Chat now with support
Chat mit Support

Password Manager 5.13.1 - Administration Guide

About Password Manager Getting Started Password Manager Architecture
Password Manager Components and Third-Party Solutions Typical Deployment Scenarios Password Manager in Perimeter Network Management Policy Overview Password Policy Overview Secure Password Extension Overview reCAPTCHA Overview User Enrollment Process Overview Questions and Answers Policy Overview Password Change and Reset Process Overview Data Replication Phone-Based Authentication Service Overview
Management Policies
Checklist: Configuring Password Manager Understanding Management Policies Configuring Access to the Administration Site Configuring Access to the Self-Service Site Configuring Access to the Helpdesk Site Configuring Questions and Answers Policy Workflow overview Custom workflows Custom Activities Self-Service Workflows Helpdesk Workflows Notification Activities User Enforcement Rules
General Settings
General Settings Overview Search and Logon Options Import/Export Configuration Settings Outgoing Mail Servers Diagnostic Logging Scheduled Tasks Web Interface Customization Instance Reinitialization Realm Instances Domain Connections Extensibility Features RADIUS Two-Factor Authentication Internal Feedback Password Manager components and third-party applications Unregistering users from Password Manager Bulk Force Password Reset Fido2 key management Working with Redistributable Secret Management account Email Templates
Upgrading Password Manager Administrative Templates Secure Password Extension Password Policies Enable S2FA for Administrators & Enable S2FA for HelpDesk Users Reporting Password Manager Integration Accounts Used in Password Manager Open Communication Ports for Password Manager Customization Options Overview Feature imparities between the legacy and the new Self-Service Sites Glossary

Forced Enrollment

This option is used to force users to enroll to Password Manager. If users do not create or update their Q&A profiles after a series of reminders, their accounts will be disabled. They will receive the notification either by email or through the Secure Password Extension (notification dialog box). The accounts can be enabled with a customized Enable Account workflow.

Disable account

To disable the user account after a series of reminders

  1. Connect to the Administration site by typing the Administration site URL in the address bar of your web browser. By default, the URL is http://<ComputerName>/PMAdmin/.

    NOTE: When prompted to log in, provide your domain user name in a domainname\username format.

  2. Select the Management Policy you want to modify.

  3. Expand the User Enforcement Rules section and click Remind Users to Create/Update Q&A Profiles.

  4. In the Apply the following notification scenarios to users from the rule’s scope section, click Add to add a new notification scenario, or click Edit to modify an existing notification scenario.

  5. In Configure Notification Scenario window, do the following:

  6. Select the User was invited to create/update Q&A profile N days ago option and enter the required number of days within which the users have to create or update their Q&A profiles.

  7. Select Disable user account.

  8. Select Notify users by email check box to configure email notification, or select Notify users via Secure Password Extension check box to configure notification by a dialog box and click Next.

    • If you have selected the Notify users by email check box, edit the notification template if necessary. Specify the following settings if required and click Next:

      • To define the default notification language, click the language link next to the Default language option and select the required language.

      • To specify the notification text in another language, click Add new language and select the required language. Notification templates in 16 languages are available out of the box (English, Chinese (Simplified), Chinese (Traditional), Danish, Dutch, French, German, Japanese, Korean, Portuguese (Brazil), Portuguese (Portugal), Russian, Spanish, Polish, Czech, Swedish).

    • If you have selected the Notify users via Secure Password Extension check box, configure the postpone options that will be available to users on the notification dialog box: select check boxes with required time intervals and click OK.

  9. Click Save.

Enable Account

You can enable the accounts disabled through forced enrollment, using a customized enable account workflow.

NOTE: The custom workflow must be executed only through Secure Password Extension or through mobile browsers. Because user login is restricted on workstation after disabling of the account.

To enable the account, use the following activities in the workflow:

  1. Authenticate with password or any 2FA procedure such as Radius.

    NOTE: In the activity settings, you must select Authenticate users with disabled accounts check box to unlock and re-enable the disabled user accounts.

  2. Edit Q&A profile

  3. Enable account.

    NOTE: In the activity settings, you must select Enable user accounts disabled by forced enrollment check box to unlock and re-enable the disabled user accounts disabled through forced enrollment. If you do not select the check box, all the disabled user accounts in the organization are enabled.

  4. If an error occurs, restart the workflow.

Remind Users to Change Password

By using this enforcement rule you can configure Password Manager to notify users about password expiration. If you configure this notification, users will be notified by email.

The notification schedule is defined by the Reminder to Change Password scheduled task. Note that notification starts only after this scheduled task has run. For more information on the scheduled tasks, see Scheduled Tasks.

NOTE: If you disable the Reminder to Change Password scheduled task, users will not be reminded of password expiration.

To enable the rule, on the Home page of the Administration site, expand the required enforcement rules section, click Remind Users to Change Password, and then click Enable.

To configure this enforcement rule, you must specify a user scope, conditions when an email notification should be sent and an email notification text.

To configure this reminder

  1. Connect to the Administration site by typing the Administration site URL in the address bar of your Web browser. By default, the URL is http://<ComputerName>/PMAdmin/.

    NOTE: When prompted to log in, provide your domain user name in a domainname\username format.

  2. Select the Management Policy you want to modify.

  3. Expand the User Enforcement Rules section and click Remind Users to Change Password.

  4. To set the user scope of this rule, click Configure under Configure the rule’s scope, specify the following settings and click Save:

    Table 8: Configure the scope of rule

    Option

    Description

    Users from the user scope of the Management Policy

    Select this option to include all users from the Management Policy user scope to the rule’s scope.

    The following users

    Select this option to specify groups included to and excluded from the rule’s scope.

    Users included both in the Management Policy user scope and the following groups

    Specify groups included in the rule’s scope.

    NOTE: Only users belonging both to the Management Policy user scope and the specified groups will be included in the rule’s scope. To browse for groups, click Add, select the required groups and click Save.

    Users excluded from the rule’s scope

    Specify groups excluded from the rule’s scope. To browse for groups, click Add, select the required groups and click Save.

  5. To specify the conditions under which users should be notified to change their passwords, click Configure under Notify users who meet the following condition, specify the number of days before password expiration and click OK.

  6. To edit the notification template, use a WYSIWYG editor in the Configure email notification section.

  7. To define the default notification language, click the language link next to the Default language option and select the required language.

  8. To specify the notification text in another language, click Add new language and select the required language. Notification templates in 17 languages are available out of the box (English, Chinese (Simplified), Chinese (Traditional), Danish, Dutch, French, German, Italian, Japanese, Korean, Portuguese (Brazil), Portuguese (Portugal), Russian, Spanish, Polish, Czech, Swedish). The language of the notification message corresponds to the language of a user’s Q&A profile. If the corresponding language is not available, the notification message is sent in the default language.

  9. Click Save.

IMPORTANT: To send email notifications to users, you must specify an outgoing mail server (SMTP server). For more information on how to configure the SMTP server, see Outgoing Mail Servers.

Verwandte Dokumente

The document was helpful.

Bewertung auswählen

I easily found the information I needed.

Bewertung auswählen