PageSourceSearch

https://orbisid.com/docs/assets/js/bff97ff1.0aa9ad63.js

js orbisid.com collected 2026-09-25 18:37:00 UTC 10,968 bytes, 1 lines download raw bytes

1"use strict";(globalThis.webpackChunkorbisid_docs=globalThis.webpackChunkorbisid_docs||[]).push([[536],{3164(e,s,n){n.r(s),n.d(s,{assets:()=>l,contentTitle:()=>c,default:()=>h,frontMatter:()=>d,metadata:()=>r,toc:()=>o});const r=JSON.parse('{"id":"target-systems/one-identity-safeguard","title":"One Identity Safeguard","description":"Description","source":"@site/docs/target-systems/one-identity-safeguard.md","sourceDirName":"target-systems","slug":"/target-systems/one-identity-safeguard","permalink":"/docs/target-systems/one-identity-safeguard","draft":false,"unlisted":false,"tags":[],"version":"current","sidebarPosition":34,"frontMatter":{"sidebar_position":34,"title":"One Identity Safeguard"},"sidebar":"mainSidebar","previous":{"title":"Okta","permalink":"/docs/target-systems/okta"},"next":{"title":"Oracle Database","permalink":"/docs/target-systems/oracle"}}');var t=n(4848),i=n(8453);const d={sidebar_position:34,title:"One Identity Safeguard"},c="One Identity Safeguard",l={},o=[{value:"Description",id:"description",level:2},{value:"System Type Classification",id:"system-type-classification",level:2},{value:"Version Support",id:"version-support",level:2},{value:"Supported Protocol",id:"supported-protocol",level:2},{value:"What OrbisID Discovers",id:"what-orbisid-discovers",level:2},{value:"Connection Requirements",id:"connection-requirements",level:2},{value:"Required Permissions",id:"required-permissions",level:3},{value:"Credential Mapping",id:"credential-mapping",level:3},{value:"Network Requirements",id:"network-requirements",level:3},{value:"Configuration Steps",id:"configuration-steps",level:2},{value:"Troubleshooting",id:"troubleshooting",level:2}];function a(e){const s={code:"code",h1:"h1",h2:"h2",h3:"h3",header:"header",li:"li",ol:"ol",p:"p",strong:"strong",table:"table",tbody:"tbody",td:"td",th:"th",thead:"thead",tr:"tr",ul:"ul",...(0,i.R)(),...e.components};return(0,t.jsxs)(t.Fragment,{children:[(0,t.jsx)(s.header,{children:(0,t.jsx)(s.h1,{id:"one-identity-safeguard",children:"One Identity Safeguard"})}),"\n",(0,t.jsx)(s.h2,{id:"description",children:"Description"}),"\n",(0,t.jsxs)(s.p,{children:["The One Identity Safeguard connector uses the ",(0,t.jsx)(s.strong,{children:"Safeguard REST API"})," to discover managed accounts, entitlement grants, and user-to-account access policies within a One Identity Safeguard for Privileged Passwords (SPP) or Safeguard for Privileged Sessions (SPS) deployment. It authenticates using a certificate or username/password and provides complete PAM inventory visibility."]