A password sync group is used to control password validation and reset across all associated accounts. The same password is used for one or more accounts associated with the same or different assets. For example, synchronized passwords can be used for accounts that support clusters or systems that sync between development, test, and production. An account can belong to only one password sync group. Multiple password sync groups can be added to a partition profile.
The profile change schedule is applied to the sync group. The sync group controls the tasks to change the passwords for the accounts in the sync group. Change tasks occur in the order of password sync group priority. If synchronization fails for an individual account in the sync group, the account is retried multiple times and, if failing after that, the sync task halts and is rescheduled. The administrator must correct the cause of the failure for the sync task to continue.
If an account is associated with a profile with a daily check schedule and also associated with a password sync group, a mismatch on the daily check will trigger a task to set the account password to the current sync group password.
For more information, see Creating a partition profile.
When an account is added to a password sync group, the default priority is 0 which is the highest priority. Subsequent numbers are lower priority (for example, 0, 1, 2, where 0 is the highest priority and 2 is the lowest). Priority determines the order in which account passwords are changed. If all accounts have the same priority, they are synchronized simultaneously. When different priorities are set, passwords at the highest priority (for example, 0) are synchronized first. If priority 0 is successful, accounts at the next priority are synchronized. If any account at a priority fails, the synchronization processing stops and the group is scheduled for synchronization retry. For example, a cluster of systems may have an admin account with the same password. If one master system is set at priority 0 and the subordinates are set at priority 1, the password change on the master must be successful before the passwords on the subordinates are changed. If the master password change fails, the subordinates are unaffected, the cluster continues to function, password change is rescheduled, and the error is logged.
Navigate to Administrative Tools | Settings | Profile | Password Sync Groups. The Password Sync Groups pane displays the following for each sync group.
Property | Description |
---|---|
Enable |
If Enable is selected, the sync runs with the Partition Profile Change schedule. |
Status |
The |
Name |
The name of the password sync group. |
Partition | The partition that uses the rule. |
Profile |
The profile that uses the rule. |
Accounts | The number of accounts to synchronize with a common password. |
Next Sync Date |
The date the sync group password will be synchronized across all accounts. |
Description |
Information about the rule. |
Use the following toolbar buttons to manage password sync groups.
|
NOTE: Changes made from the Password Sync Groups pane are reflected in the password sync groups in the partition profile. See Creating a partition profile. |
Option | Description |
---|---|
Add a password sync group. For more information, see Adding a password sync group. | |
Update the list of password sync groups. | |
Modify the selected password sync group rule. For more information, see Modifying a password sync group. | |
|
Change the password for the selected sync group. All accounts in the password sync group synchronize with the new password. |
The Asset Administrator or a partition's delegated administrator defines the password sync group. An account can belong to only one password sync group. To assign sync groups and related accounts when adding the profile to a partition, see Creating a partition profile.
To create a password sync group
Click Add to open the Password Sync Group dialog.
Click Browse to select a Profile. The Profile name displays.
|
NOTE: Multiple password sync groups can be added to a profile. The profile change schedule is applied to the sync group. The sync group controls the tasks to change the passwords for the accounts in the sync group. Change tasks occur in the order of password sync group priority. For more information, see Password sync group priority. |
Click Add and select one or more Accounts to be synchronized.
The Accounts list displays with the following information about the account: Name, Parent, Service Account, Needs a Password ( if yes or
if no), and Description. Click any columns to sort the accounts.
You can make modifications to the priority of a password sync group, the accounts assigned to a password sync group, or sync the selected account password.
To modify the priority of a password sync group or perform other modifications
To modify an account priority, select the account then click Edit.
Enter the Priority then click OK. For more information, see Password sync group priority.
Safeguard for Privileged Passwords allows you to configure these settings related to accessing One Identity Safeguard for Privileged Passwords. Navigate to Administrative Tools | Settings | Profile | Safeguard Access.
Setting | Description |
---|---|
Login Control | Where you configure the user login control settings. |
Password Rules | Where you configure user password complexity rules. |
© 2021 One Identity LLC. ALL RIGHTS RESERVED. Feedback Terms of Use Privacy