PRiSM Security. Configuration and considerations



Similar documents
Secure Global Desktop (SGD)

Desktop Web Access Single Sign-On Configuration Guide

Alert Notification of Critical Results (ANCR) Public Domain Deployment Instructions

Please note that a username and password will be made available upon request. These are necessary to transfer files.

Mapping ITS s File Server Folder to Mosaic Windows to Publish a Website

STATISTICA VERSION 9 STATISTICA ENTERPRISE INSTALLATION INSTRUCTIONS FOR USE WITH TERMINAL SERVER

How To Use Exhange On Outlook On A Pc Or Macintosh Outlook 2007 On Your Pc Or Ipad (For Windows Xp) On Your Ipad Or Ipa (For Your Windows Xp). (For A Macintosh) On A

EMR Link Server Interface Installation

aims sql server installation guide

AVALANCHE MC 5.3 AND DATABASE MANAGEMENT SYSTEMS

Application Note. ShoreTel 9: Active Directory Integration. Integration checklist. AN June 2009

SECURE MOBILE ACCESS MODULE USER GUIDE EFT 2013

Tool Tip. SyAM Management Utilities and Non-Admin Domain Users

Using Internet or Windows Explorer to Upload Your Site

SQL Server Setup for Assistant/Pro applications Compliance Information Systems

9. Database Management Utility

Integrating Webalo with LDAP or Active Directory

SQL EXPRESS INSTALLATION...

Active Directory Integration for Greentree

Propalms TSE Quickstart Guide

Phone Manager Application Support OCTOBER 2014 DOCUMENT RELEASE 4.1 SAGE CRM

Using ELM Reports in WhatsUp Gold. This guide provides information about configuring ELM reports in WhatsUp Gold v15.0

Installation Instruction STATISTICA Enterprise Small Business

Installation Guide v3.0

Using Microsoft Windows Authentication for Microsoft SQL Server Connections in Data Archive

STATISTICA VERSION 12 STATISTICA ENTERPRISE SMALL BUSINESS INSTALLATION INSTRUCTIONS

Crystal Reports Installation Guide

Event Notification Module TM

Fax User Guide 07/31/2014 USER GUIDE

OneDrive for Business from Desktop or Laptop Windows devices

Web Meetings through VPN. Note: Conductor means person leading the meeting. Table of Contents. Instant Web Meetings with VPN (Conductor)...

Remote Desktop Solution, (RDS), replacing CITRIX Home Access

Upgrading from MSDE to SQL Server 2005 Express Edition with Advanced Services SP2

InfoRouter LDAP Authentication Web Service documentation for inforouter Versions 7.5.x & 8.x

Secure Messaging Server Console... 2

STATISTICA VERSION 10 STATISTICA ENTERPRISE SERVER INSTALLATION INSTRUCTIONS

How To Sync Google Drive On A Mac Computer With A Gmail Account On A Gcd (For A Student) On A Pc Or Mac Or Mac (For An Older Person) On An Ipad Or Ipad (For Older People) On

ELM Server Exchange Edition Virtual Archive Mailbox version 5.5

Historical Reporting Client (HRC) User Login Fails

IIS, FTP Server and Windows

How to Create a Delegated Administrator User Role / To create a Delegated Administrator user role Page 1

owncloud Configuration and Usage Guide

Mesa DMS. Once you access the Mesa Document Management link, you will see the following Mesa DMS - Microsoft Internet Explorer" window:

How to FTP (How to upload files on a web-server)

