Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
Original file line number Diff line number Diff line change
Expand Up @@ -52,8 +52,11 @@ himself.

After verification, the **SAML application** can be started from the Basic view view.

**CAUTION:** As this is a passwordless authentication, it is not necessary to link the **SAML
:::warning
As this is a passwordless authentication, it is not necessary to link the **SAML
application** with a password.
:::


NOTE: Setup and configuration instructions for
[SAML Application for Dropbox](/docs/passwordsecure/9.1/configuration/advancedview/clientmodule/applications/exampleapplications/saml_application_for_dropbox.md)
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -86,6 +86,9 @@ future. Pressing the button directly opens the linked application.

![start application](/img/product_docs/passwordsecure/9.1/configuration/advanced_view/clientmodule/applications/learning_the_applications/learning_the_applications_7-en.webp)

**CAUTION:** With respect to permissions, applications are subject to the same rules as for
:::warning
With respect to permissions, applications are subject to the same rules as for
passwords, roles or documents. It is possible to separately define which group of users is permitted
to use each application.

:::
Original file line number Diff line number Diff line change
Expand Up @@ -31,11 +31,11 @@ disk space usage.
Session recording firstly needs to be activated for the relevant RDP or SSH application before it
can take place.

RDP
**RDP**

![activating session recording](/img/product_docs/passwordsecure/9.1/configuration/advanced_view/clientmodule/applications/rdp_and_ssh_applications/recording_a_session/recording_a_session_2-en.webp)

SSH
**SSH**

![activating session recording](/img/product_docs/passwordsecure/9.1/configuration/advanced_view/clientmodule/applications/rdp_and_ssh_applications/recording_a_session/recording_a_session_3-en.webp)

Expand Down Expand Up @@ -65,7 +65,7 @@ effectively and quickly viewed so as only to see the relevant actions.

![viewing a session recording](/img/product_docs/passwordsecure/9.1/configuration/advanced_view/clientmodule/applications/rdp_and_ssh_applications/recording_a_session/recording_a_session_6-en.webp)

When are indicators set?
**When are indicators set?**

- Mouse click
- Keyboard command
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -79,8 +79,11 @@ finished, the **Network Scan** scans the **network** according to these guidelin
second section defines the scan configuration for the local computer. Select from either Local
user of services or _Local user_.

**CAUTION:** The system executing the scan – on which the Server Manager is installed – is not
:::warning
The system executing the scan – on which the Server Manager is installed – is not
scanned!
:::


## Interval / Executing server / Tags

Expand All @@ -105,6 +108,9 @@ After the **Discovery Service Task** has been configured, a connection test is p
configuration is saved. The system then indicates whether the configuration is correct or faulty.
Depending on the message, the **Discovery Service Task** may need to be amended.

**CAUTION:** The **default setting** for the **Discovery Service Task** after it has been saved is
:::warning
The **default setting** for the **Discovery Service Task** after it has been saved is
**Activated!** It will **immediately actively** scan the network for data. This data is **read** but
not amended!

:::
Original file line number Diff line number Diff line change
Expand Up @@ -76,8 +76,11 @@ The **settings** will be described in more detail below:
5. The **responsible user for the Password Reset** is entered here.
6. Various **triggers for the Password Reset** can be selected here.

**CAUTION:** After clicking on **Finish**, the **Password Resets** will be **immediately executed**
:::warning
After clicking on **Finish**, the **Password Resets** will be **immediately executed**
and the **passwords changed!**. This also applies to **Windows passwords!**
:::


If option 1: **Do you also want to add a Password Reset?** is not selected, \*steps 4, 5 and 6 are
not displayed for configuration.
Expand Down Expand Up @@ -137,12 +140,18 @@ creating **Password Resets**. If the option **Execute Password Resets immediatel
created** is used in the configuration, the **selected passwords** are immediately changed after
clicking on **Finish**.

