立即与支持人员聊天
与支持团队交流

Identity Manager 9.1.3 - Administration Guide for Privileged Account Governance

About this guide Managing a Privileged Account Management system in One Identity Manager Synchronizing a Privileged Account Management system
Setting up the initial synchronization of a One Identity Safeguard Customizing the synchronization configuration for One Identity Safeguard Running synchronization Tasks following synchronization Troubleshooting Ignoring data error in synchronization Pausing handling of target system specific processes (Offline mode)
Managing PAM user accounts and employees Managing assignments of PAM user groups Login information for PAM user accounts Mapping of PAM objects in One Identity Manager PAM access requests Handling of PAM objects in the Web Portal Basic data for managing a Privileged Account Management system Configuration parameters for managing a Privileged Account Management system Default project template for One Identity Safeguard Editing One Identity Safeguard system objects One Identity Safeguard connector settings Known issues about connecting One Identity Safeguard appliances

Editing the synchronization project for a PAM appliance

Synchronization projects in which an appliance is already used as a base object can also be opened in the Manager. You can, for example, check the configuration or view the synchronization log in this mode. The Synchronization Editor is not started with its full functionality. You cannot run certain functions, such as, running synchronization or simulation, starting the target system browser and others.

NOTE: The Manager is locked for editing throughout. To edit objects in the Manager, close the Synchronization Editor.

To open an existing synchronization project in the Synchronization Editor:

  1. In the Manager, select the Privileged Account Management > Appliances category.

  2. Select the appliance in the result list.

  3. Select the Change main data task.

  4. Select the Edit synchronization project task.

Related topics

Displaying the PAM appliance overview

Use this task to obtain an overview of the most important information about an appliance.

To obtain an overview of an appliance

  1. In the Manager, select the Privileged Account Management > Appliances category.

  2. Select the appliance in the result list.

  3. Select the PAM appliance overview task.

PAM user accounts

You can use One Identity Manager to manage Privileged Account Management user accounts. A user account enables an employee to log onto the Privileged Account Management system, for example, onto One Identity Safeguard. One Identity Manager manages the local users of a Privileged Account Management system and directory users. Directory users are user accounts from an external target system, for example Active Directory or LDAP.

Through their user group, the user receives the required entitlements, for example, for requesting a password for an asset account or a session for the accounts and assets in the Privileged Account Management system.

A user account can be linked to an employee in One Identity Manager. You can also manage user accounts separately from employees.

NOTE: It is recommended to use account definitions to set up user accounts for company employees. In this case, some of the main data described in the following is mapped through templates from employee main data.

NOTE: If employees are to obtain their user accounts through account definitions, the employees must own a central user account and obtain their IT operating data through assignment to a primary department, a primary location, or a primary cost center.

Related topics

Creating local PAM user accounts

To create a local PAM user account

  1. In the Manager, select the Privileged Account Management > User accounts category.

  2. Click in the result list.

  3. On the General tab, enter the following data as a minimum:
    • Appliance: Appliance to which the user account belongs.

    • Identity provider: Select the Local value.

    • User name: Enter the name to display.

    • Authentication provider: Select how the user is authenticated in the Privileged Account Management system. Depending on the authentication provider, other data may be required.

      • Local: Enter the login name, password, and password confirmation.

      • <External organization>: Enter the email address or the name claim.

      • <RADIUS server>: Enter the login name of the RADIUS server.

    • Time zone: The user's time zone. The default time zone is UTC (Coordinated Universal Time).

  4. Save the changes.
Related topics
相关文档

The document was helpful.

选择评级

I easily found the information I needed.

选择评级