Vendor Onboarding Guide

Vendor Privileged Access Management (VPAM) is an Imprivata application that enables you to provide secure support through remote connections, known as sessions. The remote sessions connect you, a vendor representative (or Vendor Rep), to your customers assets. Your customers assets might include their data, their services (such as Software, Infrastructure, and Platforms), or their applications.

As a Vendor Rep, you connect to their assets through custom Gateway applications that your customer configures for you. All of your activities in their assets are monitored by the VPAM server to provide detailed activity logs and ensure asset safety. Features available to you depend on your assigned role and the configuration defined by your customer.

This guide describes the process to connect to your customer's VPAM server and initiate sessions to provide remote support. This guide contains the following topics:

Workstation System Requirements

Vendors and Vendor Reps must meet the following system requirements to access their customer's VPAM server:

  • System Requirements

    • Java 8

    • 1 GHz of CPU

    • 1 GB of disk space

    • 200-250 MB for application installation, backups, and logs

    • 500 MB of free space for future upgrades

    • 512 MB of RAM

  • Network Requirements

    • Outbound ports SSH (22), HTTP (80), and HTTPS (443).

  • Supported Operating Systems

    • Windows 10 and 11

    • Red Hat (including Alma, CentOS, and Rocky) 8 and 9

    • Ubuntu 20.04, 22.04, 24.04

    • SUSE Enterprise Server 10, 11, 12, 15, 15.5

    • Unix

  • Supported Web Browsers

    • Microsoft Edge

    • Google Chrome

    • Mozilla Firefox

    • Safari

Vendor Self-Registration

IMPORTANT:
To use the Vendor Self-Registration, your customer must enable this feature in their VPAM server. Some VPAM customers may not to enable self-registration, so reach out to them and ask to have a new Vendor Rep user account created for you.

VPAM System Administrators can enable the Vendor self-registration, shown in the UI as the Vendor Representative Registration. This self-registry enables you to log in to your customer's VPAM server by registering your company email and completing an information form.

Start your Vendor Self-Registration by clicking Vendor Representative Registration:

Complete the self registration form:

IMPORTANT:
Use your personal company email address, as VPAM customers place security restrictions to generic addresses (such as sales, support, or similar) and email domains (such as @gmail.com, @yahoo.com).
NOTE:
The email, name fields, and CAPTCHA fields are mandatory.

When you complete your registry, you will receive an Account Activation message to the email you input in the form.

Access Your Account

Accessing a Vendor Rep VPAM account requires you to have an email address with a domain associated to a Vendor organization. The Vendor-associated email is always the Vendor Rep's User ID.

The Vendor Rep email or User ID is set up either:

  • During the Vendor Representative Registration workflow, or

  • During the Vendor and Vendor Rep setup by the VPAM System Administrator.

Session Types

Depending on your customer's configuration of their VPAM server, Vendor Reps can have the following types of sessions:

Credentials

During a session, Vendor Reps can run services in their customer's assets. Depending on the Session Type, you can run Different Services.

Some services in a session may require credentials for accessing and using the service. The required credentials are never directly available nor visible for Vendor Reps, as they are stored in the customer's vault.

Depending on the configuration of the VPAM server, some of these credentials can be automatically and secretly injected into the services that you use.

The following table outlines if a service uses credential injection:

Service Type Connection Manager Session Browser-Based Session
RDP Yes Yes
SSH Yes Yes
Telnet Yes Not available
FTP / SFTP Yes Not available
VNC & Desktop Sharing Yes Not available
HTTP / HTTPS Partially Not available
Database Services

No

Not available
Custom Services No Not available
NOTE:
  • HTTP / HTTPS credential injection is possible, but with several limitations. Reach out to your VPAM System Administrator with further questions.
  • Database and Custom Services do not support injection of credentials, so manual login will be required.