Symantec IGA

 View Only
  • 1.  Select Endpoints for Password Propagation

    Posted Aug 28, 2016 04:50 AM

    Hi,

    Is there a way to select or specify endpoints for password propagation after password reset event?

    Arij



  • 2.  Re: Select Endpoints for Password Propagation

    Posted Aug 29, 2016 05:31 PM

    Hello Arij,

     

    My understanding is if you have endpoint A, B and C. You only want passwords to update on endpoints A and B on a password reset and not C? On the accounts tab, there are options for you to look at to see if these are something that would work out for you.

     

    A option I see is "Account is sensitive and cannot be delegated". Would this be something that could be possible for you? If these options aren't what you are looking for, I can look into other suggestions for you.

     

    Thank you,

    Andrew Nguyen



  • 3.  Re: Select Endpoints for Password Propagation

    Posted Sep 02, 2016 08:41 PM

    Hello Andrew,

    The option "Account is sensitive and cannot be delegated" will not allow the credentials to be used by even trusted applications.

    Moreover this is an option set in a account template, and is good only at creation time.

    I would love to hear your further suggestions and ideas.

    Thank you,

    Arij



  • 4.  Re: Select Endpoints for Password Propagation

    Posted Aug 30, 2016 04:05 AM

    Hi Arij,

     

    In the provisioning manager, look at the endpoint properties - right click or double click on your endpoint. In the 'Endpoint Settings' tab, you will see an option called "Disable password propagation to accounts'. All password updates to all users in that endpoint will not take place. 

     

    Cheers,

    Marline



  • 5.  Re: Select Endpoints for Password Propagation

    Posted Aug 30, 2016 09:32 AM

    Hi Marline,

     

    That setting would be endpoint-wise. I'm looking for fine-grained user-level control.

    Based on business logic, we want to be able to select endpoints for password propagation dynamically for each user.

     

    Thank you,

     

    Arij



  • 6.  Re: Select Endpoints for Password Propagation

    Posted Aug 30, 2016 11:47 PM

    Hi Arij,

     

    Correct. This is endpoint wide. There is no capability to do fine grained selection.

     

    Regards,

    Marline