Chat now with support
Chat with Support

One Identity Safeguard for Privileged Passwords 6.0.7 LTS - Administration Guide

Introduction System requirements and versions Using API and PowerShell tools Using the virtual appliance and web management console Cloud deployment considerations Setting up Safeguard for Privileged Passwords for the first time Using the web client Getting started with the desktop client Using the desktop client Search box Privileged access requests Toolbox Accounts Account Groups Assets Asset Groups Discovery Entitlements Partitions Settings
Access Request settings Appliance settings Asset Management settings Backup and Retention settings Certificate settings Cluster settings External Integration settings Messaging settings Profile settings Safeguard Access settings
Users User Groups Disaster recovery and clusters Administrator permissions Preparing systems for management Troubleshooting Frequently asked questions Appendix A: Safeguard ports Appendix B: SPP 2.7 or later migration guidance Appendix C: SPP and SPS join guidance Appendix D: Regular Expressions SPP glossary

Managing assets

Use the controls and tabbed pages on the Assets page to perform the following tasks to manage Safeguard for Privileged Passwords assets:

Adding an asset

It is the responsibility of the Asset Administrator to add assets and accounts to Safeguard for Privileged Passwords.

Safeguard for Privileged Passwords allows you to set up Asset Discovery jobs that run automatically. For more information, see Asset Discovery job workflow.

Before you add systems to Safeguard for Privileged Passwords, make sure they are properly configured. For more information, see Preparing systems for management.

NOTE: There are special considerations for adding an MS SQL asset to Safeguard. See KB 261806 for details.

To add an asset

  1. Navigate to Administrative Tools | Assets.
  2. Click Add Asset from the toolbar.
  3. In the Asset dialog, provide information in each of the tabs:
    General tab (add asset)

    Where you add general information about the asset

    Management tab (add asset)

    Where you add the network address, operating system, and version information

    Account Discovery tab (add asset)

    Where you add the Account Discovery job

    Connection tab (add asset) Where you add the authentication type information or custom platform properties

    Attributes tab (add asset)

    Where you add attributes to directory assets

Related Topics

Adding an account to an asset

Assigning an asset to a partition

Assigning a profile to an asset

Assigning assets or accounts to a profile

General tab (add asset)

Use the General tab to specify general information about the asset, including the partition and profile to which the asset is assigned. An asset can only be in one partition at a time. When you add an asset to a partition, all accounts associated with that asset are automatically added to that partition. All assets must be governed by a profile and new assets are automatically governed by the default profile unless otherwise specified.

Table 50: Asset: General properties
Property Description
Name

Enter a unique display name for the asset.

Limit: 100 characters

Required

Description

(Optional) Enter information about this managed system.

Limit: 255 characters

Partition

Browse to select a partition for this asset. You can set a specific partition as the default, see Setting a default partition.

Profile

Browse to select a profile to manage this asset's accounts.

You must assign all assets to a profile. Safeguard for Privileged Passwords assigns all new assets to the default profile unless you specify another. You can set a specific profile as the default. For more information, see Setting a default partition profile.

Click Reset to set the profile to the current default.

The Reset button only becomes active when the asset has been explicitly assigned to the profile. If the asset is only implicitly assigned to the profile, Safeguard for Privileged Passwords does not activate the Reset button. If you do not explicitly assign an asset to a profile, it is always assigned to the current default profile.

Management tab (add asset)

Use the Administrative Tools | Assets | Management tab to add the network address, operating system or directory service, and version information for an asset.

When you create a directory asset, accounts created display as discovered accounts in the Discovered Accounts properties grid. For more information, see Discovered Accounts.

The settings for an asset are shown below.

Table 51: Asset: Management tab properties (for example, Windows, Linux, OpenLDAP, or Active Directory)
Property Description
Product

Select an operating system or directory service, for this asset.

A custom platform can be selected. For more information, see Custom platforms.

NOTE: Safeguard for Privileged Passwords allows you to select a generic operating system of Other, Other Managed, or Other Linux. This allows you to add an asset to Safeguard for Privileged Passwords without designating a specific platform.

  • Other: An asset with an Other operating system cannot be managed. You can manually change passwords on accounts associated with an asset with an Other operating system. Safeguard for Privileged Passwords cannot connect to the asset so there is no automatic password check and change, test connection, or other activity requiring a connection.
  • Other Managed: Safeguard for Privileged Passwords stores the password and can automatically check and change it per the profile configuration. There is no active connection or service account. The passwords are rotated internally and event notifications are sent when the rotation is complete. Another component or piece of automation can change the password or make use of the password in configuration files. For example, a listener can pick up the change event via the Safeguard for Privileged Passwords Application to Application (A2A) service and perform actions, as required.
  • Other Linux: Safeguard for Privileged Passwords manages an asset with "Other Linux" on a best effort basis.

Other platform details: Any Other platform type can be changed to different platform type. Conversely, any platform type can be changed to Other, however, any property values specific to the current platform type will be lost. For example, you may want to change an Other Linux operating system to any type of Linux, such as AIX, HP-UX, or Solaris. Then, the specific platform type can be changed back to Other, if needed. For more information, see Modifying an asset.

Version

If applicable, select the operating system version. When adding a Linux or Macintosh OS X system, Safeguard for Privileged Passwords allows you to choose an Other version.

NOTE: Safeguard for Privileged Passwords does not manage passwords for accounts on domain controllers. Manage accounts on domain controllers through the directory asset that hosts the domain controller. For more information, see Adding an account to an asset.

Architecture

If applicable, the product's system architecture.

Network Address

If applicable, enter a network DNS name or the IP address used to connect to the managed system over the network.

For Amazon Web Services assets, enter the Amazon AWS Account ID or Alias.

Domain Name (directory)

The domain for the asset (Name on the General tab). A domain can be identified for more than one directory asset so that multiple directory assets can be governed the same domain.

Manage Forest (directory)

Select if you want to manage the whole forest. Do not select if you want to manage just one domain.

Available for discovery across all partitions

If applicable, select to make this asset read-access available for Asset Discovery jobs beyond partition boundaries. Any partition that exists is able to use this directory asset. Other partition owners do not have read password access. If not selected, partition owners and other partitions will not know the directory asset exists.

In setting up the Asset Discovery job, use the Directory asset discovery Method so that directory assets that are shared can be discovered into any partition. For more information, see General tab (asset discovery).

Enable Session Request

If applicable, this check box is selected by default, indicating that authorized users can request session access for this asset.

Clear this check box if you do not want to allow session requests for this asset. If an asset is disabled for sessions and an account on the asset is enabled for sessions, sessions are not available because the asset does not allow sessions.

Advanced

 

Managed Network

The managed network that is assigned for work load balancing. For more information, see Managed networks.

RDP Session Port

If applicable, specify the access port on the target server to be used for RDP session requests.

Default: Port 3389

SSH Session Port

If applicable, specify the access port on the target server to be used for SSH session requests.

Default: Port 22

Telnet Session Port

If connecting to TN3270 or TN5250, the port for connection. By default, a telnet server typically listens on port 23.

Sync additions every [number] minutes

For directory assets, enter or select how often you want Safeguard for Privileged Passwords to synchronize additions (in minutes). This updates Safeguard for Privileged Passwords with any additions, or modifications that have been made to the objects, including group membership and user account attributes mapped to Safeguard for Privileged Passwords.

Default: 15 minutes

Range: Between 1 and 2147483647

Directory Sync is enabled by default and can be disabled. For more information, see Enable or Disable Services (Access and management services).

Sync deletions every [number] minutes

For directory assets, enter or select how often you want Safeguard for Privileged Passwords to synchronize deletions (in minutes).

This updates Safeguard for Privileged Passwords with any deletions that have been made to the objects, including group membership and user account attributes mapped to Safeguard for Privileged Passwords.

Default: 15 minutes

Range: Between 1 and 2147483647

Directory Sync is enabled by default and can be disabled. For more information, see Enable or Disable Services (Access and management services).

Related Documents

The document was helpful.

Select Rating

I easily found the information I needed.

Select Rating