Identity Manager 8.1 - Installation Guide

About this Guide One Identity Manager overview Installation prerequisites Installing One Identity Manager Installing and configuring the One Identity Manager Service Automatic updating of One Identity Manager Updating One Identity Manager Installing and updating an application server Installing the API Server Installing, configuring and maintaining the Web Portal Installing and updating the Manager web application Logging in to One Identity Manager tools Error handling Appendix: Creating a One Identity Manager database for a test or development environment from a database backup Appendix: Extended configuration of the Manager web application Appendix: Machine roles and installation packages Appendix: Settings for a new SQL Server database

One Identity Manager tools

Different tools are provided for different tasks. For example, the tool used to configure One Identity Manager differs from the tool used to manage employee data. The contents to be displayed and the extent to which it can be altered is determined in conjunction with the access rights of the respective user through the object layer.

Table 2: Overview of One Identity Manager tools
Tool Short description

Launchpad

Launchpad is the central tool for starting One Identity Manager administration tools and configuration tools. You can use Launchpad to check the existing One Identity Manager installation and start One Identity Manager tools to execute individual tasks.

The Launchpad can be customized. You can define your own menu items and action for the Launchpad in the Designer.

Web Portal

The Web Portal is a web-based application for all One Identity Manager users. The Web Portal provides the stringent workflows in the following areas:

  • Change employee master data and own password
  • Edit or enter employee master data for subordinate staff.
  • Search, request, cancel or renew products in the IT Shop.
  • Delegate user-specific roles.
  • Edit assigned approvals, attestation cases and rule violations.

In the info system, you see several evaluations, for example, about your own requests and attestation cases, employee numbers, approvals, rule violations, or the Unified Namespace.

The Web Portal requires a web server. Via a web browser, users can access the website that has been dynamically set up and customized for them. Once the web server has been configured and a web project in Web Designer has been shared, you can start the Web Portal in your own web browser.

Password Reset Portal

The Password Reset Portal allows users to reset passwords of the user accounts they manage securely.

To utilize the Password Reset Portal, it must be installed as a dedicated web application. The necessary security is guaranteed by multi-factor authentication.

Operations Support Web Portal

The Operations Support Web Portal was created with help desk employees in mind, who need support when executing tasks and process steps. You can use the Operations Support Web Portal to monitor the handling of processes and DBQueue tasks. You can also create access codes for your colleagues.

Before you can use the Password Reset Portal, you must install an API Server.

Manager

Manager is the main administration tool for setting up information about employees and their identities. It displays and maintains all the data required for the administration of employees, their user accounts, permissions, and company-specific roles in a One Identity Manager network. Company resources employees require can be entered and assigned to them.

You can also use Manager to

  • Define custom IT policies
  • Set up an IT Shop from which company resources and assignments can be requested
  • Set up special approval processes for authorizing requests and checking compliance to IT policy
  • Set up attestation procedures for regularly testing the correctness of data about employees or roles and their assignments

By implementing One Identity Manager application roles, every One Identity Manager user obtains only those access permissions they require to fulfill necessary administrative duties.

Manager functionality can be provided by web applications.

Synchronization Editor

You use the One Identity Manager to connect different target systems to Synchronization Editor. Use this tool to configure data synchronization for any target system and specify which target system data is mapped to the One Identity Manager database. You also define the object properties mapping and the synchronization sequence as a workflow.

Analyzer

Use the Analyzer to automatically detect and analyze data correlations in the database. This information can be used to replace, for example, direct permissions assignments with indirect assignments, therefore reducing the administration effort.

Job Queue Info

Job Queue Info helps you to check the current status of the services running in a One Identity Manager network. It displays, in a detailed and comprehensive manner, the tasks in the job queue and the different One Identity Manager Service requests on the servers. The tool provides on-the-fly status information and makes fast error detection possible.

