Tchater maintenant avec le support
Tchattez avec un ingénieur du support

One Identity Safeguard for Privileged Passwords 2.11 - Administration Guide

Introduction System requirements Using the virtual appliance and web management console Using the cloud Setting up Safeguard for Privileged Passwords for the first time Search box Using the web client Installing the desktop client Using the desktop client Privileged access requests Toolbox Accounts Account Groups Assets Asset Groups Discovery Entitlements Partitions Settings
Access Request settings Appliance settings Asset Management settings Backup and Retention settings Certificate settings Cluster settings External Integration settings Messaging settings Profile settings Safeguard Access settings Sessions settings
Users User Groups Disaster recovery and clusters Administrator permissions Preparing systems for management Troubleshooting Frequently asked questions Appendix A: Safeguard ports Appendix B: SPP 2.7 or later migration guidance Appendix C: SPP and SPS join guidance Appendix D: Regular Expressions Appendix E: Historical changes by release Glossary

Access Request settings

Use the Access Request settings to enable (or disable) access request and password management services and to define global reason codes that can be used when creating access request policies.

Navigate to Administrative Tools | Settings | Access Request.

Table 103: Access Request settings
Setting Description

Enable or Disable Services (Access and management services)

Toggle on

Toggle off

Where you enable or disable the following Safeguard for Privileged Passwords services:

  • Session requests
  • Password requests
  • Check password management
  • Change password management
Reasons

Where you configure access request reason codes, which can then be used when creating access request policies.

Enable or Disable Services

One Identity Safeguard for Privileged Passwords allows you to enable or disable access request and password management services. These settings control session and password release requests, manual account

password validation, and reset tasks, as well as the automatic profile check and change tasks in Partitions.

All services are enabled by default. The toggles appear blue with the switch to the right when a service is enabled, and gray with the switch to the left when a service is disabled.

These global settings are enabled by default. By default, these services are disabled for service accounts and for accounts and assets found as part of a discovery job.

Service accounts can be modified to adhere to these schedules and discovered accounts can be activated when managed.

It is the responsibility of the Appliance Administrator to manage the access request and password key management services.

Navigate to Administrative Tools | Settings | Access Request | Enable or Disable Services.

Table 104: Enable or Disable Services settings
Setting Description

Requests

Toggle on or Toggle off

Session Requests Enabled

Session requests are enabled by default, indicating that authorized users can make session access requests. There is a limit of 1,000 sessions on a single access request.

Click the Session Requests Enabled toggle to disable this service so sessions can not be requested.

NOTE: When Session Requests is disabled, no new session access requests can be initiated. Depending on the access request policies that control the target asset/account, you will see a message informing you that the Session Request feature is not available.

In addition, current session access requests cannot be launched. A message appears, informing you that Session Requests is not available. For example, you may see the following message: This feature is temporarily disabled. See your appliance administrator for details.

Password Requests Enabled

Password requests are enabled by default, indicating that authorized users can make password release requests

Click the Password Requests Enabled toggle to disable this service so passwords can not be requested.

NOTE: Disabling the password request service will place any open requests on hold until this service is reenabled.

Password Management

Toggle on or Toggle off

Check Password Management Enabled

Check password management is enabled by default, indicating that Safeguard for Privileged Passwords automatically performs the password check task if the profile is scheduled, and allows you to manually check an account's password.

Click the Check Password Management Enabled toggle to disable the password validation service.

Note: Safeguard for Privileged Passwords enables automatic password management services by default. Typically, you would only disable them during an organization-wide maintenance window.

When disabling a password management service, Safeguard for Privileged Passwords allows all currently running tasks to complete; however, no new tasks will be allowed to start.

Change Password Management Enabled

Change password management is enabled by default, indicating that Safeguard for Privileged Passwords automatically performs the password change task if the profile is scheduled, and allows you to manually reset an account's password.

Click the Change Password Management Enabled toggle to disable the password reset service.

Note: Safeguard for Privileged Passwords enables automatic password management services by default. Typically, you would only disable them during an organization-wide maintenance window.

When disabling a password management service, Safeguard for Privileged Passwords allows all currently running tasks to complete; however, no new tasks will be allowed to start.

