Filtering supports restrictions on verbs, extensions, and request limits. Test changes against required HRPro functions, including uploads, downloads, reports, and sign-in, before applying them to production.
Use firewall rules to allow database access only from approved application servers and authorised administration systems.
For Internet-facing deployments, use network-level firewalls alongside Windows Defender Firewall. Keep SQL Server, RDP, and IIS management inaccessible from the public Internet.
Additional recommended controls:
Use a dedicated application database account with permissions appropriate to HRPro’s requirements.
Avoid using a highly privileged database account merely to resolve a permissions error.
Restrict access to configuration files containing database credentials.
Manage database credentials separately from database connection encryption.
Confirm required database permissions with HRPro support before changing an existing deployment.
Keep Windows Server, IIS, SQL Server, and HRPro updated through a controlled maintenance process. Current patches and monitoring are part of the existing HRPro recommendations for public-facing deployments.
As an additional operational practice, establish a monitoring checklist covering:
Repeated failed logins and account lockouts.
Unexpected changes to application files or configuration.
Unusual administrative access.
Repeated application errors or suspicious web requests.
Certificate expiry.
Failed scheduled jobs or backups.
Assign responsibility for reviewing alerts and define when an issue should be escalated. Avoid recording passwords, verification codes, or unnecessary personal information in diagnostic logs.
Review document protection
Employee Portal provides an option to password-protect downloaded documents such as payslips and IR56B forms. Review Password Protect Download Documents in Employee Portal Setup and assess whether it is appropriate for your organisation.
Maintain a tested recovery plan
As an additional operational recommendation:
Back up the HRPro databases, required application files and configuration.
Protect backups with restricted access and appropriate encryption.
Retain a recovery copy that is isolated from normal production access.
Test restoration periodically.
Document how to recover the website, database connections, and required certificates.
A backup process should include evidence that restoration works, not only confirmation that backup jobs completed.
Use the following checklist before publishing a deployment and during periodic reviews:
Only necessary web services are exposed to the Internet.
SQL Server, RDP, and IIS management remain private.
Employee Portal and HR Workspace use HTTPS.
Certificates are valid, and renewal is planned.
Two-step verification or identity-provider MFA is enforced where appropriate.
CAPTCHA is used only as a supplementary control.
Predictable initial passwords have been replaced.
Password policies and account lockout settings have been reviewed.
UseSecureCookies and SqlConnectionEncrypt have been reviewed and enabled as appropriate.
Database connections use encryption with certificate validation.
IIS application pool identities and folder permissions follow least-privilege principles.
Server and application updates are maintained.
Security logs and alerts have an assigned owner.
Backups are protected, and restoration has been tested.
Access is reviewed when employees leave or change roles.
This checklist combines the documented HRPro controls with the additional deployment and operational recommendations above; it is not a statement that every item is automatically enforced by HRPro.
Consult your system or network administrator to configure and maintain IIS and the supporting network infrastructure. Use HTTPS, restrict administrative access, apply appropriate permissions, and keep the server and application software up to date.
IIS Configuration References
Refer to the following Microsoft resources:
Review each recommendation against your HRPro deployment and application requirements before applying changes.
Additional Security Solutions
Your IT administrator may consider optional third-party solutions to strengthen security, depending on your organisation’s infrastructure and access requirements:
Web application firewall (WAF) — Helps protect an Internet-facing Employee Portal by inspecting web requests and blocking common web attacks. Examples include Cloudflare WAF 🡕 and Azure Web Application Firewall 🡕.
Secure remote access — Provides controlled access to private applications and administrative services through VPN or zero-trust network access. An example is Cisco Secure Client, including AnyConnect 🡕.
Identity and authentication — Provides additional authentication and access-management controls where supported by the selected infrastructure. Examples include RSA SecurID and ID Plus 🡕.
These solutions serve different purposes and should complement—not replace—secure IIS configuration, HRPro security settings, and regular maintenance.
Compatibility and Deployment
Third-party products are listed for reference only. Their inclusion does not indicate a certified HRPro integration or guaranteed compatibility. Your IT administrator or security provider should confirm suitability, licensing, and configuration requirements.
Before deployment, test the relevant HRPro functions, including sign-in, two-step verification, external sign-in, file uploads, document downloads, and mobile access. Where a proxy or caching service is used, ensure that authenticated pages and confidential documents are not stored in a shared cache.
Related Help Topics
How to Enable Active Directory Authentication for Employee Portal Login
How to Enable SSL (HTTPS) Connection for HRPro Web Application Server
Configure IIS Application Pools and Folder Permissions for HRPro
The Help Center includes these authentication, setup, and deployment topics for further configuration guidance.