Chat now with support
Chat mit Support

Safeguard Privilege Manager for Windows 4.5 - Administration Guide

About this guide What is Safeguard Privilege Manager for Windows? Installing Safeguard Privilege Manager for Windows Configuring Client data collection Configuring Instant Elevation Configuring Self-Service Elevation Configuring Temporary Session Elevation Configuring privileged application discovery Deploying rules Removing local admin rights Reporting Client-side UI customization Using Microsoft tools Maintaining a least privileged use environment Database Planning Product Improvement Program

Using Validation Logic rules

The Validation Logic Rules sub-tab in the Create Rule Wizard allows you to set additional parameters to target the rule. You can define whether the rule will run on computers with a prefix in the name, a group or IP address range, or a user currently logged in. For example, you can target the rule to computers belonging to OUs that end with DEPARTMENT and are in subnet 192.168.0.X, except for the IP address 192.168.0.1.

NOTE: Client Deployment Settings can only be targeted to specific computers and not to user accounts or groups.

Setting rule parameters

To set rule parameters using the Validation Logic Rules sub-tab in the Create Rule Wizard

  1. Click Add to open the Add Validation Logic Rule window.

  2. Select the type of rule:

Type of Rule

Action

Computer Group

Set a rule for one or several names, or partial names, of your Active Directory computer groups. Enter the NetBIOS name, for example:

DERPA\DOMAIN CONTROLLERS

User Group

Set a rule for one or several names, or partial names, of your Active Directory user groups. The group membership value you enter will be compared against the groups that the user belongs to during the logon process and must match for the configuration to be processed. Enter the NetBIOS name, for example:

DERPA\ADMINISTRATORS

User Name

Set a rule if specific users are logged into client computers. Enter the NetBIOS name, for example:

DERPA\HELPDESK

OU (Computer)

Set a rule for names, or partial names, of computer-based OUs or the Computers container in your Active Directory. The OU value you enter will be compared against the OU the client computer belongs to during the logon process and must match for the configuration to be processed. Enter the fully qualified domain name (FQDN), for example:

DERPA.DERPADEV.LOCAL\DOMAIN CONTROLLERS

  • To select OUs, select the OU checkboxes.

  • To select all containers (instead of OUs), select the domain so that it is highlighted.

  • To include child objects, highlight the parent object and check Include child objects.

OU (User)

Set a rule for names or partial names of the user-based OUs or the Users container in your Active Directory. The OU value you enter will be compared against the OU the user belongs to during the logon process and must match for the configuration to be processed. Enter the FQDN, for example:

DERPA.DERPADEV.LOCAL\USER ACCOUNTS

  • To select OUs, select the OU checkboxes.

  • To select all containers (instead of OUs), select the domain so that it is highlighted.

  • To include child objects, highlight the parent object and check Include child objects.

Computer Name

Set a rule for computers with names or partial names. Enter the FQDN, for example:

DERPA.DERPADEV.LOCAL\PASERVER

IP Address Range (v4/v6)

Set a rule for IP addresses or ranges of computers.

Registry Key Exists

Set a rule based on the registry keys on client computers.

File Exists

Set a rule for files on the client computer or on the network. Specify a file that must exist on the client computer or on the network in order for the rule to run, for example:

\\ComputerName\SharedFolder\Filename.exe DriveLetter:\Filename.exe

NOTE: On the Type tab of the Create Rule Wizard, check the User’s context will be used to resolve system and resource access check box to ensure that the rule will apply.

Date and Time Range

Define when a rule should start and/or stop being enforced.

    Select the check boxes before the date and/or time fields in the Date Range / Time Range sections.

    In the Date Range and Time Range sections:

    1. Set the values.

    2. The rule will apply according to the time/date parameters of the Console used to create the rule.

User’s context will be used to resolve system and resource access to ensure that the rule will apply.