}),"\n",(0,t.jsx)(s.h2,{id:"system-type-classification",children:"System Type Classification"}),"\n",(0,t.jsxs)(s.table,{children:[(0,t.jsx)(s.thead,{children:(0,t.jsxs)(s.tr,{children:[(0,t.jsx)(s.th,{children:"Field"}),(0,t.jsx)(s.th,{children:"Value"})]})}),(0,t.jsxs)(s.tbody,{children:[(0,t.jsxs)(s.tr,{children:[(0,t.jsx)(s.td,{children:(0,t.jsx)(s.strong,{children:"System Type"})}),(0,t.jsx)(s.td,{children:"PAM Tool"})]}),(0,t.jsxs)(s.tr,{children:[(0,t.jsx)(s.td,{children:(0,t.jsx)(s.strong,{children:"Default Scan Priority"})}),(0,t.jsx)(s.td,{children:"500"})]})]})]}),"\n",(0,t.jsx)(s.h2,{id:"version-support",children:"Version Support"}),"\n",(0,t.jsxs)(s.table,{children:[(0,t.jsx)(s.thead,{children:(0,t.jsxs)(s.tr,{children:[(0,t.jsx)(s.th,{children:"OrbisID Edition"}),(0,t.jsx)(s.th,{style:{textAlign:"center"},children:"Supported"})]})}),(0,t.jsxs)(s.tbody,{children:[(0,t.jsxs)(s.tr,{children:[(0,t.jsx)(s.td,{children:"Community"}),(0,t.jsx)(s.td,{style:{textAlign:"center"},children:"No"})]}),(0,t.jsxs)(s.tr,{children:[(0,t.jsx)(s.td,{children:"Pro"}),(0,t.jsx)(s.td,{style:{textAlign:"center"},children:"Yes"})]}),(0,t.jsxs)(s.tr,{children:[(0,t.jsx)(s.td,{children:"Enterprise"}),(0,t.jsx)(s.td,{style:{textAlign:"center"},children:"Yes"})]})]})]}),"\n",(0,t.jsx)(s.h2,{id:"supported-protocol",children:"Supported Protocol"}),"\n",(0,t.jsxs)(s.table,{children:[(0,t.jsx)(s.thead,{children:(0,t.jsxs)(s.tr,{children:[(0,t.jsx)(s.th,{children:"Protocol"}),(0,t.jsx)(s.th,{style:{textAlign:"center"},children:"Port"}),(0,t.jsx)(s.th,{children:"Notes"})]})}),(0,t.jsx)(s.tbody,{children:(0,t.jsxs)(s.tr,{children:[(0,t.jsx)(s.td,{children:"REST API (HTTPS)"}),(0,t.jsx)(s.td,{style:{textAlign:"center"},children:"443 TCP"}),(0,t.jsxs)(s.td,{children:["Bearer token authentication via ",(0,t.jsx)(s.code,{children:"/service/core/v4/Token/LoginResponse"})]})]})})]}),"\n",(0,t.jsx)(s.h2,{id:"what-orbisid-discovers",children:"What OrbisID Discovers"}),"\n",(0,t.jsxs)(s.table,{children:[(0,t.jsx)(s.thead,{children:(0,t.jsxs)(s.tr,{children:[(0,t.jsx)(s.th,{children:"Data"}),(0,t.jsx)(s.th,{children:"Source"})]})}),(0,t.jsxs)(s.tbody,{children:[(0,t.jsxs)(s.tr,{children:[(0,t.jsx)(s.td,{children:"Managed accounts"}),(0,t.jsx)(s.td,{children:(0,t.jsx)(s.code,{children:"GET /service/core/v4/ManagedAccounts"})})]}),(0,t.jsxs)(s.tr,{children:[(0,t.jsx)(s.td,{children:"Managed systems"}),(0,t.jsx)(s.td,{children:(0,t.jsx)(s.code,{children:"GET /service/core/v4/ManagedSystems"})})]}),(0,t.jsxs)(s.tr,{children:[(0,t.jsx)(s.td,{children:"Entitlements"}),(0,t.jsx)(s.td,{children:(0,t.jsx)(s.code,{children:"GET /service/core/v4/Entitlements"})})]}),(0,t.jsxs)(s.tr,{children:[(0,t.jsx)(s.td,{children:"Access policies"}),(0,t.jsx)(s.td,{children:(0,t.jsx)(s.code,{children:"GET /service/core/v4/AccessPol
