Access Management administration
This topic outlines the tasks that are part of the role of an administrator responsible for the HelloID Access Management.
Monitoring
Monitor HelloID using the built-in mechanisms; see HelloID administration.
Review notifications about expiring certificates.
Review Access Management reports.
Resolve Incidents:
Troubleshoot a failed Directory sync.
The Agent is down:
Restart the Agent services.
Make sure the necessary domains are whitelisted.
Verify that the agent has been updated to the latest version. If necessary, Manually update an Agent.
Ensure the agent is running with a service account that has sufficient permissions. See Agent requirements.
Monitor the use of licenses via the License widget on the Admin dashboard.
Monitor all systems and applications connected to the Access Management module.
Review and update certificates.
Tip
Ensure procedures are in place to replace certificates before they expire, to prevent downtime in the Single Sign-On (SSO) connections.
Monitor the organization for changes that may affect the configuration of HelloID Access Management.
The Access Management configuration helps you discover and regularly check the relevant details of your HelloID Access Management configuration.
Troubleshooting
For user management tasks and issues, see HelloID tenant and user administration.
- 1. An application is inaccessible.
- 2. A certificate is about to expire.
- 3. The use of licenses is exceptionally high.
1. | An application is inaccessible. | ||||||
| |||||||
2. | A certificate is about to expire. | ||||||
ImportantReplace the certificate before it expires. SAML and WS-Federation-based Single Sign-On (SSO) applications may continue to function with an expired certificate, although this is not recommended. OpenID Connect, however, requires a valid (i.e., unexpired) certificate. Depending on the supplier, the certificate might need to be added manually, or it may update automatically using metadata (a "well-known configuration" document), which is refreshed every few minutes or hours. If you only update the certificate in HelloID and not on the supplier's side, it may cause downtime for the SSO connection. | |||||||
3. | The use of licenses is exceptionally high. | ||||||
Note: By default, new applications are added to the Users group. This means the application can be assigned to all synced users, even if they do not use HelloID Access Management. This may lead to extra license costs, because each user uses a license as soon as the application is assigned.
|
Helpdesk tasks/maintenance
- 1. An application must be temporarily disabled or hidden.
- 2. An application must be added, edited, or removed.
- 3. SSO claims need to be adjusted for an application. For example, instead of an email address, the employee ID must be sent to the application.
1. | An application must be temporarily disabled or hidden. | ||||||
| |||||||
2. | An application must be added, edited, or removed. | ||||||
3. | SSO claims need to be adjusted for an application. For example, instead of an email address, the employee ID must be sent to the application. | ||||||
|