Chatta subito con l'assistenza
Chat con il supporto

Password Manager 5.13.2 - Administration Guide

About Password Manager Getting started Password Manager architecture
Password Manager components and third-party applications Typical deployment scenarios Password Manager in a perimeter network Management Policy overview Password policy overview Secure Password Extension overview reCAPTCHA overview User enrollment process overview Questions and Answers policy overview Password change and reset process overview Data replication Phone-based authentication service overview
Management policies
Checklist: Configuring Password Manager Understanding Management Policies Configuring access to the Administration Site Configuring access to the Legacy Self-Service Site or Password Manager Self-Service Site Configuring access to the Helpdesk Site Configuring Questions and Answers policy Workflow overview Custom workflows Custom activities Legacy Self-Service or Password Manager Self-Service Site workflows Helpdesk workflows Notification activities User enforcement rules
General Settings
General Settings overview Search and logon options Importing and exporting configuration settings Outgoing mail servers Diagnostic logging Scheduled tasks Web Interface customization Instance reinitialization Realm Instances Domain Connections Extensibility features RADIUS Two-Factor Authentication Internal Feedback Password Manager components and third-party applications Unregistering users from Password Manager Bulk Force Password Reset Fido2 key management Working with Redistributable Secret Management account Email templates
Upgrading Password Manager Administrative Templates Secure Password Extension Password Policies Enable 2FA for administrators and helpdesk users Reporting Password Manager integration Accounts used in Password Manager Open communication ports for Password Manager Customization options overview Feature imparities between the legacy and the new Self-Service Sites Third-party contributions Glossary

Register

Use this workflow to select which registration methods to display on the User site.

Select registration mode allows the administrator to configure which registration methods are allowed for registration to the users. The following are the three methods available for the users to register:

  • Corporate authentication

  • Security questions

  • Personal contact method: Email and Mobile

The selected options is added in the Password Manager User site.

NOTE: When the administrator selects registration method(s), only the respective authentication methods are visible to the administrator in Authentication methods.

Select one of the radio buttons to set the method as mandatory registration method. The administrator can set a method mandatory from Select the registration method that must be set as the mandatory registration method for users in the User site. When the administrator selects a method as mandatory, it is compulsory for users for registration in the User site. To set as mandatory registration method for the users in the Password Manager User site, select one of the following options:

  • Corporate authentication

  • Security questions

  • Personal contact method: Email and Mobile

  • Allow user to choose

Configuring the country code drop-down menu

You can configure the options to add, remove, or modify the country code drop-down menu.

To modify the view of the drop-down menu to display the country name or the country code, navigate to the location where Password Manager is installed. Open the QPM.Service.Host.exe.config file. Add the required details in the <CountryConfig ShowWith="Attribute"> tag, where <"Attribute"> can be CountryName or CountryCode.

To add a new country code, provide the required details in the <add CountryName="<required country name>" CountryCode="<required country code>" ISDCode="<required ISD code>">.

Restart the Password Manager service to view the updates in the country code drop-down menu.

Manage My Profile

The Manage My Profile workflow allows the administrator to manage user profiles in Active Directory by using the Administration Site. Manage My Profile uses settings of Register workflow.

Use this workflow only if the user's Questions and Answers profile is pending for update.

To configure the Manage My Profile workflow

  1. Select Manage My Profile workflow in the Password Manager Administration Site.

  2. Click Settings.

  3. Select Run this activity only if user's profile should be updated check box.

NOTE: In case of an upgrade from 5.8.2 to 5.9.x, if the user is registered with Personal Contact Method (Mobile) in 5.8.2, then the user will be prompted to re-enter the country code as well as the mobile number, the very first-time (post-upgrade to 5.9.x) while trying to update the profile through the Manage My Profile workflow.

Forgot My Password

You can use this workflow to configure the Forgot My Password task for the Self-Service Site. The Forgot My Password task allows users to reset passwords for their accounts in Active Directory and in connected data sources (if integration with One Identity Quick Connect Sync Engine is configured) by using the Self-Service Site. For more information on using Quick Connect Sync Engine, see Reset Password in Active Directory and Connected Systems.

IMPORTANT: To display password policies on the Self-Service Site when users reset passwords, add the required domains on the Password Policies tab of the Administration Site. For more information see Creating and Configuring a Password Policy.

Depending on the selected registration methods in Register activity settings in Register workflow, authentication modes (corporate authentication, security questions, and personal contact method) is displayed in Authentication Mode activity settings in Forgot My Password workflow.

For example: if administrator has configured only Q&A as registration method, only Random and Specific authentication modes display in Authentication Mode activity settings.

The default configuration of this workflow is the following:

  1. Authentication Methods.

  2. Lock Q&A profile.

  3. Reset password in Active Directory.

  4. Restart workflow if error occurs.

  5. Email user if workflow succeeds.

  6. Email user if workflow fails.

Related Documents

The document was helpful.

Seleziona valutazione

I easily found the information I needed.

Seleziona valutazione