1icies"})})]}),(0,t.jsxs)(s.tr,{children:[(0,t.jsx)(s.td,{children:"Memberships"}),(0,t.jsx)(s.td,{children:"Derived from entitlement-to-account grants"})]})]})]}),"\n",(0,t.jsx)(s.h2,{id:"connection-requirements",children:"Connection Requirements"}),"\n",(0,t.jsx)(s.h3,{id:"required-permissions",children:"Required Permissions"}),"\n",(0,t.jsx)(s.p,{children:"Create a dedicated Safeguard local user account with read-only auditor access."}),"\n",(0,t.jsx)(s.p,{children:"Minimum permissions:"}),"\n",(0,t.jsxs)(s.ul,{children:["\n",(0,t.jsxs)(s.li,{children:[(0,t.jsx)(s.strong,{children:"Auditor"})," role \u2014 provides read-only access to accounts, entitlements, and policies"]}),"\n"]}),"\n",(0,t.jsx)(s.h3,{id:"credential-mapping",children:"Credential Mapping"}),"\n",(0,t.jsxs)(s.table,{children:[(0,t.jsx)(s.thead,{children:(0,t.jsxs)(s.tr,{children:[(0,t.jsx)(s.th,{children:"OrbisID Field"}),(0,t.jsx)(s.th,{children:"Value"})]})}),(0,t.jsxs)(s.tbody,{children:[(0,t.jsxs)(s.tr,{children:[(0,t.jsx)(s.td,{children:(0,t.jsx)(s.code,{children:"credential.username"})}),(0,t.jsx)(s.td,{children:"Safeguard local username"})]}),(0,t.jsxs)(s.tr,{children:[(0,t.jsx)(s.td,{children:(0,t.jsx)(s.code,{children:"credential.password"})}),(0,t.jsx)(s.td,{children:"Safeguard password"})]}),(0,t.jsxs)(s.tr,{children:[(0,t.jsx)(s.td,{children:(0,t.jsx)(s.code,{children:"system.hostname"})}),(0,t.jsx)(s.td,{children:"Safeguard appliance hostname or IP"})]})]})]}),"\n",(0,t.jsx)(s.h3,{id:"network-requirements",children:"Network Requirements"}),"\n",(0,t.jsx)(s.p,{children:"The OrbisID server must have HTTPS access to the Safeguard appliance on port 443."}),"\n",(0,t.jsx)(s.h2,{id:"configuration-steps",children:"Configuration Steps"}),"\n",(0,t.jsxs)(s.ol,{children:["\n",(0,t.jsxs)(s.li,{children:["In the Safeguard admin console, create a local user account and assign the ",(0,t.jsx)(s.strong,{children:"Auditor"})," role"]}),"\n",(0,t.jsxs)(s.li,{children:["Create a ",(0,t.jsx)(s.strong,{children:"Credential"})," in OrbisID:","\n",(0,t.jsxs)(s.ul,{children:["\n",(0,t.jsxs)(s.li,{children:[(0,t.jsx)(s.strong,{children:"Username:"})," Safeguard local username"]}),"\n",(0,t.jsxs)(s.li,{children:[(0,t.jsx)(s.strong,{children:"Password:"})," Safeguard password"]}),"\n"]}),"\n"]}),"\n",(0,t.jsxs)(s.li,{children:["Navigate to ",(0,t.jsx)(s.strong,{children:"Systems \u2192 Add System"})]}),"\n",(0,t.jsx)(s.li,{children:"Fill in the fields:"}),"\n"]}),"\n",(0,t.jsxs)(s.table,{children:[(0,t.jsx)(s.thead,{children:(0,t.jsxs)(s.tr,{children:[(0,t.jsx)(s.th,{children:"Field"}),(0,t.jsx)(s.th,{children:"Value"})]})}),(0,t.jsxs)(s.tbody,{children:[(0,t.jsxs)(s.tr,{children:[(0,t.jsx)(s.td,{children:(0,t.jsx)(s.strong,{children:"Name"})}),(0,t.jsxs)(s.td,{children:["Descriptive