Employee Portal provides employees with secure online access to HR information and self-service functions. This guide explains recommended security practices for IIS-hosted Employee Portal and HR Workspace deployments, including limiting public exposure, securing authentication, encrypting data, and protecting supporting servers and network services.
Multi-factor Authentication (MFA) requires two or more verification factors before granting access, protecting against credential theft.
Employee Portal supports these MFA methods:
2-step verification: Username/password plus a code sent via email, ensuring email access is needed post-password compromise.
CAPTCHA login: Challenge-response test to block automated bots and verify human users.
Active Directory Authentication: Integrates with Microsoft AD for domain credentials, adding enterprise identity security.
Important note on CAPTCHA in the AI era
Traditional text-recognition CAPTCHA is increasingly unreliable as a primary security control because modern bots and AI agents can often solve CAPTCHA challenges automatically. For this reason:
CAPTCHA in Employee Portal should be treated as a basic bot‑mitigation measure, not as MFA or strong protection against targeted attacks.
Administrators are strongly recommended to enable modern MFA options (email codes, Microsoft/Google sign‑in with MFA, or AD‑backed authentication) and not rely on CAPTCHA alone for account security.
Enable in Employee Portal Setup > General tab (Login panel)
Sign in with Microsoft: Uses Microsoft Entra ID (OAuth 2.0); inherits organisation MFA policies (e.g., Authenticator, SMS, conditional access). Employees log in with existing Microsoft Work/School/Personal accounts (Office 365, Outlook) instead of separate portal passwords. Centralizes identity via email matching in Employee Master. How to Enable "Sign In with Microsoft".
Sign in with Google: Leverages Google OAuth 2.0 and Workspace MFA (e.g., Authenticator, security keys). Authenticates via Google Account (Gmail/Workspace) with email match in Employee Master, reducing password fatigue and support overhead. How to Enable "Sign In with Google".
Implement a Password Policy to enforce strong passwords, preventing unauthorized access and data leaks. Benefits include better strength enforcement and reduced breach risk.
Configure HTTPS in IIS for encrypted client-server communication using an SSL certificate and HTTPS binding. Test via secure requests to prevent data interception.
As a security best practice, do not expose the core HRPro application server, SQL Server/database server, or administrative interfaces directly to the public Internet. Keep these systems on a private internal network and access them through secure methods such as VPN, private connectivity, or a controlled remote-access solution with MFA.
Where employees require external self-service access, publish only the Employee Portal/HR Workspace through HTTPS and protect it with appropriate security controls, such as a firewall/WAF, MFA or SSO, strong password policies, CAPTCHA/rate limiting, current OS/IIS/application patches, restricted database connectivity, and monitoring.
The Employee Portal web server should be separated from the HRPro application and database servers where practical. Do not permit direct Internet access to SQL Server, RDP, IIS management, or other administrative ports.
Proper firewall configuration limits exposure, blocking unauthorized access while allowing legitimate traffic. For internet-facing setups, use network firewalls (e.g., Azure NSG, hardware appliances) alongside Windows Defender Firewall.
Consult your network administrator for IIS management. Key guidelines:
It is also recommended to enable these for enhanced control:
Turn on UseSecureCookies and SqlConnectionEncrypt in HRPro.config and EPortal.config.
SQL Server Password Encryption.
See also:
2-step verification at Personal Options (EPortal)
2-step verification at Personal Options (HR Workspace)
Password Policy in Employee Portal Setup, General tab
Password Policy in System Manager Setup
How to Enable Active Directory Authentication for Employee Portal Login
Turn on UseSecureCookies in HRPro.config and EPortal.config.
How to Enable SSL (HTTPS) Connection for HRPro Web Application Server