One Identity Safeguard for Privileged Passwords can manage cloud platform accounts such as Amazon Web Services (AWS), Facebook (deprecated), and Twitter (deprecated).
Before you add cloud platform accounts to Safeguard for Privileged Passwords, you must first add an asset with which to associate the accounts. For more information, see Prepare Amazon Web Services platforms.
To add a cloud platform to Safeguard for Privileged Passwords
- log in to Safeguard for Privileged Passwords and navigate to Administrative Tools.
- In Assets, click Add Asset from the toolbar.
- In the General tab:
- Name: Enter an asset name that is meaningful to you, such as "Cloud Account Server" which you can use to manage all cloud platform accounts.
- (Optional) Description: Enter a description for the asset.
- Partition: Select the partition you want Safeguard for Privileged Passwords to use to manage the cloud platform account passwords.
- Profile: Select the profile you want Safeguard for Privileged Passwords to use to manage the cloud platform account passwords.
-
In the Management tab:
- Product: Select the appropriate product, such as Amazon Web Services.
- Version: For Amazon Web Services, select the version.
- Network Address: For Amazon Web Services, enter the AWS Account ID or Alias which can be found on the AWS IAM User's view.
-
For Amazon Web Services, in the Connection tab, select:
-
Access Key to authenticate to the asset using an access key. Enter the following information:
- Service Account Name: Enter the configured IAM service account.
- Access Key ID: Enter the Access Key ID created for the IAM service account.
- Secret Key: Enter the Secret Key created for the IAM service account.
-OR-
- None to not authenticate to the asset and manually manage the asset.
-
Once you add the cloud platform asset, you can associate accounts with it.
To add an account to the cloud platform
- In Assets, select the cloud platform asset and switch to the Accounts tab.
- Click Add Account from the details toolbar.
- In the User Name field, enter the cloud platform account username, email address, or phone number.
- In the Password field, enter the account password for the user name you provided.
- Click Test Connection to verify that Safeguard for Privileged Passwords can communicate with this cloud platform using the credentials that you have provided.
- (Optional) Enter a Description.
- Browse to select a profile to govern this account
- Ensure the Enable Password Request option is checked and click Add Account.
Now you can manually check, change, or set the cloud platform account password; and, Safeguard for Privileged Passwords can automatically manage the password according to the Check and Change settings in the profile governing the account.
To check out the cloud platform account
- Add a cloud platform Account Group and add the accounts to the group.
- Add an entitlement for the cloud platform accounts.
- Add users to the entitlements.
- Add a password release policy to the entitlement.
- Add the cloud platform Account Group to the scope of the policy.