**CAUTION:** **If you are not paying careful attention, this could have inconvenient consequences.**
:::warning
**If you are not paying careful attention, this could have inconvenient consequences.**
:::


**Security level 1:** An **Important note** is displayed in the **Summary** after clicking on
**Finish**.

**CAUTION:** **Please observe the note and read it through carefully!**
:::warning
**Please observe the note and read it through carefully!**
:::


An **Overview** of which actions will be carried out is displayed for the user together with this
note. The user can then still decide to **Cancel** the process. If you click on **OK**, an
Expand All @@ -155,7 +164,10 @@ note. The user can then still decide to **Cancel** the process. If you click on
Another **confirmation prompt** highlights that it is important to understand what you are about to
do. It will no longer be possible to reverse the actions afterwards!

**CAUTION:** **Last chance to cancel the execution!**
:::warning
**Last chance to cancel the execution!**
:::


![securtiy warning](/img/product_docs/passwordsecure/9.1/configuration/advanced_view/clientmodule/discoveryservice/converting_entries/converting_entries_11-en.webp)

Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -24,8 +24,11 @@ data. Before configuring the **Network Scan**, a password needs to be issued tha
data. This user should be a member of admin for the corresponding group of domains. Otherwise, you
can use a domain administrator.

**CAUTION:** A corresponding **password** with **rights** for the **domains** must exist before
:::warning
A corresponding **password** with **rights** for the **domains** must exist before
adding a **Network Scan**!
:::


### Password

Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -34,8 +34,11 @@ The following options are required to change forms.

- Can change form for a password

**CAUTION:** Please note that information could be lost during this process! In the example, this
:::warning
Please note that information could be lost during this process! In the example, this
applies to the fields "Website" and "Information".
:::


## The effects of changes to forms on existing records

Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -58,8 +58,11 @@ desired. (**Note**: It is possible to select
[Password rules](/docs/passwordsecure/9.1/configuration/advancedview/mainmenufc/extras/password_rules.md)
within the field settings; they are defined as part of the options in the main menu)

**CAUTION:** If a form has been created, it can then be selected for use when creating new records.
:::warning
If a form has been created, it can then be selected for use when creating new records.
The prerequisite is that the logged-in user has at least read rights to the form.
:::


## Permissions for forms

Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -70,6 +70,9 @@ NOTE: Groups in groups Memberships, which may be present in the Active Directory
displayed within Netwrix Password Secure. Both groups are imported as roles, but independent and not
linked in any way.

**CAUTION:** If Master Key mode has been selected for the Active Directory profile, the AD is the
:::warning
If Master Key mode has been selected for the Active Directory profile, the AD is the
leading system. In this mode, roles that have been imported cannot be changed locally in Netwrix
Password Secure.

:::
Original file line number Diff line number Diff line change
Expand Up @@ -77,10 +77,13 @@ connection is not possible, deactivate SecureSocketsLayer and try again.
being established to the domain **jupiter.local** or an IP address, the login can only be carried
out with **jupiter\user** if **jupiter** has been saved here.

**CAUTION:** The master key is added in form of a certificate. It is **essential to back up** the
:::warning
The master key is added in form of a certificate. It is **essential to back up** the
generated certificate! If the database is being moved to another server, the certificate also needs
to be transferred! Further information can be found in the section
[Certificates](/docs/passwordsecure/9.1/configuration/servermanger/certificates/certificates.md).
:::


NOTE: You can now use the option to integrate a RADIUS server. Read more in
[RADIUS authentication](/docs/passwordsecure/9.1/configuration/advancedview/clientmodule/organisationalstructure/directoryservices/activedirectorylink/radius_authentication.md).
Expand Down Expand Up @@ -192,7 +195,10 @@ password. If the logon via Kerberos does not work – e.g. due to incorrect conf
domain controller – the logon via the NTLM protocol is attempted. However, these are all settings
that have to be made on the domain controller and have nothing to do with Netwrix Password Secure.

