13.04.2013 Views

Digipass Plug-In for SBR Administrator Reference - Vasco

Digipass Plug-In for SBR Administrator Reference - Vasco

Digipass Plug-In for SBR Administrator Reference - Vasco

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

<strong>Digipass</strong> <strong>Plug</strong>-<strong>In</strong> <strong>for</strong> <strong>SBR</strong> <strong>Administrator</strong> <strong>Reference</strong> Set Up Active Directory Permissions<br />

<strong>Digipass</strong> User Account Link – the link attribute used to share a <strong>Digipass</strong> between two<br />

user accounts<br />

<strong>Digipass</strong> User Account Stored Password – the Stored Password attribute<br />

Write permission <strong>for</strong> any individual properties on <strong>Digipass</strong> objects, except <strong>for</strong> one<br />

Property Set that is defined to control the <strong>Digipass</strong> assignment link<br />

Write permission <strong>for</strong> any individual properties on <strong>Digipass</strong> Application objects, except <strong>for</strong><br />

one Property Set that is defined to include the <strong>Digipass</strong> 'blob' that is required <strong>for</strong> any<br />

administrative operation such as Reset PIN, Test, Set Event Counter, etc.<br />

Create and delete permission on <strong>Digipass</strong> and <strong>Digipass</strong> Application objects (note that this<br />

can be necessary <strong>for</strong> assigning <strong>Digipass</strong> to users, because a move from one location to<br />

another is controlled by permissions to delete from the source and create in the<br />

destination)<br />

5.2.4 System <strong>Administrator</strong>s<br />

The term 'System <strong>Administrator</strong>' is used here to refer to an administrator who will be<br />

responsible <strong>for</strong> management of the Component and Policy records, rather than <strong>Digipass</strong> User<br />

Accounts and <strong>Digipass</strong>. They need permissions within the <strong>Digipass</strong> Configuration Container to<br />

create, modify and delete Component (vasco-Component) and Policy (vasco-Policy) objects.<br />

<strong>In</strong> practice, System <strong>Administrator</strong>s can typically be given full control over the <strong>Digipass</strong>-<br />

Configuration container. If you wish to grant more limited permissions, this can be handled<br />

with the standard Active Directory permissions on these objects within the scope of the<br />

container.<br />

5.3 Assign Administration Permissions to a User<br />

Note<br />

This example assumes that the administrator's User account has read<br />

permissions <strong>for</strong> all User records already.<br />

To grant permissions to manage <strong>Digipass</strong> records, you will need to follow these steps:<br />

1. Right-click on the Organizational Unit in which to assign permissions.<br />

2. Select Delegate Control... from the right-click menu.<br />

3. The Delegate Control Wizard will be displayed.<br />

4. Select the User or Windows Group to assign permissions.<br />

5. Click on OK.<br />

6. Select the Delegate Common Tasks option button.<br />

7. Select Create, Delete and Manage <strong>Digipass</strong> from the list.<br />

8. Click on Next.<br />

9. Click on Finish.<br />

If you wish to grant permissions to modify <strong>Digipass</strong> User Account properties, you will need to<br />

follow these steps:<br />

© 2006 VASCO Data Security <strong>In</strong>c. 64

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!