UM8000 Voic System Administration Guide

Querying Databases Using the DB Query and JDBC Query Nodes

Insight Video Net. LLC. CMS 2.0. Quick Installation Guide

Quick Start Guide. Hosting Your Domain

Video Administration Backup and Restore Procedures

Accessing the Media General SSL VPN

ClicktoFax Service Usage Manual

Virtual Code Authentication User s Guide. June 25, 2015

Training module 2 Installing VMware View

Active Directory Requirements and Setup

Deployment of Keepit for Windows

Deploying BitDefender Client Security and BitDefender Windows Server Solutions

CIMHT_006 How to Configure the Database Logger Proficy HMI/SCADA CIMPLICITY

Installing RMFT on an MS Cluster

System Administration Training Guide. S100 Installation and Site Management

How to install and use the File Sharing Outlook Plugin

Xythos on Demand Quick Start Guide For Xythos Drive

Propalms TSE Quickstart Guide

Installation Instruction STATISTICA Enterprise Server

FaxCore Ev5 Database Migration Guide :: Microsoft SQL 2008 Edition

Administration: Users and Roles

LifeSize Control Installation Guide

First Time On-Campus VLab Setup Windows XP Edition

Integrating Trend Micro OfficeScan 10 EventTracker v7.x

FTP Use. Internal NPS FTP site instructions using Internet Explorer:

Immotec Systems, Inc. SQL Server 2005 Installation Document

6 Oracle Business Activity Monitoring

Initial DUO 2 Factor Setup, Install, Login and Verification

How to Configure Active Directory based User Authentication

CDUfiles User Guide. Chapter 1: Accessing your data with CDUfiles. Sign In. CDUfiles User Guide Page 1. Here are the first steps to using CDUfiles.

Qsync Install Qsync utility Login the NAS The address is :8080 bfsteelinc.info:8080

Managing User Security: Roles and Scopes

How to use SURA in three simple steps:

Configuration Guide. BES12 Cloud

MIGRATING TO AVALANCHE 5.0 WITH MS SQL SERVER

Configuring the Active Directory Plug-in

Using and Contributing Virtual Machines to VM Depot

3 Setting up Databases on a Microsoft SQL 7.0 Server

HWS Virtual Private Network Configuration and Setup Mac OS X 12/19/2006

Changing Your Cameleon Server IP

Webmail Access. Contents

HelpDesk / Technical Support * 1350 Euclid Avenue Ste 1500 * Cleveland, OH *

DEP S REMOTE ACCESS USER GUIDE

CREDENTIAL MANAGER IN WINDOWS 7

Polar Help Desk 4.1. User s Guide

NOTE: Please refer to the LinkNavigator CD-ROM s IP Setup Utility if you do not know the LinkStation s IP Address or Host Name.

Using Windows Task Scheduler instead of the Backup Express Scheduler

Implementing a SAS Metadata Server Configuration for Use with SAS Enterprise Guide

WirelessOffice Administrator LDAP/Active Directory Support

HOW TO SILENTLY INSTALL CLOUD LINK REMOTELY WITHOUT SUPERVISION

Deploying BitDefender Client Security and BitDefender Windows Server Solutions

WatchDox for Windows User Guide. Version 3.9.0

User Guide. UserGuide_VersionCS8.1

Setting Up Scan to SMB on TaskALFA series MFP s.

Binding an OS X computer to Active Directory at NEIU (Existing User)

How do I Install and Configure MS Remote Desktop for the Haas Terminal Server on my Mac?

Transcription:

PRiSM Security Configuration and considerations

Agenda Security overview Authentication Adding a User Security Groups Security Roles Asset Roles

Security Overview

Three Aspects of Security Authentication Who can log into PRiSM Security Groups What items can they view Security Roles What actions can they do

Authentication

PRiSM Users Windows active directory Active directory user Active directory user group Local machine accounts PRiSM Server only Security considerations PRiSM Stores only the windows system identifier (SID) Not usernames Not passwords

Authentication Process 1. Collect SID from client machine 2. Compares SID to PRiSM database List of authorized users and groups List of authorized user groups 3. Active directory server authenticates password 4. Connection is established

Web Authentication PRiSM Server Client Computer Active Directory Server Service PRiSM Client (Desktop) Archive edna Database SQL Oracle PRiSM Web (Browser) LDA P Web Service SID

Client Authentication - Web PRiSM Server Client Computer Active Directory Server Service PRiSM Client (Desktop) SID Archive edna Database SQL Oracle PRiSM Web (Browser) LDAP Web Service

Client Authentication - Local LDAP PRiSM Server Client Computer Active Directory Server Service PRiSM Client (Desktop) SID Archive edna Database SQL Oracle PRiSM Web (Browser) Web Service

