지금 지원 담당자와 채팅
지원 담당자와 채팅

Safeguard Privilege Manager for Windows 4.7 - Administration Guide

TitlePageProxy Copyright Table of Contents About this guide What is Safeguard Privilege Manager for Windows? Installing Safeguard Privilege Manager for Windows Configuring Client data collection Configuring Instant Elevation Configuring Self-Service Elevation Configuring Temporary Session Elevation Configuring privileged application discovery Deploying rules Removing local admin rights Reporting Client-side UI customization Using Microsoft tools Maintaining a least privileged use environment Database Planning Product Improvement Program About us

Using the Resultant Set of Policy Wizard

The Resultant Set of Policy (RSoP) Wizard is a built-in MMC snap-in. It helps you view policy settings applied to selected computers and users (in logging mode), or simulate a policy implementation to plan changes to your network (in planning mode). You have to enable .NET Framework 3.5 with the Turn Windows features on or off dialog or the PM Console installed in order to view the values of the RSoP Wizard.

NOTE: You might have to restart your computer after enabling .NET Framework 3.5.

To use the Resultant Set of Policy Wizard to report on policies you have applied

  1. Install the Client on the computer for which you are viewing or simulating a policy.

  2. Open the MMC. On the Start menu, click Run, type MMC, and then click OK.

  3. From the File menu, select Add/Remove Snap-in. The Add or Remove Snap-ins dialog appears.

    1. Select Resultant Set of Policy under the list of snap-ins.

    2. Click Add.

    3. Click OK.

  4. The Console Root window now has a snap-in, Resultant Set of Policy, rooted at the Console Root folder.

  5. Under the Name column, click Resultant Set of Policy.

  6. Complete one of the following steps:

    1. Right-click Resultant Set of Policy and select Generate RSoP Data.

    2. Under the Resultant Set of Policy pane in the Actions column, click More Actions and select Generate RSoP Data.

      The Resultant Set of Policy Wizard appears.

  7. Complete the following steps:

    1. Choose the Logging mode to review policy settings or the Planning mode to simulate a policy implementation.

    2. Specify the data requested in each tab and click Next.

    3. Click Finish to quit the wizard.

      The Console Root window now has Privilege Manager for Windows nodes, rooted at the Console Root folder under Computer Configuration and User Configuration. Privilege Manager for Windows Details appears on the right, showing the rules and advanced policy settings that are applied.

Client-side UI customization

Detailed information about this topic

Safeguard Privilege Manager for Windows supports the text customization of all user-facing dialogs on client computers. In addition to the ability to change the default English dialog text, admins can also create client-side UI customization files for any non-English client language locale.

Language translation files

To customize the language used in the client-side UI, one or more translation files must be located in the same folder where the client files are installed, by default: C:\Program Files (x86)\Common Files\One Identity\Safeguard Privilege Manager for Windows\Client.

A language-specific translation file must be named as follows: <two_letter_language_code>-pmlang.ini

Example:
  • Spanish translation language file name: es-pmlang.ini

  • English translation language file name: en-pmlang.ini (used to customize client computers with English locale)

  • French translation language file name: fr-pmlang.ini

NOTE: The en-pmlang.ini file is used. For information on language translation files currently available for download, as well as configuration and troubleshooting tips, see Knowledge Base Article Safeguard Privilege Manager for Windows User Interface Language Translation (4228235).

Safeguard Privilege Manager for Windows automatically searches for the language translation file corresponding to the language local setting on a client computer. If no translation file is found, default English client-side text strings are used.

A specific language translation file can be used regardless of the Window's local settings with the use of a registry setting.

  • Hive: HKCU\Software\Scriptlogic Corporation\Privilege Authority

  • Key: Preferred Language

  • Type: REG_SZ

  • Value: name of language file, for example, es-pmlang.ini

    The corresponding translation file must exist as described above.

In addition to checking locally on the client computer for language translation files, the Safeguard Privilege Manager for Windows Client automatically copies (and overwrites older, already existing) language files found on the NETLOGON share.

NOTE: NETLOGON is checked for updated language files every time a user logs on to a computer.

Additionally, Administrators can configure the Safeguard Privilege Manager for Windows Client to check an alternate location for updated language translation files. This can be done by updating the TranslationFilesFolder value in HKLM\Software\Scriptlogic Corporation\Privilege Authority.

Using Microsoft tools

You can use Microsoft tools with Safeguard Privilege Manager for Windows to:

관련 문서

The document was helpful.

평가 결과 선택

I easily found the information I needed.

평가 결과 선택