Configuration Wizard

The Configuration Wizard is used to set up the database on a SQL Server for use in a One Identity Manager network. All the One Identity Manager schema tables, data types and database procedures are loaded into the database with the Configuration Wizard. The SQL Server logins and database users with permissions for the One Identity Manager schema are created.

Automatic version control is integrated into the One Identity Manager, ensuring that One Identity Manager components are always consistent with each other and with the database. If program updates are implemented that change the structure (for example, table extensions), database migration is then necessary. The Configuration Wizard executes this schema installation depending on the current status of the schema.

Designer

The Designer is the main tool for configuring the One Identity Manager. The program offers an overview of the entire One Identity Manager data model. It enables the configuration of global system settings, for example, language or configuration parameters, as well as customizing the user interface for the various administration tools. The rights structure for different administrative tasks of individual users and user groups is also set up with the Designer. Another important task is the definition of workflows for technically illustrating the administration procedures in a company. The Designer provides various editors for the One Identity Manager system configuration. The range of functions and the operating methods of the editors are tailored to the differing configuration requirements.

Web Designer

The Web Designer is used to configure and extend the Web Portal. It includes functions for adapting the Web Portal workflows and developing new workflows.

Data Import

With the Data Import program, the One Identity Manager offers a simple means of importing data from other systems. Use this program if you want to import company resource data from external sources into your database. The program supports importing from files and importing directly from other database systems. You can import data immediately. You also have the option to import data from customized processes using the import scripts that are created. The import definition is saved so that you can use it for future data imports.

Crypto Configuration

In certain circumstances it is necessary store encrypted information in the database. Encryption is carried out using the Crypto Configuration program. This program creates a code file and converts the contents of the affected database column. The coded information is stored in the database.

Database Compiler

The One Identity Manager database must be compiled after changes to configuration data. After a migration package or full custom configuration package is imported, compiling the database is started immediately from the Configuration Wizard or Database Transporter.

The Database Compiler compiles the One Identity Manager database after hotfixes are imported or when changes have been made to processes, scripts, formatting rules, object definitions, task definitions, and preprocessor-relevant configuration parameters.

Report Editor

With the Report Editor, you can group One Identity Manager object data together into reports. You can group, accumulate, and graphically represent this data. Some of our own reports are supplied with the initial migration. However, you can also create your own reports with the Report Editor.

Schema Extension

The Schema Extension extends the existing application data schema of the One Identity Manager database with customer-specific tables and columns. Using the object technology in the One Identity Manager, it is possible to do this at database level such that these additions are available with full functionality at the object level.

System Debugger

The System Debugger allows you to process and test scripts. Existing scripts in your One Identity Manager database are imported into a Visual Studio script library. There, you can edit and test the scripts. Subsequently, you decide whether your changes should be transferred to the One Identity Manager database.

Database Transporter

The Database Transporter transfers objects and custom changes as well as custom database procedures, triggers, functions, and sets from the One Identity Manager database (source) to another One Identity Manager database (target).

HistoryDB Manager

One Identity Manager historical data is transferred at regular intervals into a One Identity Manager History Database. Therefore, the One Identity Manager History Database provides an archive of change information. The HistoryDB Manager tool displays the data in the One Identity Manager History Database. Use the HistoryDB Manager to set up access to the source databases.

Job Service Configuration

Job Service Configuration is used to create and customize the configuration file for One Identity Manager Service. One Identity Manager Service and its plugins are configured with this file. The configuration file is necessary both for One Identity Manager Service on a Windows based operating system and also for the Linux daemon.

License Meter

Using the License Meter, you can track and maintain the licences in your One Identity Manager database. The wizard creates a report with license-relevant information.

Software Loader

Use the Software Loader to load new or modified files, for example custom form archives, in the One Identity Manager database in order to distribute them to One Identity Manager network workstations and Job servers using automatic software updating.

Server Installer

Use the Server Installer to install and configure the One Identity Manager Service. The program executes remote installation of the One Identity Manager Service. Local installation of the service is not possible with this program.

