Depending on how the Security Policy Administrator configured the policy, a sessions request will either require approval by one or more Safeguard for Privileged Passwords users, or be auto-approved.
You can configure Safeguard for Privileged Passwords to notify you of an access request that requires your approval. For more information, see Configuring alerts..
To approve or deny a session request
Click Approvals on the left of the page to manage approvals. On the Approvals page, you can:
- View details by selecting a request then looking at the details display on the right of the page.
- Approve one or more request: Select the requests. Then, click Approve all selected requests to approve all the requests you selected. Optionally, enter a comment.
- Deny one or more request: Select the requests. Then, click Deny all selected requests to deny all the requests you selected. Optionally, enter a comment.
- Change the columns that display: Click and select the columns you want to see. You can select columns including:
- Action: Displays Approve only this request and Deny only this request.
- Requester / Status: Displays the user name and the status of the approval (for example, Pending 1 approval).
- Asset / Access Type: Displays the name of the asset and the type of access (for example, Password, SSH Key, RDP, SSH, API Key, or Telnet).
- Account: Displays the managed account name.
- Ticket Number: Displays the ticket number, if required.
- Requested For: Displays the date and time as well as the window of availability (for example, March 20, 2021 9:56 AM 2 hours).
- Search: For more information, see Search box..
Once an SSH session request becomes available, the requester can launch the SSH client to start the session.
To launch the SSH client to begin your session then close your session
- If the User Supplied option is selected in the policy, you will be prompted to enter your user credentials. After entering the requested credentials, click Apply. This will retrieve the information (for example, Hostname Connection String) required to launch the SSH client.
-
Click the Start SSH Session button associated with the asset name. In the web client, a session will launch if you have an application registered (ssh:// for SSH protocol).
NOTE: The Start SSH Session options are available only if enabled by user preferences.
-
In the SSH client, run the commands or programs on the target host.
If there is no activity in an open session for about 10 minutes, the session will be closed. However, as long as the request is in an Available state, you can launch the session again to resume your tasks.
-
Once you are completed, log out of the target host and select Check in to complete the session request process.
Once an RDP session request becomes available, the requester can launch the remote desktop connection to start the session.
To launch a remote desktop connection
- If the User Supplied option is selected in the policy, you will be prompted to enter your user credentials. After entering the requested credentials, click Apply. This will retrieve the information (for example, Username Connection String) required to launch the remote desktop session.
-
In the web client:
NOTE: The Start RDP Session option is available only if enabled by user preferences.
- If you have an application registered (rdp:// for RDP sessions), you can click the Start RDP Session button associated with the asset name then click Connect. See KB 313918 for details on application registration. A password must be entered and we recommend sg. A blank password will cause the session to fail.
- If you do not have an application registered, download the RDP launch file instead of using the Start RDP Session button. A password must be entered and we recommend sg. A blank password will cause the session to fail.
Begin your RDP session and close the session
-
In the remote desktop session, run the commands or programs on the target host.
If there is no activity in an open session for about 10 minutes, the session will be closed. However, as long as the request is in an Available state, you can launch the session again to resume your tasks.
-
Once you are completed, log out of the target host and select Check in to complete the session request process.
In order to launch a remote desktop application session request, some additional configuration is required.
To configure and launch a remote desktop application
-
Install and configure Safeguard for Privileged Sessions's RemoteApp launcher available starting with 6.12. For more information, see One Identity Safeguard for Privileged Sessions Administration Guide.
-
Publish the OISGRemoteAppLauncher application following Microsoft's instructions. All remote applications that will be launched using SPP/SPS need to be configured to launch with the OISGRemoteAppLauncher and include a command line which references the intended remote application. Take note of the RemoteApp Program Name and Alias since they will be needed when configuring the access request policy.
-
On Asset Management > Assets, you need the following assets (for more information, see Adding an asset (web client)):
-
Windows Server asset: This asset will be used to connect with a Windows Application Server.
-
Other/Other Managed asset: This asset (of either platform type) is used to connect with the remote application. It requires the following settings:
-
On Security Policy Management > Entitlements, you will need an entitlement containing a Remote Desktop Application access request policy. For more information, see Creating an access request policy (web client).
-
Within Safeguard for Privileged Sessions, a channel policy needs to be modified or created to include the following attributes. This channel policy will also need to be referenced from an RDP connection policy. For more information, see One Identity Safeguard for Privileged Sessions Administration Guide.
-
In RDP Control > Connections, set the Channel policy to applications.
-
In RDP Control > Channel Policies, create the following:
-
Dynamic virtual channel: No configured settings.
-
Custom: Add the following to Permitted channels:
Once a remote desktop application session request becomes available, the requester can launch the remote desktop connection to start the session.
To launch a remote desktop application connection
In the web client: Click the Start RDP Session button associated with the asset.
NOTE: The Start RDP Session option is available only if enabled by user preferences and if you have installed Session Client Application Launch Uri System (for more information, see SCALUS).
NOTE: A black window may appear on the screen as the launcher loads the remote desktop application session.