0% found this document useful (0 votes)
718 views7 pages

IBM SAM E-SSO Server Policies Best Practices For PoTs and PoCs

This slide deck gives an idea of what configurations and policies should be set for a typical IBM SAM E-SSO Proof of Concept/Proof of Technology.

Uploaded by

IBMSAMESSO
Copyright
© Attribution Non-Commercial (BY-NC)
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd
0% found this document useful (0 votes)
718 views7 pages

IBM SAM E-SSO Server Policies Best Practices For PoTs and PoCs

This slide deck gives an idea of what configurations and policies should be set for a typical IBM SAM E-SSO Proof of Concept/Proof of Technology.

Uploaded by

IBMSAMESSO
Copyright
© Attribution Non-Commercial (BY-NC)
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd
You are on page 1/ 7

IMS Server Policies and Configuration Quick Guide for PoCs

IBM Tivoli Access Manager for Enterprise Single Sign-On : IMS Server Policies and Configuration Quick Guide for PoCs

2009 IBM Corporation

Configuration Utility accessed at http://<tamesso_server>/webconf

Provision First User Provision IMS administrator (ensure that the user is in AD/LDAP before this) AccessAdmin->User Interface Policy assignment attribute : memberOf (if you want to use AD group as the assignment attribute) Enable delete user button: Enabled Length of the authorization code, in characters: 4 AccessAdmin->Login Allow form-based login to AccessAdmin from remote machine: True

2009 IBM Corporation

User Policy Template in AccessAdmin

AccessAssistant and Web Workplace Policies Second factor authentication required.. : No Display personal authentication : No Wallet Policies Enable automatic sign-on for personal authentication services : No

2009 IBM Corporation

Machine Policy Templates in AccessAdmin

Sign Up Policies Enable Automatic Sign-Up AccessAgent Policies->Display Policies AccessAgent feedback link: <company_email> AccessAgent Policies->Engina Policies Enable Application Launch from EnGINA: Yes Display Label for Application Launch: I forgot my password Command line for application launch: C:\Program Files\Internet Explorer\iexplore.exe k http://<tamesso server name>/aawwp/app/reset_password_front_page.jsp AccessAgent Policies->Desktop Inactivity Policies Desktop Inactivity Action: Lock Computer AccessAgent Policies->Logon/Logoff Policies Enable TAM ESSO Network Provider
2009 IBM Corporation

System Policies in AccessAdmin

Password Policies->Password Change Policies Force provisioned users : No Self-Service Policies->Self-Service Registration and Bypass Enable self-service registration : Yes Wallet Policies Wallet caching option : Always cache Default automatic sign-on password entry option : Automatic Logon Enable automatic sign-on for personal authentication services : No Enable auto-learning: No Sign Up Policies Option for specifying secret : Secret not required

2009 IBM Corporation

Authentication Service Policies in AccessAdmin

Ideally, for most authentication services Default automatic sign-on password entry option to Automatic Logon

2009 IBM Corporation

Recommendations?

Email Archit Lohokare, Product Manager at [email protected]

2009 IBM Corporation

You might also like