Manual Policy Configuration
This process normally runs automatically, so the manual configuration below is not required. It is optional. For information on the automated process, see Step 2: Secure Access.
For more details about these settings, see Identity Policies.
Follow the steps below to manually configure the platform for allow-list authentication, similar to existing Secret Server behavior. The steps configure an Allow List identity policy that mirrors the default policy but is scoped to a specific group membership so that only the specified users can meet the profile. You can then set the default policy to deny access to any users who do not meet the new profile that is configured.
-
Navigate to the Groups page.
-
Create a new group.
-
Name the group to indicate that it defines all users who can authenticate to the platform, such as Acme Platform Users.
-
Add the cloudadmin user to the group
-
Add any other users that are currently using the platform to the group, either directly or by a group that they are a member of.
-
Navigate to the Identity Policies page.
-
Add a new policy.
-
Name the policy to indicate that it will control how most users authenticate to the platform, such as Acme Default Authentication Policy.
-
Leave the policy disabled.
-
Add a description if desired.
-
Target specific groups, and select the group that was configured above.
-
In the new policy, click the Authentication tab.
-
Edit the Services section.
-
Enable authentication policy controls.
-
Set the Default Authentication Profile to Default Other Login Profile.
-
Save the section.
-
-
Edit the Authentication Rules section.
-
Add a rule named, Identity cookie is not present.
-
Select the Default New Device Login Profile.
-
Add a filter by selecting Identity Cookie and setting Is not present for the condition.
-
Save the filter, rule and section.
If saving any of these settings causes an error:
-
Ensure that all steps above have been completed correctly,
-
Ensure that the cloudadmin user can meet the requirements of the two authentication profiles configured above.
-
-
-
Open the Overview tab and enable the policy.
-
Navigate back to Identity Policies.
-
Edit the default policy.
-
Open the Authentication tab and edit the Authentication rules section.
-
Select the row and delete any authentication rules.
-
Save the section.
-
Edit the Services section.
-
Set the Default Authentication Profile to Deny platform authentication.
-
Save the section.