Chat now with support
Chat with Support

Safeguard Authentication Services 4.1.5 - Evaluation Guide

One Identity Privileged Access Suite for Unix Introducing One Identity Authentication Services Installing and configuring Authentication Services Getting started with Authentication Services

Set Supervisor Password dialog

The supervisor account is the default account for accessing all features of the mangement console. The supervisor is a member of all roles and no permissions can be removed from supervisor. However, the supervisor does not have Active Directory credentials and therefore is blocked from performing Active Directory tasks.

To set the supervisor password

  1. On the Set supervisor password dialog, enter a password for the supervisor account and click Next.

    The Summary dialog displays.

  2. To log on using the console supervisor account, use "supervisor" as the user name.

Note: The supervisor is the only account that has rights to change the supervisor account password in System Settings. (See Reset the Supervisor Password in the mangement console online Help for details.)

Summary dialog

To complete the Management Console for Unix Setup wizard

  1. On the Summary dialog, click Finish.

    The Management Console for Unix log in screen opens.

Management Console for Unix log on page

Whenever you launch the mangement console, you must enter an authorized account to proceed. The Management Console for Unix features that are available depend on the account with which you log in.

To use the core version to manage local Unix users and groups and to access the mangement console system settings, you must use the supervisor account (that is, you must log on with the supervisor user name). However, to use the Active Directory features of Management Console for Unix, you must log on with an Active Directory account that has been granted access to the mangement console. That is, defined during the post-installation configuration. (See Setup Console Access by Role in online Help for details.) To add additional accounts to this access list, see Add (or Remove) Role Members in online Help for details.

To log on to the mangement console

  1. Enter the user name and password and click Sign In.

    Enter:

    • the supervisor account name
    • a sAMAccountName, which uses the default domain
    • a User Principal Name in the form, username@domain

    The mangement console opens and displays the user name you specified in the upper right-hand corner of the screen.

  2. To log on using a different account, click the authenticated user's login name and click Sign Out. Then sign back on using a different account.

    The Log-on page redisplays, allowing you to enter a different account.

Prepare Unix hosts

The mangement console provides a central management and reporting console for local Unix users and groups.

Using Management Console for Unix with Authentication Services not only allows you to centrally manage your hosts, but it allows you to do these additional features for managing Unix systems with Active Directory:

  • Ability to remotely install Authentication Services agents, join systems to Active Directory, and implement AD-based authentication for Unix, Linux, and Mac OS X systems.
  • Ability to manage access control on a single host system or across multiple hosts.
  • Ability to create reports about Unix-enabled users and groups in Active Directory.
  • Ability to create access control reports that show which user is permitted to log into which Unix host.

Whether you have the core version or are using the mangement console with Authentication Services, once you have successfully installed Management Console for Unix, you must first add your hosts to the console, and then profile them to gather system information. Once a host is added and profiled you can then manage users and groups on the hosts and run reports.

Related Documents