Sessions Module

Toggle on or Toggle off

Session Module Password Access Enabled

Session module password access is disabled by default. When the toggle is on, Safeguard for Privileged Passwords (SPP) can create an access request and check out a password from Safeguard for Privileged Sessions (SPS) on behalf of another user. When the toggle is switched off, this ability is revoked. This functionality supports Safeguard for Privileged Sessions (SPS) version 6.2.0 or later. For more information, see the One Identity Safeguard for Privileged Sessions Administration Guide: One Identity Safeguard for Privileged Sessions - Technical Documentation.

 

Reasons

In an access request policy, a Security Policy Administrator can require that a requester provide a reason for requesting access to a password or session. Then, when requesting access, the user can select a predefined reason from a list. For example, you might use these access request reasons:

  • Software Updates
  • System Maintenance
  • Hardware Issues
  • Problem Ticket

To configure access request reasons

  1. Navigate to Administrative Tools | Settings | Access Request | Reasons.
  2. Click Add Reason to add a new reason.
  3. In the Reason dialog, enter the following:
    1. Name: Enter a name for the reason.

      Limit: 50 characters

      Required

    2. Description: Enter a description for the reason.

      Limit: 255 characters

      Required

  4. Click Add Reason.
  5. To edit a reason, click Edit Reason.

    The Reason dialog appears allowing you to modify the name or description.

  6. To delete a reason, click Delete Reason.

    In the confirmation dialog, click Yes.

Related Topics

Creating an access request policy

Appliance settings

Use the Appliance settings to view general information about the appliance, run diagnostic tools, and reset or update the One Identity Safeguard for Privileged Passwords hardware appliance.

Safeguard for Privileged Passwords can be set up to use a virtual appliance. For more information, see Using the virtual appliance and web management console.

Navigate to Administrative Tools | Settings | Appliance.

One Identity Safeguard for Privileged Passwords provides the following information to help you resolve many common problems you may encounter as you deploy and use your appliance.

Table 105: Appliance settings
Setting Description

Appliance Diagnostics

Where you execute a trusted, secure diagnostics package to help solve a configuration issue, synchronization issue, clustering issue, or other internal issues.

Appliance Information

Where you view general information about the appliance, as well as its performance utilization and the memory usage. This page also contains power controls to shut down or restart your appliance.

Network Diagnostics

Where you run diagnostic tests on your appliance.

Enable or Disable Services

Where you enable or disable the Application to Application functionality.

Factory Reset from the desktop client

Where you perform a factory reset to revert your appliance to its original state when it first came from the factory.

Licensing

Where you add or update a Safeguard for Privileged Passwords license.

Lights Out Management (BMC)

Where you enable and disable lights out management, which allows you to remotely manage the power state and serial console to Safeguard for Privileged Passwords using the baseboard management controller (BMC).

Networking

Where you view and configure the primary network interface, and if applicable, the sessions network interface.

Operating system licensing

Where you configure the operating system for the virtual appliance.

Support bundle

Where you create a support bundle containing system and configuration information to send to One Identity Support to analyze and diagnose issues with your appliance.

If you have the embedded sessions licensed, this is where you enable (and disable) session debug logging to be included in a support bundle.

Time

Where you enable Network Time Protocol (NTP) and set the primary and secondary NTP servers.

NOTE: A replica in the cluster will always reference the primary appliance as its NTP server.

Updates

Where you upload and install an update file. For more information, see Updates.

In addition to the appliance options, One Identity Safeguard for Privileged Passwords provides these troubleshooting tools:

Table 106: Additional troubleshooting tools
Tool Description

Activity Center

View the details of specific events or user activity. For more information, see Activity Center.

LCD status messages

An LCD screen on the appliance to view the status of the appliance as it is starting up or shutting down. For more information, see LCD status messages.

Recovery Kiosk (Serial Kiosk)

A terminal or laptop connected directly to the appliance to view basic appliance information, restart the appliance remotely, shut down the appliance, reset the bootstrap administrator’s password to its initial value, perform a factory rest, or to generate and send a support bundle to a Windows share. For more information, see Recovery Kiosk (Serial Kiosk).
Documents connexes