立即与支持人员聊天
与支持团队交流

One Identity Safeguard for Privileged Passwords 8.0 LTS - User Guide

Launching an RDP session

Once an RDP session request becomes available, the requester can launch the remote desktop connection to start the session.

To launch a remote desktop connection

  1. If the User Supplied option is selected in the policy, you will be prompted to enter your user credentials. After entering the requested credentials, click Apply. This will retrieve the information (for example, Username Connection String) required to launch the remote desktop session.
  2. In the web client:

    NOTE: The Start RDP Session option is available only if enabled by user preferences.

    • If you have an application registered (rdp:// for RDP sessions), you can click the Start RDP Session button associated with the asset name then click Connect. See KB 313918 for details on application registration. A password must be entered and we recommend sg. A blank password will cause the session to fail.
    • If you do not have an application registered, download the RDP launch file instead of using the Start RDP Session button. A password must be entered and we recommend sg. A blank password will cause the session to fail.

Begin your RDP session and close the session

  1. In the remote desktop session, run the commands or programs on the target host.

    If there is no activity in an open session for about 10 minutes, the session will be closed. However, as long as the request is in an Available state, you can launch the session again to resume your tasks.

  2. Once you are completed, log out of the target host and select Check in to complete the session request process.

Configuring and launching a Remote Desktop Application session

In order to launch a remote desktop application session request, some additional configuration is required.

To configure and launch a remote desktop application

  1. Install and configure Safeguard for Privileged Sessions's RemoteApp launcher available starting with 6.12. For more information, see One Identity Safeguard for Privileged Sessions Administration Guide.

  2. Publish the OISGRemoteAppLauncher application following Microsoft's instructions. All remote applications that will be launched using SPP/SPS need to be configured to launch with the OISGRemoteAppLauncher and include a command line which references the intended remote application. Take note of the RemoteApp Program Name and Alias since they will be needed when configuring the access request policy.

  3. On Asset Management > Assets, you need the following assets (for more information, see Adding an asset (web client)):

    1. Windows Server asset: This asset will be used to connect with a Windows Application Server.

    2. Other/Other Managed asset: This asset (of either platform type) is used to connect with the remote application. It requires the following settings:

      • Network Address: None

      • Authentication Type: None

      • An account from the remote application added to the Accounts tab.

  4. On Security Policy Management > Entitlements, you will need an entitlement containing a Remote Desktop Application access request policy. For more information, see Creating an access request policy (web client).

  5. Within Safeguard for Privileged Sessions, a channel policy needs to be modified or created to include the following attributes. This channel policy will also need to be referenced from an RDP connection policy. For more information, see One Identity Safeguard for Privileged Sessions Administration Guide.

    1. In RDP Control > Connections, set the Channel policy to applications.

    2. In RDP Control > Channel Policies, create the following:

      1. Dynamic virtual channel: No configured settings.

      2. Custom: Add the following to Permitted channels:

        • rail

        • rail_ri

        • rail_wi

Once a remote desktop application session request becomes available, the requester can launch the remote desktop connection to start the session.

To launch a remote desktop application connection

In the web client: Click the Start RDP Session button associated with the asset.

NOTE: The Start RDP Session option is available only if enabled by user preferences and if you have installed Session Client Application Launch Uri System (for more information, see SCALUS).

NOTE: A black window may appear on the screen as the launcher loads the remote desktop application session.

Reviewing a completed session request

The Security Policy Administrator can configure an access request policy to require a review of completed session requests for assets or accounts in the scope of the policy.

NOTE: You can configure Safeguard for Privileged Passwords to notify you of an access request that requires your review. For more information, see Configuring alerts.

Desktop Player User Guide

To download the player user guide, go to One Identity Safeguard for Privileged Sessions - Technical Documentation. Scroll to User Guide and click One Identity SPS [version] Safeguard Desktop Player User Guide.

To review a completed sessions request

To manage reviews, on the left of the page, select (Reviews). On the Reviews page, you can:

  • View the details of a workflow by selecting it.

  • Mark one or more request as reviewed by selecting the requests, then performing one of the following actions:

    • If no comment is required, click (Mark all the selected requests as reviewed).

    • If a comment is required, this icon will display as (One or more of the selected requests requires review comments). Add the comment, then click Mark as Reviewed.

  • Change the columns that display: Click (Select columns to display) and select the columns you want to see.

    • Action: Displays (This request requires review comments) or (Mark only this request as reviewed).

    • Requester: Displays the user name of the requester.

    • Access Type: Displays the type of access (for example, Password, SSH Key, RDP, RDP Application, SSH, API Key, or Telnet).

    • Account: Displays the managed account name.

    • Ticket Number: Displays the ticket number, if required.

    • Request For/Duration: Displays the date and time as well as the window of availability (for example, March 20, 2021 9:56 AM 2 hours).

  • Search: To see a list of searchable elements, click click (Search). For more information, see Search box.

File release request workflow

One Identity Safeguard for Privileged Passwords provides secure control of managed accounts by storing account files until they are needed, and releases them only to authorized persons.

Typically, a file release request follows this workflow.

  1. Request: Users that are designated as an authorized user of an entitlement can request files for any account in the scope of that entitlement's policies.

  2. Approve: Depending on how the Security Policy Administrator configured the policy, a file release request will either require approval by one or more Safeguard for Privileged Passwords users, or be auto-approved. This process ensures the security of account files, provides accountability, and provides dual control over the system accounts.

  3. Review: The Security Policy Administrator can optionally configure an access request policy to require a review of completed file release requests for accounts in the scope of the policy.

相关文档

The document was helpful.

选择评级

I easily found the information I needed.

选择评级