Overview
This article explains the information that should be provided to end users in advance, login URLs, and procedures for various settings when starting to use each HENNGE One service.
Notes
- Consider the information to be provided to end users according to the service and intended use.
- The URLs for each HENNGE One service differ depending on your environment.
- The content of this article is based on product specifications as of October 2026 and may be changed without notice.
Table of Contents
- Access Control User Portal URL
- Login URL via groupware
- Username / Password
- How to change the Access Control password
- How to configure receiving OTP (one-time password)
- How to install and register the application
- How to configure unread notifications
Device Certificate (Device Certificate)
- Installing the device certificate and the login screen
- [Password Manager] User Help
- Procedure for deploying and starting the agent
- Destinations accessible using Mesh Network
- [Mesh Network] User Help
- Organizational operating rules
- Email DLP user screen URL
- HENNGE Email DLP User Console Guide
- Secure Transfer screen URL
- [Secure Transfer] User Help
- Force stop file sharing
- Notification emails to users
- Notification regarding the use of Tadrill Alert (reporting add-on) (for HENNGE One Pro subscribers only)
Access Control
Access Control User Portal URL
If you use SSO with multiple services, using the User Portal makes it convenient to access various services.
In the User Portal, links to services integrated with Access Control and URLs of frequently used pages can be displayed as links by the administrator.
About the feature of the Portal Site
The following operations are available on the Access Control User Portal screen.
※ Some items may not be displayed depending on the administrator's settings.
- How to change the login password on HENNGE Access Control ※ Only when end-user passwords are not synchronized from Active Directory
- OTP (one-time password) settings ([Access Control] Configuration for Receiving OTP (One-Time Password) via Connected Application / [Access Control] Configuration for Receiving OTP (One-Time Password) via Email)
- Registering Secure Browser
- How to deactivate the HENNGE Device Certificate of your own device?
The URL for logging in to the portal differs depending on the login screen you use.
- URL for the new design:https://ap.ssso.hdems.com/
-
URL for the old design:https://ap.ssso.hdems.com/portal/sampledomain.com/
※Please replace the sampledomain.com portion of the URL with your main domain.
Login URL via groupware
If you do not use the Access Control User Portal screen, please notify end users in advance of the URL for accessing groupware (such as Microsoft 365 and Google Workspace).
After implementing Access Control, when a user enters their username on the groupware login screen, they will be redirected to the Access Control screen, where Access Control user information is required.
Please refer to the following articles for examples of screen transitions.
- [Access Control] How to Log in to Microsoft 365 via Access Control
- [Access Control] How to Log in to Google Workspace via Access Control
By using the following URLs, you can also display the Access Control login screen directly without going through the groupware login screen.
Each URL includes the primary domain of your environment.
Replace the sampledomain.com portion of the URL with your primary domain.
-
Microsoft 365
https://portal.office.com/?domain_hint=sampledomain.com
-
Google Workspace
https://mail.google.com/a/sampledomain.com/ -
Other Web Services
For login URLs when using single sign-on (SSO) between other web services (such as Salesforce) and Access Control, please check the URL for each web service.
Username/Password
Please notify users in advance of the username and password required to log in to Access Control.
If passwords are synchronized from Active Directory and users know their passwords, notification is not required.
If user passwords have been registered directly in Access Control, they must be notified in advance.
How to Change the Access Control Password
If user passwords are not synchronized from Active Directory, each user must change their password in Access Control.
End users can access the screen to change their own password using either of the following methods.
-
Access from the Access Control User Portal screen
This method accesses the password change screen from the Access Control User Portal screen.
How to change the login password on HENNGE Access Control
-
Access the password change screen URL directly
This method directly accesses the screen for changing your own Access Control password.
The URL for the Access Control password change screen includes the primary domain of your environment.
Replace the sampledomain.com portion of the URL with your primary domain.https://ap.ssso.hdems.com/portal/sampledomain.com/password/
How to Configure Receiving OTP (One-Time Password)
If two-factor authentication using OTP (one-time passwords) is required as an access control rule, such as when accessing from outside the company, end users must configure in advance how they will receive OTPs (one-time passwords).
Specifically, users can receive them by email each time they log in through Access Control or through an OTP (one-time password) generator application.
- [Access Control] Configuration for Receiving OTP (One-Time Password) via Connected Application
- [Access Control] Configuration for Receiving OTP (One-Time Password) via Email
Secure Browser
How to Install and Register the Application
Secure Browser must be installed on end-user devices and registered for use in advance.
Please refer to the following detailed configuration pages for detailed setup procedures.
