立即与支持人员聊天
与支持团队交流

Password Manager 5.14.2 - Administration Guide

About Password Manager Getting started Password Manager architecture
Password Manager components and third-party applications Typical deployment scenarios Password Manager in a perimeter network Management Policy overview Password policy overview Secure Password Extension overview reCAPTCHA overview User enrollment process overview Questions and Answers policy overview Password change and reset process overview Data replication Phone-based authentication service overview
Management policies
Checklist: Configuring Password Manager Understanding Management Policies Adding or cloning a new Management Policy Configuring access to the Administration Site Configuring access to the Password Manager Self-Service Site Configuring access to the Helpdesk Site Configuring Questions and Answers policy Workflow overview Custom workflows Custom activities Password Manager Self-Service Site workflows Helpdesk workflows Notification activities User enforcement rules
General Settings
General Settings overview Search and logon options Importing and exporting configuration settings Outgoing mail servers Diagnostic logging Scheduled tasks Web Interface customization Instance reinitialization Realm Instances Domain Connections Extensibility features RADIUS Two-Factor Authentication Internal Feedback Customizing help link URL Password Manager components and third-party applications Unregistering users from Password Manager Bulk Force Password Reset Fido2 key management Working with Redistributable Secret Management account Email templates
Upgrading Password Manager Administrative Templates Secure Password Extension Password Policies Enable 2FA for administrators and helpdesk users Reporting Password Manager integration Accounts used in Password Manager Open communication ports for Password Manager Customization options overview Third-party contributions Glossary

Telephone verification feature license

Password Manager requires a separate license for the Telephone verification feature that allows users to authenticate themselves via one-time PINs received as text messages or through automated voice calls. For more information about this feature, see Phone-based authentication service overview.

You can install this license during Password Manager installation or provide the license file later on the Administration Site. To install the license after Password Manager installation, see Updating the License.

You must specify a separate scope of users for telephone verification service. Only users included in the scope will have access to the service.

License violation occurs in the following cases:

  • The actual number of users exceeds the maximum licensed number for the telephone verification service. In this case, users will not be able to authenticate via phone if you do not decrease the number of user accounts set in the scope or do not update the license.

  • The license for the telephone verification service expired. In this case, you will have a grace period of 30 days during which the telephone verification service is available. Once the grace period has expired, users will not be able to authenticate via phone, but, other authentication mechanisms such as Q&A, are not affected by expiry/non-compliance of this Telephone Verification license.

Installing Password Manager: Checklist

This checklist provides tasks that an administrator should perform when installing Password Manager.

  1. Before you install Password Manager, configure the Password Manager Service account and application pool identity. For more information, see Configuring Password Manager Service Account and Application Pool Identity.

  2. It is strongly recommended that you enable HTTPS on the server where Password Manager is installed. For more information, see Enabling HTTPS.

  3. Install an instance of Password Manager. For more information, see Installing Password Manager: Checklist.

Installing Password Manager

This section describes how to install Password Manager. You will learn how to configure Password Manager Service account and application pool identity. A separate section will guide you through the steps required to install Password Manager.

IMPORTANT: Password Manager for Active Directory (AD) and Password Manager for Active Directory Lightweight Directory Services (ADLDS) must not be installed on the same server.

Configuring the Password Manager service account and the application pool identity

When installing Password Manager, you are prompted to specify two accounts: the Password Manager Service account and the application pool identity. The Password Manager Service account is an account under which Password Manager Service runs. You can also use the Password Manager Service account as a domain management account (the account that is necessary to add managed domains when configuring the user and Helpdesk scopes). To do this, ensure that the Password Manager Service account has the minimum permissions required to successfully perform password management tasks in the domain. For more information, see Configuring permissions for domain management account.

Application pool identity is an account under which the application pool's worker process runs. The account you specify as the application pool identity will be used to run Password Manager Web sites.

For Password Manager to run successfully, the accounts you specify when installing Password Manager must meet the following requirements:

  • The Password Manager Service account must be a member of the Administrators group on the web server where Password Manager is installed.

  • The Application pool identity account must be a member of the IIS_IUSRS local group on the web server in IIS 7.0 and must have permissions to create files in the <password-manager-installation-folderr>\App_Data folder.

  • The Application pool identity account must have the full control permission set for the following registry keys: HKEY_LOCAL_MACHINE\SOFTWARE\One Identity\Password Manager.

  • If the Application pool identity account is a domain user with minimal permission, provide the <password-manager-installation-folder>\Web folder with a full control permission set for the Application pool identity account.

Before you install Password Manager, make sure that the Password Manager Service account and the application pool identity account have the rights listed above.

相关文档

The document was helpful.

选择评级

I easily found the information I needed.

选择评级