Chat now with support
Chat with Support

One Identity Safeguard for Privileged Passwords 6.0.9 LTS - Administration Guide

Introduction System requirements and versions Using API and PowerShell tools Using the virtual appliance and web management console Cloud deployment considerations Setting up Safeguard for Privileged Passwords for the first time Using the web client Getting started with the desktop client Using the desktop client Search box Privileged access requests Toolbox Accounts Account Groups Assets Asset Groups Discovery Entitlements Partitions Settings
Access Request settings Appliance settings Asset Management settings Backup and Retention settings Certificate settings Cluster settings External Integration settings Messaging settings Profile settings Safeguard Access settings
Users User Groups Disaster recovery and clusters Administrator permissions Preparing systems for management Troubleshooting Frequently asked questions Appendix A: Safeguard ports Appendix B: SPP 2.7 or later migration guidance Appendix C: SPP and SPS join guidance Appendix D: Regular Expressions SPP glossary

Asset Administrator permissions

An Asset Administrator manages all partitions, assets, and accounts:

  • Creates (or imports) assets and accounts.
  • Creates partitions and partition profiles.
  • Delegates partition ownership to users.

    NOTE: A delegated partition owner has a subset of permissions that an Asset Administrator has. That is, the delegated partition owner is authorized to manage a specific partition and the assets and accounts assigned to that partition.

  • Assigns assets to partitions.
  • Manages account password rules.

NOTE: Asset Administrators can only view the user object history for their own account.

Table 201: Asset Administrator: Permissions
Navigation Permissions

Dashboard | Account Automation

Full control for accounts related to all Safeguard for Privileged Passwords assets.

NOTE: Delegated partition owners have control for accounts related to the assets managed through delegated partition profile.

Activity Center

View and export asset activity events.

Administrative Tools | Toolbox

Access to the Accounts, Assets, Partitions and Users view.

Access to the Tasks pane.

Administrative Tools | Accounts

Add, modify, delete, and import accounts.

Check, change, and set account passwords.

Access password archive.

Enable or disable the access request services for an account.

Administrative Tools | Assets

Add, modify, delete, and import assets.

Configure and manage Asset Discovery jobs.

Download SSH Key.

Administrative Tools | Discovery

Create and run discovery jobs to find assets, accounts, and services in your network environment.

Administrative Tools | Partitions

Add, modify, and delete partitions and partition profiles.

Set partition as default.

Add assets to the scope of a partition profile.

Administrative Tools | Settings:

 

  • Asset Management | Custom Platforms

Add a custom platform that includes uploading the custom platform script.

  • Asset Management | Tags

Create and manage dynamic tags for assets and asset accounts.

  • Messaging | Message of the Day

Login notification: View only.

Set message of the day.

  • Profile | Account Password Rules

Add, modify, and delete account password complexity rules.

  • Profile | Change Password

Add, modify, and delete change password settings.

  • Profile | Check Password

Add, modify, and delete check password settings.

  • Profile | Password Sync Groups

Add, modify, and delete password sync groups.

Administrative Tools | Users

Delegate partition ownership to users.

Auditor permissions

The Auditor administrator has read-only access to all features, giving him the ability to review all access request activity:

  • Monitors appliance information.
  • Reviews everything.
  • Exports object history.
  • Runs entitlement reports.

On some pages, it may appear the administrator can edit data, but the change cannot be saved. A message like the following will display: Authorization is required for this request.

Table 202: Auditor administrator: Permissions
Navigation Permissions

Dashboard

View only.

Activity Center

View and export activity events.

Audit access request workflow.

Reports

View and export entitlement reports.

Administrative Tools | Toolbox

Access to all Administrative Tools views and the Tasks pane.

Administrative Tools | Accounts

View only.

Administrative Tools | Account Groups

View only.

Administrative Tools | Assets

View Asset Discovery jobs.

Administrative Tools | Asset Groups View only.

Administrative Tools | Entitlements

View only.

Administrative Tools | Partitions

View only.

Administrative Tools | Settings:

 

  • Access Request
View only.
  • Appliance

View Appliance Information.

Run diagnostics on appliance.

View licensing information.

View Lights Out Management (BMC) settings.

View Networking settings.

View Time settings.

View update history.

  • Asset Management

View only.

  • Backup and Retention
View only.
  • Certificates
View only.
  • Cluster
View only.
  • External Integration
View only.
  • Messaging

Login notification: View only.

Set message of the day.

  • Profile

View only.

  • Safeguard Access
View only.

Administrative Tools | Users

View only.

Administrative Tools | User Groups

View only.

Authorizer Administrator permissions

The Authorizer Administrator is the permissions administrator and performs the following:

  • Creates (or imports) Safeguard for Privileged Passwords users.
  • Grants administrator permissions to users.
  • Sets passwords, unlocks, and enables or disables both local and directory user accounts.
  • Creates and maintains the Password Rule.

IMPORTANT: Authorizer Administrators can change the permissions for their own account, which may affect their ability to grant permissions to other users. When you make changes to your own permissions, they take effect next time you log in.

NOTE: Also has User Administrator and Help Desk Administrator permissions.

Table 203: Authorizer Administrator: Permissions
Navigation Permissions

Activity Center

View and export user activity events, including authentication events.

Administrative Tools | Toolbox

Access to the Users and User Groups view.

Access to Tasks pane.

Administrative Tools | Settings

 
  • External Integration | Identity and Authentication
Add, update, and delete directories used for identity and authentication. External Federation and Radius providers can be configured for authentication use.
  • Messaging | Message of the Day

Login notification: View only.

Set message of the day.

  • Safeguard Access | Login Control

View only.

  • Safeguard Access | Password Rules
Configure user password rules.
  • Safeguard Access | Time Zone

View time zone.

Administrative Tools | Users

Add, modify, delete, and import users.

Set administrator permissions.

Set passwords and unlock users.

Delete users.

Enable or disable users.

Administration Tools | User Groups

Add or delete directory groups, if a directory has been added to Safeguard for Privileged Passwords.

Help Desk Administrator permissions

A Help Desk Administrator:

  • Sets passwords for non-administrative user accounts.
  • Unlocks accounts for all user accounts.

NOTE: Help Desk Administrators can only view the user object history for their own account.

Table 204: Help Desk Administrator: Permissions
Navigation Permissions
Activity Center View and export user activity events.

Administrative Tools | Toolbox

Access to the Users view and the Tasks pane.
Administrative Tools | Settings:  
  • Messaging | Message of the Day

Login notification: View only.

Set message of the day.

  • Safeguard Access | Login Control

View only.

  • Safeguard Access | Password Rules

View only.

  • Safeguard Access | Time Zone

View only.

Administrative Tools | Users

Unlock and set passwords for non-administrator users.

A Help Desk Administrator can unlock another Help Desk user but cannot set that user's password.

Related Documents

The document was helpful.

Select Rating

I easily found the information I needed.

Select Rating