**CAUTION:** Logging on to Netwrix Password Secure using SSO via Kerberos is currently not possible.
:::warning
Logging on to Netwrix Password Secure using SSO via Kerberos is currently not possible.
:::


## Permissions to imported objects

Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -51,7 +51,7 @@ create new Entra ID profiles" enabled.
Login to the [Azure portal](https://portal.azure.com/#azure-portal) and go to the management page of
your Microsoft Entra ID.

NOTE: You need an account with administrative permissions
**NOTE: You need an account with administrative permissions**

- Write down your "Tenant ID" shown in the Azure console or by using PowerShell:

Expand All @@ -74,8 +74,11 @@ available in the Azure Gallery.
- In the navigation, click "Users and groups"
- Add the Users and groups that should be available to Netwrix Password Secure

**CAUTION:** The import of Azure groups as Netwrix Password Secure roles is only possible if you
:::warning
The import of Azure groups as Netwrix Password Secure roles is only possible if you
have booked the Azure package Entra ID Premium P1!
:::


- Navigate to the "Provisioning" page
- Configure the Provisioning Mode to "Automatic"
Expand Down Expand Up @@ -111,10 +114,13 @@ created in Netwrix Password Secure now
NOTE: Azure´s default provisioning interval is 40 Minutes. So it may some time until the users and
roles are shown in Netwrix Password Secure.

**CAUTION:** Please note that Azure establishes the connection to Netwrix Password Secure. For this,
:::warning
Please note that Azure establishes the connection to Netwrix Password Secure. For this,
the client URL must be accessible from an external network / provisioning agent and any used SSL
certificate must be valid! If the users are not created in Netwrix Password Secure, consult the
Azure Enterprise Application Provisioning log for more information.
:::


### Azure login configuration

Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -27,7 +27,8 @@ The configuration is done via the user setting **First factor**.

NOTE: This option is only valid for users in master key mode

**CAUTION:** Be Aware" The smartcard logon tries to determine whether the certificate belongs to the
:::warning
Be Aware" The smartcard logon tries to determine whether the certificate belongs to the
user to be logged on based on the applicant in the smartcard certificate. This is done using regex,
the default regex `^{username}[.@\\/-_:]({domain})$` or `^({domain})[.@\\/-_:]({username})$` is
applied to the applicant. In this case, `{username}` is replaced with the user to be registered and
Expand All @@ -36,6 +37,8 @@ positive, the user is registered. If the format of your applicant in your certif
compatible with these two regex queries, you must set a custom regex query in the Server Manager.
Please note that `{username}` for username and `{domain}` for the AD domain SHOULD be present in the
regex query. If the domain must be explicitly specified, it must be written in capital letters.
:::


In addition, the smartcard certificate must of course also be valid on the server!

Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -20,7 +20,7 @@ The following options are required to add local users.

### User rights

Can add new users -Display organisational structure module
**Can add new users -Display organisational structure module**

## Adding local users

Expand All @@ -45,7 +45,7 @@ only the differences will be covered below.
themselves. The property **restricted user** is used to limit the visibility of the password
field. It thus deals with purely administrative users or controlling entities.

NOTE: Restricted users cannot view any passwords
**NOTE: Restricted users cannot view any passwords**

### Configuring rights

Expand All @@ -71,8 +71,11 @@ other editions you can only purchase Advanced view licenses. Please note that li
users are not able to use the Advanced view. However, Advanced view Users can also switch to the
Basic view.

**CAUTION:** For licensing reasons, it is not intended to switch from a Advanced view user to a
:::warning
For licensing reasons, it is not intended to switch from a Advanced view user to a
Basic view user!
:::


Our sales team will be happy to answer any questions you may have about licensing.

Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -73,8 +73,11 @@ This configuration means that the user password cannot be reset by administrator
is that if the password is lost there is no technical solution for "resetting" the password in the
system.

**CAUTION:** It is not recommended to configure the permissions so that only the user themselves has
:::warning
It is not recommended to configure the permissions so that only the user themselves has
membership. No other interventions can be made if the password is then lost.
:::


## Adding local organisational units

Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -34,5 +34,8 @@ The two highlighted options are now available on the ribbon.
Both mechanisms are protected by a confirmation prompt. If both "inherit" and also "overwrite" are
selected, "overwrite" is considered the overriding function.

