Settings

The System Admin Settings menu provides in-depth configuration to your VPAM server. From this menu located in the System Admin tab, you can manage your entire server's behavior. This document contains the different configurations available for your VPAM System Admin.

To view all the settings, navigate to the System Admin tab and hover the Settings menu.

The available settings are:

  • System Settings

  • Plugin Settings

  • AD/LDAP Settings

  • SAML Settings

  • Passwords & Accounts

  • System Messages

  • Report Distribution Lists

  • Mail Settings

  • User Fields

  • Host Fields

  • Field Patterns

  • Vendor Connection Forms

  • Approvals

  • Global Host Groups

  • Tunneled Services

  • Best Practices Checklist

  • Archiving and Pruning

System Settings

The System Settings page enables you to view and add authorized domains, establish a custom form, manage customer credentials, set your server to maintenance mode, set expiration time for a session in your VPAM server, set Best Practices, share audit logs with a syslog server, and change your Connection Manager encryption preference.

The following sections provide details on each section in the System Settings page.

Plugin Settings

The Plugin Settings provide options for System Admins to configure Privileged Access Management (PAM) provider plugins. In this page, you can start and stop PAM providers plugins, or create a new PAM Server Configuration.

AD or LDAP Settings

The Active Directory (AD) or Lightweight Directory Access Protocol (LDAP) Settings enable you to set AD or LDAP Credentials from an AD or LDAP provider. This feature facilitates the authentication of your VPAM server users by pulling their identity and credential from and AD or LDAP provider. Additionally, this page enables you to set a default user role and user group for users that sign in to your VPAM server using the linked AD or LDAP provider.

SAML Settings

The SAML Settings page contains the configuration of SAML in your VPAM server. You can upload your Identity Provider Metadata to configure SAML.

Passwords & Accounts

The Passwords & Accounts enables you to configure settings for user accounts, passwords, physical devices, Remote Desktop Protocol (RDP), authentication requirements, authorized networks and API Keys.

System Messages

System Messages enables you to configure messages for your VPAM user and your customers.

Report Distribution Lists

Your VPAM server enables you to create distribution lists to share specific reports with key people in your organization.

To create a distribution list, click New Report Distribution List. Type the emails of the people who receive the report. When you finish, click Save.

These users will receive reports set in your Reports tab.

Mail Settings

Mail Settings has the connection information for sending an email. Only two protocols are supported: SMTP and TLS. Typically SMTP is port 25, and TLS is port 587. SSL (port 465) is not supported since it has been replaced by TLS.

Up to three different mail servers can be configured. The Primary Mail Server is the preferred one. This provides some resilience in the mail delivery service. In case VPAM is not able to connect to the primary server, it uses the First Backup Mail Server to send emails. In case the First Backup Mail Server is not usable, VPAM tries the Second Backup Mail Server instead.

Test emails can be sent from the Mail Settings section. This makes it easy to verify that the mail settings for each server are correct before saving the configuration.

Custom Fields

Custom Fields are created and edited by System Admins to allow additional data to be kept about Users and Hosts.

Field Patterns

Field Patterns are used in multiple areas of the system including Custom Fields and Connection Forms. Field patterns consist of four pieces of information.

Vendor Connection Forms

Vendor Connection Forms are customizable formats that you create to obtain information from the VPAM user that initiates a connection to an Application and starts a session through the Connection Manager. The format helps you and your customer to track all the connections and sessions between your VPAM server, your VPAM users, and your customers.

To create a connection form, click New and provide a unique name and description for your connection form. After your connection form is created, you can click View to add fields that may or may not have a Field Pattern.

After you finish editing your connection form, navigate to the System Settings to set is as default.

Approvals and Approval Profiles

When a vendor rep's access has expired, the next time they log in they are placed into an approval queue. This section contains the actions to review and approve requests, and the approval profiles you can configure for your vendors and applications.

Global Host Groups

The Global Host Groups feature provides the capability to create Global Host Groups that can be applied to Gatekeeper hosts by VPAM System Admins.

When editing a Gatekeeper host, the VPAM Administrator can assign a Global Host Group to the host from the list of Global Host Groups.

When a Vendor Rep connects to a Gatekeeper, is able to group the hosts together by their Global Host Group, to help organize Gatekeepers with many hosts, as opposed to simply sorting all hosts alphabetically when grouping is not used.

Users are also able to show/hide groups to display only the groups they are interested in.

Best Practices Checklist

This feature checks and reports the status of several system settings. Each option displays whether or not the recommended setting has been met. An overall score is assigned based on the number of passing checks.

The administrator is allowed to accept the current score, or fix the settings with a click on the individual checks.

Once the minimum score has been accepted, when any setting is modified that lowers the accepted score, the administrator is notified of this with a message that remains at the top right of each page. To remove this message, the administrator may click on it and accept the new score.

Administrators can also select the individual compliance levels they want their server to comply to, between different compliance regulations. We try to keep these recommendations up to date with the latest legislation.

Archiving and Pruning Audit Files

Archiving and Pruning enables System Admins to: