Chat now with support
Chat with Support

One Identity Safeguard for Privileged Passwords 2.4 - Administration Guide

Introduction System requirements Installing the One Identity Safeguard for Privileged Passwords desktop client Setting up Safeguard for Privileged Passwords for the first time Getting acquainted with the console Privileged access requests Toolbox Accounts Account Groups Assets Asset Groups Directories Entitlements Partitions Settings
Access Request settings Appliance settings Asset Management settings Backup and Retention settings Certificate settings Cluster settings External Integration settings Messaging settings Profile settings Access settings Sessions settings
Users User Groups Disaster recovery Administrator permissions Preparing systems for management Troubleshooting Frequently asked questions
How do I access the API How do I audit transaction activity How do I configure external federation authentication How do I manage accounts on unsupported platforms How do I modify the appliance configuration settings How do I prevent Safeguard for Privileged Passwords messages when making RDP connections How do I see which assets and/or accounts are governed by a profile How do I set the appliance system time How do I setup discovery jobs How do Safeguard for Privileged Passwords database servers use SSL What are the access request states What do I do when an appliance goes into quarantine What is required for One Identity Safeguard for Privileged Passwords Privileged Sessions What is required to integrate with Starling Identity Analytics & Risk Intelligence What needs to be set up to use Application to Application What role-based email notifications are generated by default When does the rules engine run for dynamic grouping and tagging Why did the password change during an open request Why join Safeguard for Privileged Passwords to One Identity Starling
Safeguard Desktop Player Appendix: Safeguard ports

General tab

The General tab lists information about the selected asset.

Large tiles at the top of the tab display the number of Accounts, Account Dependencies (when applicable), Access Request Policies and Asset Groups associated with the selected asset. Clicking a tile heading opens the corresponding tab.

NOTE: The Asset Groups tile is only visible to the Auditor.

Table 51: Assets General tab: General properties
Property Description
Name The asset name.
Partition The name of the partition where the selected asset resides.
Profile

The name of the profile that manages the asset's accounts.

NOTE: All assets must be governed by a profile. All new assets are automatically governed by the default profile unless otherwise specified.

License Type

Indicates your license model.

Last Successful Account Discovery

The date and time of the last successful account discovery job.

Next Account Discovery

The date and time of the next automated account discovery job as set in the Account Discovery schedule of the partition profile. (For more information, see Creating a partition profile.)

Directory

The name of the directory where the asset was discovered.

NOTE: This property is only displayed for assets discovered from a directory.
Domain Name

The name of the domain where the asset was discovered.

NOTE: This property is only displayed for assets discovered from a directory.
NetBios name

The NetBios name of the asset that was discovered.

NOTE: This property is only displayed for assets discovered from a directory.
Distinguished Name

The distinguished name of the asset that was discovered.

NOTE: This property is only displayed for assets discovered from a directory.

Table 52: Assets General tab: Management properties
Property Description
Product The platform of the selected managed system.
Version The operating system version.

Architecture

The operating system architeture.

Network Address The network DNS name or IP address of the managed system.
Enable Session Request True or False, indicating whether session access requests are enabled for the asset.
RDP Session Port The access port on the target server used for RDP session access requests.
SSH Session Port The access port on the target sever used for SSH session access requests.

Managed Network

The managed network that is assigned for work load balancing. For more information, see Managed Networks.

Table 53: Assets General properties: Connection properties
Property Description
Authentication Type How the console connects with the managed system. For more information, see Connection tab.
Service Account Name The account used by Safeguard for Privileged Passwords to securely manage accounts and passwords on the asset.
Connection Timeout The session timeout period.
Privilege Elevation Command Displays the elevation command (such as sudo) if it is populated on the Connection tab.
Port The port used by SSH to log into the managed system.
SSH Host Key Fingerprint The fingerprint of the SSH key that Safeguard for Privileged Passwords uses to authenticate to the asset.

Tags: Tag assignments for the selected asset.