  1. Specify the rule's parameters in the dialog window that will display on the right:

    • Use the common asterisk (*) and question mark (?) wildcards in the validation value, as necessary.

      • * : Stands for no or any number of any characters

      • ? : Stands for a single character

    • Check the NOT check box to exclude the items specified from the rule.

    • For Computer Group, User Group, User Name, OU (Computer), OU (User), and Computer Name use one of the following options:

      • Use the Name field to specify the rule's value manually (see example values in the table above), and then click the button.

      • Use the Browse button to select the items available on your network. You can filter the items by the first letters. Wildcards are not supported in the Filter field.

      The desired value will be added to the list. You may add as many rule values as necessary.

  2. Click OK when you are finished specifying the settings within the rule type. The record will display in the main Validation Logic Rules list.

  3. To add another Validation Logic rule, repeat the steps above.

  4. Add or combine Validation Logic rules with AND or OR Boolean logic. By default, rules will combine with OR Boolean logic. To make the rule use the AND operator, select AND at the bottom of the Validation Logic Rules window.

  5. To edit a rule setting:

    1. Within the Validation Logic Rules list, double-click a rule value or click Edit.

    2. Make changes in the dialog.

  6. When finished specifying Validation Logic rules, click Next. If the Display Advanced Options check box has not been selected, complete the rule creation process.

Granting/denying privileges (Privilege Elevation Rules only)

On the Privileges tab in the Create Rule Wizard you can grant or deny privileges for a process, based on the standard Windows policies in the User Rights Assignment list (Local Security Settings\Local Policies).

To grant or deny privileges for processes (including child processes) using the Privileges tab in the Create Rule Wizard:

  1. Select the privilege and click Grant or Deny. To select multiple privileges, hold down the CTRL (or SHIFT) key while selecting the items.

  2. To discard your choices, select the privilege and click Not Set.

Differentiating security levels (Privilege Elevation Rules only)

You can differentiate the security levels with which a process will run using the Integrity tab in the Create Rule Wizard. The integrity level is a feature of Windows operating systems.

This parameter can be applied to clients running any of the following operating systems:

  • Windows Server 2012 or newer.

  • Windows 8.1 or newer.

By default, this setting will not apply and is set to the High integrity level.

Managing rules

Topics:

Once a rule is created, you can:

  • change its settings,

  • delete it,

  • import it, and

  • export it.

To delete, modify, or share a rule

  1. Use the applicable toolbar buttons.

To use the Edit Rule Wizard to configure a rule

  1. Select the Privilege Elevation Rules or Blacklist Rules tab based on the type of rule to be created.

  2. Double-click a rule's title or click Details on the toolbar to open the Edit Rule Wizard.

  3. Specify the data requested in each tab and click Next.

    1. Follow the prompts through the default tabs:

      • Description

      • Type

      • Groups

      • Validation Logic

        NOTE: This option is available only in Safeguard Privilege Manager for Windows Professional Edition and Professional Evaluation Edition.

      The Privileges and Integrity tabs display as advanced options.

    2. Enter the required fields, marked with an asterisk '*' on the Description and Type tabs.

  4. To save nd apply the rule, click Finish. If you did not specify the required data, the wizard notifies you.

  5. Click the Save button on the menu bar of the Rule section. Or, if prompted, confirm that you want to save the rule.

More information for managing rules:
  • To delete or modify a GPO created with Safeguard Privilege Manager for Windows, use the Microsoft Group Policy Management Console (GPMC). You can also edit rules using the GPMC. For more information, see Using the Group Policy Management Editor.

  • If you are using Safeguard Privilege Manager for Windows Community Edition and open a rule with a Professional Edition feature to view or modify its settings, you will receive a notification. To open the Edit Rule window to display all the rule settings except for the Professional ones, click Yes.

    NOTE: Modifying the rule will discard its Professional features.

Verwandte Dokumente

The document was helpful.

Bewertung auswählen

I easily found the information I needed.

Bewertung auswählen