Anonymous Authentication Prompted only if current use not authorized in PRiSM database Can modify shortcut with /a command

Adding a User

Administer Users File // Administer Users

Add User

Configure Security Group and Role

Security Groups

Security Groups Restricted View Access Assets Templates Projects Real time services

Full Access Group Grants access to all items Cannot be edited or deleted

New Security Group Administrator defined

Details Group Name Name shown when configuring a user *2.7.2 and below require additional configuration

Assets Allowed Assets Drag and drop from hierarchy to pane on right Add every asset or folder the user will have access to Deleting Click ID Press Delete

Assets Access in Client Users will be able to view all assets

Assets Access in Web Users will be able to view allowed assets only For the most part

Templates Allowed Templates Check Allow

Templates Access Application Users will be able to view allowed templates only

Templates Access Application Users will be able to associate allowed templates only Users can still view projects with associated to restricted templates

Project Access Access to projects determined by asset and template access Asset (Default configuration) Both Asset and Template Either Asset or Template

Project Access Example Asset Only The user has been given asset to Allowed Asset Allowed Template Allowed Asset Project No Template Project Allowed Template Project Restricted Template Restricted Asset Project No Template Project Allowed Template Project Restricted Template

Project Access Example Both Asset and Template The user has been given asset to Allowed Asset Allowed Template Allowed Asset Project No Template Project Allowed Template Project Restricted Template Restricted Asset Project No Template Project Allowed Template Project Restricted Template

Project Access Example Either Asset or Template The user has been given asset to Allowed Asset Allowed Template Allowed Asset Project No Template Project Allowed Template Project Restricted Template Restricted Asset Project No Template Project Allowed Template Project Restricted Template

(Non-derived Template) Useful with Both Asset and Template or Either Template or Asset configurations For project access grants the lack of a template is considered the project s template

Real Time Services Access Users will be able to view allowed real time services only Points Data

Service vs Service Type Service Access to specific services Service Type Access to all services Current Future

RTS Access Application Project point additions

RTS Access Application Historical Data Import

RTS Access Application Trending Actual (Source RTS) cannot be used All users will always have access to prism history

Members List of users assigned to the security group

Security Roles

Administrator Administrator Full system access All explicit roles Additional roles

User User Access Projects Templates Alarms Annunciators User Restrictions System settings Service configuration User management Asset management Notification management

Read Only Read Only Access View Projects View Templates View Alarms View Annunciators Read Only Restrictions System settings Service configuration User management Asset management Notification management

Custom Custom Roles Administrator configured No limit in count

Role Details Client login Allows user to log into PRiSM Client Web login Allows user to log into PRiSM Web Modify Projects Create, edit, and delete projects Modify Templates Create, edit, and delete templates Clear Alarms (Manage Alarms) Change alarm status or clear alarms

Role Details Quick Train The allows users to quick train projects Also requires modify projects Modify Annunciator Panel Create, edit, and delete annunciator panels Modify System Preferences Edit system preferences in PRiSM client Edit system preferences in PRiSM web Modify User Preferences Edit user preferences in PRiSM client Edit user preferences in PRiSM web

Role Details Modify Real Time Services This allows users to configure RTSs Service administration and agent administration Modify Web Services This allows users to define external web data services Modify Local Configuration This allows users to open the local configuration file though the about screen and the local hosts file from the edna Configuration Screen Modify User Libraries This allows users to access system calculation libraries

Role Details Manage Notifications This allows access to the general notification settings, notification format, and manage notification only account subscriptions. Manage Assets This allows access to the asset management screen and controls access to create new folders when changing project s asset folder. Manage Users This allows access to the user management screen for managing users, roles, and security groups and notification-only user accounts.

Additional Administrator Role Access Administrator Automatic model building Digital point definitions

Asset Roles

Asset Role Allows a user s role to be different in specific assets Example usage User s default access is read only In a specific asset has user access Training sandbox for learning prism No disruption to production projects

Asset Role Create Asset Role

Asset Role Configuration asset role

2015 Schneider Electric Software, LLC. All rights reserved.