API Designer

The API Designer allows you to create, record, compile and publish a REST-API (Representational State Transfer Application Programming Interface) in the quickest way possible. This API is based on the OpenAPI Specification and the One Identity Manager database model. To use the API, you must install an API Server.

API Server

The API that you created in the API Designer is available in the API Server. It also provides the Operations Support Web Portal and your HTML5 web applications.

Related Topics

Which components and front-ends work with an application server?

The following list tells you which One Identity Manager components can work with an application server. Some front-ends only work have limited functionality to work with an application server.

Table 3: One Identity Manager Components and Application Servers
Component Connection through Application Server? Restrictions
Launchpad

Yes

Certain application, which you can start from the Launchpad, require a direct connection to the database.

Web Portal

Yes

 

Password Reset Portal

Yes

 

Operations Support Web Portal

Yes

 

Manager

Yes

The consistency check is not supported.

Compliance rule simulation is not supported.

Some forms are not supported.

Manager web application

Yes

Some forms are not supported.

Synchronization Editor

Yes

 

Analyzer

Yes

 

Job Queue Info

No

 

Configuration Wizard

No

 

Designer

Yes

The consistency check is not supported.

Process simulation is not supported.

Database compilation is not supported.

Web Designer

Yes

 

Data Import

Yes

 

Crypto Configuration

No

 

Database Compiler

No

 

Report Editor

Yes

SQL query testing is not supported.

Schema Extension

No

 

System Debugger

Yes

 

Database Transporter

No

 

HistoryDB Manager

Yes

 

License Meter

Yes

 

Software Loader

Yes

 

SPML web application

No

 

SOAP Web Service

No

 

One Identity Manager Service

Yes

 

Server Installer Yes  

API Designer

Yes

 

API Server

Yes

 

One Identity Manager Docker images

One Identity provides various Docker images for simple and standardized installation and execution of individual One Identity Manager components in Docker containers. The One Identity Manager Docker images, together with detailed information about the usage and configuration of the individual images are available in the One Identity Docker Repository. Videos containing additional information are available in the One Identity Manager Containerization video series available at www.YouTube.com/OneIdentity. For detailed information about Docker, see https://www.docker.com/.

Table 4: Available One Identity Manager Docker images

Docker image

Description

oneidentity/oneim-job

This image executes an instance of a One Identity Manager Service. When started, it downloads the necessary files for a specific Job server. This behavior can be controlled using encrypted values and environment variables.

oneidentity/oneim-appserver

This image executes an instance of the One Identity Manager application server. When started, it downloads the necessary files from the configured One Identity Manager database. This behavior can be controlled using encrypted values and environment variables.

oneidentity/oneim-web

This image executes an instance of the Web Portal. When started, it downloads the necessary files from the configured One Identity Manager database. This behavior can be controlled using encrypted values and environment variables.

oneidentity/oneim-installer

This image contains a simple installation program that can be used in derived images to create the file structure for One Identity Manager applications.

Installation prerequisites

The following installation prerequisites represent only the minimum requirements for installing and unlimited operation of One Identity Manager. These prerequisites can be used as a starting point for other planning, depending on the size of the project and which business processes and business transactions are supported. Determining hardware capacities and any further development is part of project planning and dependent on the Identity Management project specification. Particular attention must be paid to I/O performance (in throughput and latency) and in SAN environments in particular, a targeted performance analysis of the specify infrastructure is recommended before implementation.

Every One Identity Manager installation can be virtualized. Ensure that performance and resources are available to the respective One Identity Manager component according to system requirements. Ideally, resource assignments for the database server are fixed. Virtualization of a One Identity Manager installation should only be attempted by experts with well-based knowledge of virtualization techniques. For more information about virtual environments, see Product Support Policies.

NOTE: Other system requirements for individual One Identity Manager models are listed in the corresponding documentation for those specific modules.

Detailed information about this topic
Related Documents