It is the responsibility of the Asset Administrator, or a partition's delegated administrator, to configure account password complexity rules.
To add an account password rule
Set the Password Length from 3 to 255 characters.
Default: 6 to 10 characters
|
Note: The maximum length must be equal to or greater than the sum of minimum characters described in the next step. |
First Character Type |
Choose one of the following:
Default: All | ||
Last Character Type |
Choose one of the following:
Default: All | ||
Allow Consecutively Repeated Characters |
Select this option to allow Safeguard for Privileged Passwords to create a password with consecutively repeated characters.
Default: Not allowed | ||
Allow Uppercase |
Select this option to allow Safeguard for Privileged Passwords to create a password with uppercase characters. Set the minimum number of required uppercase characters, or set it to zero if there is no minimum requirement.
Default: Require a minimum of 1 | ||
Allow Lowercase |
Select this option to allow Safeguard for Privileged Passwords to create a password with lowercase characters. Set the minimum number of required lowercase characters, or set it to zero if there is no minimum requirement.
Default: Require a minimum of 1 | ||
Allow Numeric (0-9) |
Select this option to allow Safeguard for Privileged Passwords to create a password with numeric characters. Set the minimum number of required numeric characters, or set it to zero if there is no minimum requirement.
Default: Require a minimum of 1 | ||
Allow Symbols (e.g @ # $ % &) |
Select this option to allow Safeguard for Privileged Passwords to create a password with special characters. Set the minimum number of required symbolic characters, or set it to zero if there is no minimum requirement.
Default: Not allowed | ||
Valid Symbols |
Enter allowable special characters, such as: ~!@#$%^*()_+-=;'?/\|><.,`[]{}.
|
Change password settings are the rules Safeguard for Privileged Passwords uses to reset account passwords.
Navigate to Administrative Tools | Settings | Profile | Change Password.
The Change Password pane displays the following about the listed change password setting rules.
Property | Description |
---|---|
Name |
The name of the rule. |
Partition | The partition that uses the rule. |
Description |
Information about the rule. |
Schedule | Displays the selected rule's schedule. |
Use these toolbar buttons to manage the change password setting rules.
Option | Description |
---|---|
Add a change password rule. For more information, see Adding change password settings. | |
Update the list of change password rules. | |
Modify the selected rule. | |
"Clone" the selected rule. |
It is the responsibility of the Asset Administrator or the partition's delegated administrator to configure the rules Safeguard for Privileged Passwords uses to reset account passwords.
|
IMPORTANT: Passwords for accounts associated with a password sync group are managed based on the profile change schedule and processed via the sync group. If synchronization fails for an individual account in the sync group, the account is retried multiple times and, if failing after that, the sync task halts and is rescheduled. The administrator must correct the cause of the failure for the sync task to continue. For more information, see Password Sync Groups. |
To add a password reset schedule
Optionally, select Change Passwords Manually.
For more information, see How do I manage accounts on unsupported platforms.
Interval: Choose Never, Minute, Hour, Day, Week, or Month.
|
NOTE: Best Practice: Do not use the Minute interval. |
Repeat interval: Select the interval you would like to repeat the password reset task.
Suspend account when not checked out (supported platforms): Select this option to automatically suspend managed accounts that are not in use. That is, the account on a managed asset is suspended until a request is made for it through Safeguard for Privileged Passwords, at which time Safeguard for Privileged Passwords restores the account. Once the request is checked in or closed, the account is again suspended.
Click (or tap) the supported platforms link to display a list of platforms that support this feature.
|
NOTE: When managing passwords for Windows service accounts, do not select this option. Create a separate Profile with Change Password settings that do not have this option selected for managing Windows service accounts. |
Manage SSH Key: Select this option to allow Safeguard for Privileged Passwords to rotate the SSH key it uses to communicate with an asset configured to use SSH Key Authentication. For more information, see SSH Key.
|
NOTE: Clear this option to only manage passwords. |
Check password settings are the rules Safeguard for Privileged Passwords uses to verify account passwords.
Navigate to Administrative Tools | Settings | Profile | Check Password.
The Check Password pane displays the following about the listed check password setting rules.
Property | Description |
---|---|
Name |
The name of the check password rule. |
Partition | The partition that uses the rule. |
Description |
Information about the rule. |
Schedule | Displays the selected rule's schedule. |
Use these toolbar buttons to manage the check password setting rules.
Option | Description |
---|---|
Add a check password rule. For more information, see Adding check password settings. | |
Update the list of check password rules. | |
Modify the selected rule. | |
"Clone" the selected rule. |
© 2019 One Identity LLC. ALL RIGHTS RESERVED. Feedback Terms of Use Privacy