System Administration (New UI)
This guide highlights features available only to System Administrators in the new UI. System Administrators have full access to the server, including managing users, configuring access rules and services, managing credentials, updating server settings, and controlling user permissions.
Admin Log
The Admin Logs section is available only to System Administrators. It provides an overview of both system-level messages and higher-level user activity on the server. By default, messages are listed in descending order by date (most recent first), and have the following properties:
| Admin Log Property | Description |
|---|---|
| Time | The time stamp when the event or message was generated. |
| User ID (User Activity only) | The User responsible for generating the message (only in User Activity). |
| Method | A noun (For example, DEBUG, INFO, ERROR) for system messages or a verb (For example, CREATE, UPDATE, DELETE) for user activity. |
| Object Type | A tag indicating the type of object or event associated with the message (For example, User, Customer). |
| Object Key | The system-wide unique identifier for the object related to the message. |
| Details | A human-readable note containing further details about the log message. |
Above the Admin Log records, you can see a list of available methods to filter the logs.
Use the Methods options to quickly filter the Admin Log records. Click All to clear the filter.
Methods may differ depending on the type of records being displayed.
System messages are generated by the server itself and are not attributable to any specific user. Therefore, User ID is not present in System Messages. These messages include system logins, login failures, debug information, password resets, and Desktop Sharing video recording management information.
The User Activity section of the Admin Logs helps determine "who's doing what" within the system. While the Activity Reports show the actions taken by users when connected to a Gatekeeper, the User Activity section specifically tracks changes made to system objects.
System Settings
The System Settings page enables you to view and add authorized domains, establish a custom form, manage customer credentials, set your server to maintenance mode, set expiration time for a session in your server, set Best Practices, share audit logs with a syslog server, and change your Connection Manager encryption preference.
The following sections provide details on each section in the System Settings page.
As its name suggests, the Authorized Domains section contains a list of all the domains (@domain.com) that a user's or customer's email can have to access your server. The system displays these authorized domains in the New and New User forms. Only System Admins can add, remove, and set domains as primary.
To create an authorized domain:
-
Click Add.
-
Type the domain after the @ symbol.
Instead of "@company.com", type "company.com". -
Click Save.
To remove an authorized domain, click Remove in the domain list. The system must have at least one authorized domain at all times, so you can only remove domains when you have created a new domain, and have set it to Default.
To set a domain as the Default, select Set as Default in the domain list. The domain moves to the top of the list.
Maintenance Mode disables access to the server to non-administrator users. When you set your server in Maintenance Mode, the system displays a customizable message that your non-admin users will see when trying to log in to the server.
Select the Schedule end of maintenance mode at: option to provide access to your users at a specific date and time. If you do not set an end date, a System Admin must Disable the maintenance mode manually in this same page.
The system effectively disables access 10 minutes after you click Save.
Syslog Server enables you to export audit and system events to an external server running the Syslog service.
If you are an Imprivata Cloud customer, read the Syslog Configuration for Cloud Customers section before you continue with this process.
Imprivata Cloud customers may not be able to configure the Syslog Server directly through the System Settings page of their server. Before you continue with your Syslog Configuration in the System Settings page, you must first:
-
Navigate to System Admin > Settings > Tunneled Services.
-
Create a new tunnel service for your Syslog server.
-
Provide the following information
-
Description: Provide a description for the service.
-
Host Name: Provide the DNS or FQDN of the syslog server.
-
Port: Set the default port 514 or alternate port for your syslog server.
IMPORTANT:If you use the default port 514, no additional configuration or assistance is required. However, if you specify a non-standard port, you must contactImprivata Support to open the corresponding firewall port to enable connectivity
-
Protocol: Select UDP as the syslog server protocol.
-
-
Save the service.
To configure the Syslog Server Setting:
-
Select the type of server protocol you want to use.
-
Provide the system with the IP Address or hostname of the server.
If you have not configured DNS resolution in your server, it is recommended to use IP Addresses, instead of host names when specifying a syslog server. -
Specify the communication port.
If no port is specified, port 514 is assumed.IMPORTANT:If you use the default port 514, no additional configuration or assistance is required. However, if you specify a non-standard port, you must contact ImprivataSupport to open the corresponding firewall port to enable connectivity.
The options RFC-5425 (TCP, with TLS) and RFC-3164 (TCP, with TLS) enable you to add more secure, flexible, and standards-compliant event logging across varied network environments. These options activate the following sections:
-
Syslog Server SSL Settings: The system enables you to either upload the syslog server SSL certificate or disable the verification.
-
Client Authentication Settings: The system enables you to use client authentication settings that require you upload the keystore file and password.
The Syslog Server Setting requires you to meet one of the following requirements:
-
The configuration leverages and uses tunneled services to work properly.
-
Imprivata Support assists you in opening a firewall port to allow connectivity.
The Connection Manager Cipher Preference setting enables you to express a preference for the encryption cipher used in the Connection Manager when users connect to the sessions. Since export control may limit the available ciphers for some users, a small amount of users may fall-back to using a cipher with a shorter key length than the expressed preference. recommends 128-bit AES as a compromise between connection efficiency and security appropriate for most systems.
Custom Forms & Fields
For more information, see Custom Forms.
System Messages
System Messages enables you to configure messages for your user and your customers.
The System Message opens as a banner across the top of the Login page, or optionally on every page. This is useful to notify Users of upcoming system downtime or system policy changes. You can select when to start and stop displaying the message, the display location and set the text and background colors of the message. To delete a message, clear the Message area and click Save.
The Login Page Note appears as a notice on the Login page. This is useful to provide information to everyone prior to login. You can use HTML in the note, which is sanitized before display to prevent dangerous tags.
Login Help Contact Information appears as a help contact information in Authorization when a key is requested right after being authenticated in Login, and in forgot password. This is useful to provide information about who to contact in case the authorization key is not received or the password is forgotten. You can use HTML in the contact information, which is sanitized before display to prevent dangerous tags.
Support Contact Statement allows you to customize the contact information on the footer of the emails sent by the application. The default values are a general contact email and phone number. You can update one or both values to reflect specific internal support routes, such as a help desk or administrator.
The Feedback Email specifies the email address that receives notifications when users submit Report a Problem issues or Vendor Feedback. This is useful to ensure feedback is routed to the appropriate support or administrative team.
API Keys
The API Keys page enables you to create, edit, reset, and expire API Keys. To create an API Key, click New API Key. After you complete the New API Key format, the system displays a pop up with the newly created API Key.
Copy and safe-keep the API Key, as it can not be seen again.
After you close pop up, you can Edit, Reset, and Expire the API Key.
Email Notification Lists
Set up recipients for:
-
Significant Server Events: Use the Administrator List to notify relevant users and system administrators of changes or alerts.
-
Reports Distribution Lists: These lists define groups of email addresses that will receive the reports automatically.
For more information, see Reports.
Tunneled Services
For more information, see Tunneled Services.
Best Practices Checklist
For more information, see Best Practices Checklist (new UI) or Best Practices Checklist (Legacy UI)
Device Security & Health
Select the Security Settings you want to evaluate and define the strictness level for each. Any settings not selected will be excluded from the check.
For more information, see Device Security & Health.