You can delete an asset group. When you delete an asset group, Safeguard for Privileged Passwords does not delete the associated assets.
To delete an asset group
- Navigate to Administrative Tools | Asset Groups.
- In Asset Groups, select an asset group from the object list.
- Click Delete Selected.
- Confirm your request.
Safeguard for Privileged Passwords discovery jobs can find assets, accounts, and services in your network environment. This can simplify initial deployment and ongoing maintenance of the privileged accounts in your network environment.
Details on the jobs follow.
-
Asset Discovery jobs find assets by searching directory assets, such as Active Directory, or by scanning network IP ranges. Rules control which assets are found. Asset Discovery jobs can be scheduled to run on regular intervals. The discovery job can be configured with templates to set default settings on newly created assets including connection details. The assets created by discovery jobs are considered to be managed by Safeguard, but this has no effect on the network asset. An asset with valid connection information can be used for account discovery.
If you use asset discovery Method of Directory, directory assets that are shared can be discovered into any partition. To share a directory asset, select Available for discovery across all partitions for the asset; see Management tab (add asset).
-
Account Discovery: Account Discovery jobs find accounts by searching directory assets such as Active Directory or by scanning local account databases on Windows and Unix assets (/etc/passwd) that are associated with the account discovery job. Rules control which accounts are found. Account discovery jobs can be scheduled to run on regular intervals. The discovery job can be configured to set default settings on newly created accounts. Accounts found by account discovery are neither managed nor disabled until you decide to manage them or disable them. If an account is managed by Safeguard, this means the password can be managed according to the partition profile settings associated with the discovery job. Safeguard can make the account available for password and/or session requests according to configured entitlements and policy.
The accounts in the scope of the discovery job may include accounts that were previously added (manually) to the Safeguard partition. For more information, see Adding an account.
- Service Discovery: Service Discovery jobs find Windows services that run as accounts managed by Safeguard. If Safeguard is managing the service account password, Safeguard can update the Windows service configuration to match the password when the password changes and restart the service automatically.
Discovery tiles include the following:
- Asset Discovery: The number of Asset Discovery jobs available to run against the directories or networks to discover assets for potential management displays. Click the tile for detail.
- Asset Discovery Results: The number of Asset Discovery Results in the time frame indicated displays. Click the tile for detail.
- Account Discovery: The number of Account Discovery jobs available to run against the in scope assets to discover accounts for potential management displays. Click the tile for detail.
- Account Discovery Results: The number of Account Discovery Results in the time frame indicated displays. Click the tile for detail.
- Discovered Accounts: The number of discovered accounts in the specified partition displays. Click the tile for detail.
- Discovered Services: The number of discovered services in the specified partition displays. Click the tile for detail. You can launch discover service account jobs from Administrative Tools | Assets | Discovered Services. For more information, see Discovered Services tab (asset).
You can schedule one or more Asset Discovery jobs to run automatically against the directories or network (IP range) you have added to Safeguard for Privileged Passwords. The assets in the scope of the discovery job may include assets that were previously added (manually) to the Safeguard partition. For more information, see Adding an asset.
If you use asset discovery Method of Directory, directory assets that are shared can be discovered into any partition. To share a directory asset, select Available for discovery across all partitions for the asset; see Management tab (add asset).
When an Asset Discovery job runs, the found asset is added to Assets. If the operating system cannot be detected in the Network Scan or Directory method of asset discovery, the Other Linux operating system is applied which you can modify later. For more information, see Modifying an asset.
For more information, see Asset Discovery job workflow.
Properties and toolbar
Navigate to Administrative Tools | Discovery | Asset Discovery.
Use these toolbar buttons to manage the discovery job settings.
Table 68: Asset Discovery: Toolbar
Add |
Add an Asset Discovery job. For more information, see Adding an Asset Discovery job. |
Delete Selected |
Delete the selected Asset Discovery job. |
Refresh |
Update the list of Asset Discovery jobs that have run. |
Edit |
Modify the selected Asset Discovery job. You can also double-click a row to open the edit dialog. |
Run Now |
Run the selected Asset Discovery job. A Task pop-up display which shows the progress and completion. |
Details |
View additional details about the selected Asset Discovery job including schedule frequency and rules. |
Search |
Enter the character string to be used to search for a match. For more information, see Search box. |
Asset Discovery jobs display in the grid.
Table 69: Asset Discovery: Asset Discovery job grid
Name |
Name of the discovery job |
Creator |
Indicates how the job was launched, for example, Automated System or Admin |
Method |
The type of job, for example, Windows, Unix, or Directory |
Directory |
The directory on which the discovery job runs |
Partition |
The partition in which to manage the discovered assets or assets |
Schedule |
Designates when the Asset Discovery job runs |
Last Run Date |
The date the selected Asset Discovery job ran |
Next Run Date |
The date when the Asset Discovery job is scheduled to run next |
Last Success Run Date |
The most recent date the selected Asset Discovery job successfully ran |
Last Failure Run Date |
The most recent date the selected Asset Discovery job failed |
You can configure, schedule, test, and run Asset Discovery jobs. After the job has run, you can select whether to manage the asset. You can also view information about the Asset Discovery jobs that have run.
- Create an Asset Discovery job. For more information, see Adding an Asset Discovery job.
- After you save the Asset Discovery job, you can test it by selecting Run Now. For more information, see Asset Discovery.
- After the Asset Discovery job runs, click the Asset Discovery Results tile to view the assets found. For more information, see Asset Discovery Results.
-
To control management of an asset, navigate to Administrative Tools | Assets, right-click the asset, click Enable-Disable, and choose one of these context menu options.
- On Administrative Tools | Assets, you can show or hide assets marked as disabled, use the following buttons. For more information, see Assets.
Show Disabled |
Display the disabled assets. |
Hide Disabled |
Hide assets marked as disabled. |
- Search the Activity Center for information about discovery jobs that have run. Safeguard for Privileged Passwords lists the Asset Discovery events in the Asset Discovery Activity category.