**CAUTION:** Both mechanisms are not protected by user rights. The **authorize** right for the
:::warning
Both mechanisms are not protected by user rights. The **authorize** right for the
organisational structure is required to activate the inheritance or overwrite functions.

:::
Original file line number Diff line number Diff line change
Expand Up @@ -43,8 +43,11 @@ mouse button. A permissions tab appears:
NOTE: The basic mechanisms for setting permissions is described in detail in the Authorization
concept.

**CAUTION:** It is important that the permissions displayed here are interpreted correctly! The
:::warning
It is important that the permissions displayed here are interpreted correctly! The
example above shows the permissions for the "organisational structure IT".
:::


The user Max Muster possesses all rights to the organisational structure IT and can thus edit,
delete and also grant permissions for this structure.
Expand All @@ -59,4 +62,7 @@ example above, only the administrator has the required permissions for adding ne
IT manager – who possess all other rights to the organisational structure "IT" – does not have the
right to add records.

**CAUTION:** The add right merely describes the right to create objects in an organisational unit.
:::warning
The add right merely describes the right to create objects in an organisational unit.

:::
Original file line number Diff line number Diff line change
Expand Up @@ -24,6 +24,9 @@ system to a new value.
NOTE: If an error occurs during the execution of a password reset, the affected reset is blocked
with all associated passwords. This is noted in the logbook with an entry "blocked".

**CAUTION:** Due to the complexity of the process, it is strongly recommended that Password Reset is
:::warning
Due to the complexity of the process, it is strongly recommended that Password Reset is
configured **in combination with certified partners**. The desired simplification of work processes
using the above-mentioned automated functions is accompanied by numerous risks.

:::
Original file line number Diff line number Diff line change
Expand Up @@ -75,8 +75,11 @@ and the permissions for a record are important aspects.
NOTE: If any kind of automatic permissions have been activated for the selected OU, this will always
be prioritized.

**CAUTION:** Even when creating private records, inheritance of permissions based on the logged-in
:::warning
Even when creating private records, inheritance of permissions based on the logged-in
user can also be activated as an option. This option is described in a separate section.
:::


NOTE: The user right Allow sharing of personal passwords can be used to define that personal
passwords cannot be released to other users.
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -40,9 +40,12 @@ record is the only deciding factor.
- **Extend permissions**: The existing permissions are extended to include the permissions for the
target OU

**CAUTION:** From a technical perspective, all rights will be removed from the record when
:::warning
From a technical perspective, all rights will be removed from the record when
overwriting the permissions. The permissions will then be applied to the record in accordance with
the rights template or inheritance from organisational structures. It is important to note here that
it is theoretically possible to remove your own rights to the record! The rights change will only be
carried out if at least one user retains the right to issue permissions as a result. Otherwise, the
rights change will be cancelled with a corresponding message.

:::
Original file line number Diff line number Diff line change
Expand Up @@ -63,7 +63,7 @@ The module-specific ribbon functions will be explained below.
- **Permissions**: The drop-down menu can be used to set both password permissions and also form
field permissions. This method only allows the manual setting of permissions for data (see

authorization concept)
**authorization concept)**

- **Password masking**: Masking passwords that need to be protected from unauthorized users is an
important feature of the security concept in Netwrix Password Secure.
Expand Down Expand Up @@ -98,8 +98,11 @@ via RDP, SSH, general Windows applications or websites. This makes it possible t

![external link](/img/product_docs/passwordsecure/9.1/configuration/advanced_view/clientmodule/passwords/passwords_5-en.webp)

**CAUTION:** If several sessions are opened on a client, an external link is always called in the
:::warning
If several sessions are opened on a client, an external link is always called in the
first session.
:::


- **History**: This icon opens the history for those records selected in list view in a new tab. Due
to the comprehensive recording of historical versions of passwords, it is now possible to compare
Expand Down
Loading
Loading