지금 지원 담당자와 채팅
지원 담당자와 채팅

One Identity Safeguard for Privileged Passwords 7.2 - Administration Guide

Introduction System requirements and versions Using API and PowerShell tools Using the virtual appliance and web management console Cloud deployment considerations Setting up Safeguard for Privileged Passwords for the first time Using the web client Home Privileged access requests Appliance Management
Appliance Backup and Retention Certificates Cluster Enable or Disable Services External Integration Real-Time Reports Safeguard Access Appliance Management Settings
Asset Management
Account Automation Accounts Assets Partitions Discovery Profiles Tags Registered Connectors Custom platforms
Security Policy Management
Access Request Activity Account Groups Application to Application Cloud Assistant Asset Groups Entitlements Linked Accounts User Groups Security Policy Settings
User Management Reports Disaster recovery and clusters Administrator permissions Preparing systems for management Troubleshooting Frequently asked questions Appendix A: Safeguard ports Appendix B: SPP and SPS join guidance Appendix C: Regular Expressions About us

Adding authorized user for Cloud Assistant

Once Safeguard for Privileged Passwords is joined to Starling, use the Cloud Assistant page to add the Safeguard for Privileged Passwords users that can use the Cloud Assistant feature to approve access requests.

To add users who are authorized to use Cloud Assistant

IMPORTANT: The user information configured in Safeguard for Privileged Passwords must match the user information in the Starling Cloud Assistant channel. If the user information does not match, you will need to remove the user from both Security Policy Management > Cloud Assistant and Starling Cloud Assistant's Recipients page, then re-add the user to Safeguard for Privileged Passwords using the correct user information.

  1. Log in to the Safeguard for Privileged Passwords client as a Security Policy Administrator.
  2. To go to Cloud Assistant:
    • web client: Security Policy Management > Cloud Assistant.
  3. Click Add.
  4. In the Users dialog, select users from the list and click OK.

  5. Add these Cloud Assistant users as approvers in the appropriate access request policy. For more information, see Creating an access request policy.

Once a user is added as a Cloud Assistant user and as an approver in an access request policy, when an access request requires approval, Safeguard for Privileged Passwords sends a notification to the approver's configured channel (this is configured via the Starling Cloud Assistant service). The approver can either approve or deny the access request directly from the channel.

NOTE: Revoking an access request that has already been approved is not available via the channel. You must use the Safeguard for Privileged Passwords web client to perform that action.

Asset Groups

A Safeguard for Privileged Passwords asset group is a set of assets that you can add to the scope of an access request policy. For more information, see Creating an access request policy.

Only the assets that support session management can be added to asset groups and dynamic asset groups. Assets that do not support session management include but may not be limited to Directory assets. When you create the asset, the Management tab has an Enable Session Request check box if sessions is supported. For more information, see Supported platforms. This section lists SPP and SPS support by platform.

The Auditor and the Security Policy Administrator have permission to access Asset Groups.

To access Asset Groups:

  • web client: Navigate to Security Policy Management > Asset Groups.

The Asset Groups view displays the following information about the selected asset group.

Use these toolbar buttons to manage asset groups.

Properties tab (asset group)

The Properties tab lists information about the selected asset group.

To access Properties:

  • web client: Navigate to Security Policy Management > Asset Groups > (View Details) > Properties.
Table 184: Asset Groups Properties tab: General properties
Property Description
Name

The selected asset group's name

Description

Information about the selected asset group

Asset Rules

For dynamic asset groups, a summary of the asset rules defined. On the web client, this information is available on the Asset Rules tab.

Assets tab (asset group)

The Assets tab displays the assets associated with the selected asset group.

To access Assets:

  • web client: Navigate to Security Policy Management > Asset Groups > (View Details) > Assets.

Click Add Asset from the details toolbar to add one or more assets to the selected asset group.

Search: For more information, see Search box.

Table 185: Asset Groups: Assets tab properties
Property Description
Name

The asset name assigned to the managed system.

Platform

The platform of the managed system.
Session Request A check in this column indicates that session access requests are enabled for the asset.

Disabled

A check in this column indicates that the asset is not managed, is disabled, and has no associated accounts.

Description

Information about the asset.

Use these buttons on the details toolbar.

Table 186: Asset Groups: Assets tab toolbar
Option Description
Add Asset

To add one or more assets to the asset group you selected.

Remove

Remove the selected asset.

Export

Use this button to export the listed data as either a JSON or CSV file. For more information, see Exporting data.

Refresh Update the list of assets.
Search

To locate a specific asset in this list, enter the character string to be used to search for a match. For more information, see Search box.

관련 문서

The document was helpful.

평가 결과 선택

I easily found the information I needed.

평가 결과 선택