• Talking about SPP SaaS and password vault, what happens if there is a network/internet issue?

    Hi all.

    Let's say an application uses SPP SaaS password vault in order to consume and rotate service account passwords.

    What happens if there is a network/internet issue and the application cannot reach SPP SaaS? The application is still working since…

  • Safeguard SSH key Authentication support

    Dear Community,

    I'm currently working with a Safeguard environment running version 8 LTS. We have a scenario where a user accesses an SSH asset using their username and an SSH private key without a password.

    During asset onboarding, I added the SSH…

  • Rewrite account name in a credentialstore plugin

    Hi,

    We are trying to rewrite the account name that are used when logging in to a server, as we are planning to implement SRA and prefer personal user accounts.

    When a user is requesting a root account we have crated a aa plugin that looks for a requestable…

  • Backup & Restore from SPP Virtual Appliance to Hardware Appliance

    Hi,

    soon we will need to migrate the configuration from a 3 node SPP cluster that is virtualized to a 3 node hardware cluster.

    Sticking to documentation, this migration is not possible (but it is if done the other way), so i would like to ask: is there…

  • LDAP Filter on Asset Discovery

    Hi,

    i was wondering how does the LDAP Filter on Assets Discovery does work.

    The use case is to exclude a specific sub-OU from the discovery but the filter seems only responding to parameters like CN, Description, IP, ecc....OU= is not among them.

     Would…

  • Login is required 2 times in SPP

    Hi,

    some users when logging in SPP via MFA need to do the procedure 2 times before going into SPP console.

    So they access SPP via the HTTPS link, log in the first time, gets redirected on the login page, login again and this time they can get into the…

  • SPP procedure for Directory Account password change

    Hi,

    recently we have been experiencing a problem with Domain Service Accounts to manage Directory Accounts on SPP.

    Seems like that minimum privileges are not enough to change and verify directory account secrets. It only works when the service account…

  • Integration SPS and DB

    Hello everyone,

    i'm trying to integrate DB ans SPS, and the aim is to let user access the db with the domain credentials, connected with SPS/SPP. I'm using a trasparent configuration, so I need a jump host server, where I already installed most of…

  • Using different ports on various Connections Policies

    Hi all,

    I am configuring an onDemand environment with 2 different connection policies on SPS for both RDP and SSH.

    The 2 SSH policies use port 22 and 2223 to determine which connection needs to be used.

    On SPP i am configuring an SSH asset with SSH…

  • Software download

    Hi Guys,

    Where can I download Think Client Desktop for SPP?

  • Asset massive updates

    Hi all,

    i need to change the field "Session Port" for around 200 assets. I have been trying doing it by CSV import, but seems like it is not meant for updates.
    Is there a way to modify the field in mass? Otherwise is the only solution modifying…

  • Documentation to how integrate SAP R3 at the application level

    Hi,
    I’m looking for information on how to integrate SAP R3 at the application level, or another legacy system, into One Identity Safeguard SPP and SPS. I looked within the One Identity documentation however, I haven’t found anything related, only references…
  • Is there an Audit Log reader for Archived SPP Audit Logs that have been archived?

    When the SPP Audit logs are archived, Audit Logs are stored in the Archive server and removed from the Appliance.

    Do we have an app/reader that can process the Archived SPP Audit logs? the archived audit logs are in JSON format and it's a lot of columns…

  • Access Request Workflow Events for Integration of SPP with IBM QRADAR SIEM

    Dear Community,

    We are integrating SPP with our IBM QRADAR SIEM solution and would like to understand which events from the Access Request Workflow can be forwarded to the SIEM. I have attached a screenshot where the SIEM team has pulled information from…

  • SPP and SPS upgrade

    Hello,

    we currently have an SPS cluster and an SPP cluster linked together. We need to upgrade the appliances; is it possible to do this without causing cluster downtime, or will the sessions not be functional?

    Thank you

  • API calls to create assets

    Hello all.

    I have been trying to automate asset creation on my SPP solution, and my goal is to have the appliance automatically generate and deploy the SSH key for the service account.

    I am able to generate correctly the asset (and the related accounts…

  • Change managed AD account filed

    when trying to change AD managed user password I got an error 

    Connecting with asset AD Server(xxxxxx).

    Looking up user information for XXXX.

    Changing password for account XXXX.

    Connecting to asset AD Server (xxxxxxx) failed with error: The filename…

  • One-Identity PAM

    Dear Team,

    Are there any implementation activities questioners for new implementations including all systems prerequisites and required user privileges from different managed systems?

  • Name field filled with the name of the asset in discovery

    Good morning guys, do you know if it is possible to bring the server name instead of the IP when doing network discovery? DNS is working ok. 

  • Integration with Arbor Servers

    Dears, 

    I am integrating SPP with a machine that has the ArbOS operating system (A proprietary operating system created by Netscout). However, after contacting support, I knew that the initial shell that open when someone tries to login to the server is…

  • Procedures to migrate a PAM ecosistem from a tenant to another

    Hi,

    i was wondering if there is a best practice that permits a client to transfer all the data from one appliance to another, even from different types of environments (i.e from onPrem to onPrem, from onPremo to onDemand, from onDemand to onDemand)

    Lets…

  • Discovery Job Timing

    I'm curious to know exactly how the scheduling of Discovery Jobs works, and if it can be predicted when a job will run in a massive environment.

    I'm working with a customer that has some 100k Assets just to give an idea of the scale. When we schedule…

  • How to link AD users account with Join Domain assets?

    Hi Community,

    I have a Safeguard Privileged Password (SPP), created AD users as SPP users so they can request a password to access the RDP session to joined domain Windows Servers, respectively the can you use account for access the assets (joined domain…

  • CAL Licenses for RDS Server for RDP Application implementation

    Hello,

    i was wondering how the access to the RDS Server is managed when implementing RDP Apllication protocol, in particular i'm talking about simultaneous access by using a single account.

    Usually we specify in the entitlement which user is going…

  • CISCO ISE support

    Hello,

    from documentation (https://support.oneidentity.com/it-it/technical-documents/safeguard-for-privileged-passwords-on-demand/hosted/administration-guide/3#TOPIC-1757313) i see that platform CISCO ISE is supported by SPP.

    Though the supported versions…