The tiles listed under in the Tags pane display both the dynamic tags assigned to the asset through tagging rules and static tags that were added manually. In addition to viewing tag assignments, Asset Administrators can add and remove statically assigned tags using this pane.

Description: Information about the selected asset.

Related Topics

Assigning an asset to a partition

Assigning a profile to an asset

Modifying an asset

Accounts tab

An asset's Accounts tab displays the accounts associated with this asset.

Click (or tap) Add Account from the details toolbar to associate an account with the selected asset.

Table 54: Assets: Accounts tab properties
Property Description

Name

Name of an account associated with the selected asset.

NOTE: While you can associate an account with only one asset, you can log into an asset with more than one account.

Profile

The name of the profile that manages the account.

Service Account

A check in this column indicates that the account is a service account.

Password Request

A check in this column indicates that password release requests are enabled for the account.

NOTE: Click (or tap) Access Requests from the details toolbar to enable or disable a user's ability to request access to the selected account.

Session Request

A check in this column indicates that session access requests are enabled for the account.

NOTE: Click (or tap) Access Requests from the details toolbar to enable or disable a user's ability to request access to the selected account.

Needs a Password

Displays if a password is not set for the account. For more information, see Checking, changing, or setting an account password.

Description

Descriptive information entered when the account was added.

Use these buttons on the details toolbar to manage your asset accounts.

Table 55: Assets: Accounts tab toolbar
Option Description
Add Account

Add accounts to the selected asset. For more information, see Adding an account to an asset.

Delete Selected

Remove the selected account from the asset.

Refresh

Update the list of asset accounts.

Account Security

Menu options include: Check Password, Change Password, and Set Password. For more information, see Checking, changing, or setting an account password.

Password Archive

Display the password history for the selected asset account. For more information, see Viewing password archive.

Access Requests

Select an option to enable or disable access request services for the selected account. Menu options include:

  • Enable Password Request
  • Disable Password Request
  • Enable Session Request
  • Disable Session Request

NOTE: Access request services are enabled by default for all accounts added directly to Safeguard for Privileged Passwords, except for service accounts. Access request services are disabled by default for all discovered accounts.

Set Profile

Select a profile to manage the selected asset account.

Search

To locate a specific asset account or set of accounts in this list, enter the character string to be used to search for a match. For more information, see Search box.

Account Dependencies tab

The Account Dependencies tab displays the directory accounts that the selected Windows server depends on to perform services and tasks.

Note: The Account Dependencies tab is only applicable for a Windows platform when one or more directories have been added to Safeguard for Privileged Passwords.

Click (or tap)  Add Account from the details toolbar to associate account dependencies with the selected asset.

Table 56: Assets: Account Dependencies tab properties
Property Description

Name

Name of a directory account.

Directory

The directory in which the account resides.

Domain Name

The forest root domain name for the directory.

Distinguished Name

The distinguished name for a directory account.

Description

Description of the dependent account.

Related Topics

Adding account dependencies

Access Request Policies tab

The Access Request Policies tab displays the entitlements and access request policies associated with the selected asset.

Table 57: Assets: Access Request Policies tab properties
Property Description

Entitlement

The name of the access request policy's entitlement.

Access Request Policy

The name of the policy that governs the selected asset.

Assets

The number of unique assets that are associated with the access request policy.

# Asset Groups

The number of unique asset groups in the access request policy.

Asset Groups

The names of the asset groups that associate the selected asset with the policy.

Use these buttons on the details toolbar to manage your access request policies associated with the selected asset.

Table 58: Assets: Access Request Policies tab toolbar
Option Description

Add to Policy

Add the selected asset to the scope of a session access request policy.

Remove Selected

Remove the selected policy. For more information, see Deleting an access request policy.

Refresh

Update the list of access request policies.

Details

View additional details about the selected policy. For more information, see Viewing policy details.

Search

To locate a specific policy or set of policies in this list, enter the character string to be used to search for a match. For more information, see Search box.

Related Documents