- [Secure Browser] Installing Secure Browser and Device Authentication (iOS)
- [Secure Browser] Installing Secure Browser and Device Authentication (Android)
How to Configure Unread Notifications
When you receive an email in the email system of the groupware you use (Microsoft 365 or Google Workspace), you can receive notifications from Secure Browser. (This feature is available only in the mobile version.)
Please refer to the following detailed configuration page for detailed setup procedures.
How to set Unread Email Notification on HENNGE Secure Browser
Device Certificate
Installing the Device Certificate
The device certificate must be installed on end-user devices in advance.
Please refer to the following article for detailed setup procedures.
How to Install HENNGE Device Certificate?
How to Log In Using a Device Certificate
When logging in to Access Control using a device certificate, you must explicitly select the option to log in with a device certificate on the login screen.
Please refer to the following article for examples of screen transitions.
Login operation using HENNGE Device Certificate
Password Manager
[Password Manager] User Help
End users need to be informed of how to operate each item on the user screen.
※ The items actually used vary depending on operational rules.
For detailed procedures, please refer to the following article.
[Password Manager] User Help
Mesh Network
Agent Installation and Startup Procedure
To implement Mesh Network, you need to install and log in to the agent on each client.
- Agent Installation Procedure
- Agent Startup and Login Procedure
Connection destinations accessible through Mesh Network
You need to provide information about internal systems that can be accessed through Mesh Network and how to connect to them.
Example:
・Information about the destination internal system (IP address or host name)
・Tools to use (browser, Explorer, etc.)
Mesh Network User Help
End users need to be informed of how to operate each item on the user screen.
※ The items actually used vary depending on operational rules.
For detailed procedures, please refer to the following article.
[Mesh Network] User Help
Email DLP
Organizational operational rules
End users need to be informed of the policy for preventing misdirected emails when using Email DLP.
Examples of operational rules to be communicated to end users are listed below.
- How to attach files (attach without converting to ZIP in advance, etc.)
- Hold time after sending (emails can be deleted within a certain period after sending)
- Conditions prohibited for external emails (emails cannot be sent if the subject, body, or attachment contains the phrase "Confidential", etc.)
-
How files attached to emails are delivered (sent via Secure Download, sent with ZIP encryption to specific recipients, etc.)
For detailed procedures, please refer to the following article.
[Email DLP] How to Download Files Sent with Secure Download
Email DLP user screen URL
When Email DLP temporarily holds emails sent externally by end users, you need to inform end users in advance of the URL for the screen used to cancel the sending of held emails and have them log in once before the filter is applied.
※ If an email sent by an end user who is not logged in is filtered, the history related to that email cannot be checked from the user screen.
The URL for the screen used to cancel the sending of held emails includes the main domain of your environment.
Please replace the sampledomain.com part of the URL with your main domain.
https://console.mo.hdems.com/#/sampledomain.com
Email DLP User Help
End users need to be informed of how to operate each item on the Email DLP user screen.
※ The items actually used vary depending on operational rules.
For detailed procedures, please refer to the following article.
HENNGE Email DLP User Console Guide
Email Archive
There are no items to communicate to end users.
Secure Transfer
Secure Transfer user screen URL
You need to inform end users in advance of the URL for accessing the Secure Transfer screen.
https://transfer.hennge.com/ (External link)
Secure Transfer User Help
End users need to be informed of how to operate each item on the Secure Transfer user screen.
※ The items actually used vary depending on operational rules.
For detailed procedures, please refer to the following article.
[Secure Transfer] User Help
File DLP
Forced suspension of file sharing
Inform users that sharing may be suspended if security risks in external sharing policies are detected.(Optional)
Tadrill
Notification of Tadrill Alert (reporting add-on) usage(HENNGE One Pro subscribers only)
Inform end users that Tadrill Alert (reporting add-on) will be distributed and provide guidance on how to use it.
- [Tadrill] How to Use Tadrill Alert to Report Suspicious Emails (Microsoft 365 Outlook for PC)
- [Tadrill] How to Use Tadrill Alert to Report Suspicious Emails (Microsoft 365 Outlook Mobile App)
- [Tadrill] How to Use Tadrill Alert to Report Suspicious Emails (Google Workspace Browser Version Gmail)
- [Tadrill] How to Report Suspicious Emails Using Tadrill Alert (Google Workspace Mobile Gmail)
Cloud Protection
Notification Emails to Users
Depending on the security policy settings, notifications are sent to users when a security risk is detected.
Inform users of the actions they should take upon receiving a notification. (Optional)
Translation Disclaimer
This article has been automatically translated from the original Japanese version for your convenience.
While we strive to ensure accuracy, we cannot guarantee its reliability or completeness.
In the event of any discrepancies or questions regarding the content, the official Japanese version shall prevail.