name (e.g., ",(0,t.jsx)(s.code,{children:"One Identity Safeguard \u2013 Production"}),")"]})]}),(0,t.jsxs)(s.tr,{children:[(0,t.jsx)(s.td,{children:(0,t.jsx)(s.strong,{children:"OS Type"})}),(0,t.jsx)(s.td,{children:(0,t.jsx)(s.code,{children:"OneIdentitySafeguard"})})]}),(0,t.jsxs)(s.tr,{children:[(0,t.jsx)(s.td,{children:(0,t.jsx)(s.strong,{children:"System Type"})}),(0,t.jsx)(s.td,{children:(0,t.jsx)(s.code,{children:"PAM Tool"})})]}),(0,t.jsxs)(s.tr,{children:[(0,t.jsx)(s.td,{children:(0,t.jsx)(s.strong,{children:"Hostname"})}),(0,t.jsx)(s.td,{children:"Safeguard appliance hostname or IP"})]}),(0,t.jsxs)(s.tr,{children:[(0,t.jsx)(s.td,{children:(0,t.jsx)(s.strong,{children:"Credential"})}),(0,t.jsx)(s.td,{children:"The scanning credential"})]})]})]}),"\n",(0,t.jsxs)(s.ol,{start:"5",children:["\n",(0,t.jsxs)(s.li,{children:["Click ",(0,t.jsx)(s.strong,{children:"Test Connection"})]}),"\n",(0,t.jsxs)(s.li,{children:["Click ",(0,t.jsx)(s.strong,{children:"Save"})]}),"\n"]}),"\n",(0,t.jsx)(s.h2,{id:"troubleshooting",children:"Troubleshooting"}),"\n",(0,t.jsxs)(s.table,{children:[(0,t.jsx)(s.thead,{children:(0,t.jsxs)(s.tr,{children:[(0,t.jsx)(s.th,{children:"Symptom"}),(0,t.jsx)(s.th,{children:"Likely Cause"}),(0,t.jsx)(s.th,{children:"Resolution"})]})}),(0,t.jsxs)(s.tbody,{children:[(0,t.jsxs)(s.tr,{children:[(0,t.jsx)(s.td,{children:(0,t.jsx)(s.code,{children:"Authentication failed"})}),(0,t.jsx)(s.td,{children:"Invalid credentials"}),(0,t.jsx)(s.td,{children:"Verify the local user account in the Safeguard console"})]}),(0,t.jsxs)(s.tr,{children:[(0,t.jsx)(s.td,{children:"No accounts returned"}),(0,t.jsx)(s.td,{children:"Insufficient role"}),(0,t.jsxs)(s.td,{children:["Assign the ",(0,t.jsx)(s.strong,{children:"Auditor"})," role to the scanning user"]})]}),(0,t.jsxs)(s.tr,{children:[(0,t.jsx)(s.td,{children:(0,t.jsx)(s.code,{children:"SSL certificate error"})}),(0,t.jsx)(s.td,{children:"Self-signed appliance cert"}),(0,t.jsx)(s.td,{children:"Add the Safeguard CA certificate to the OrbisID trust store"})]}),(0,t.jsxs)(s.tr,{children:[(0,t.jsx)(s.td,{children:"Cannot connect"}),(0,t.jsx)(s.td,{children:"Appliance unreachable"}),(0,t.jsx)(s.td,{children:"Verify port 443 TCP access from OrbisID to the Safeguard appliance"})]})]})]})]})}function h(e={}){const{wrapper:s}={...(0,i.R)(),...e.components};return s?(0,t.jsx)(s,{...e,children:(0,t.jsx)(a,{...e})}):a(e)}},8453(e,s,n){n.d(s,{R:()=>d,x:()=>c});var r=n(6540);const t={},i=r.createContext(t);function d(e){const s=r.useContext(i);return r.useMemo(function(){return"function"==typeof e?e(s):{...s,...e}},[s,e])}function c(e){let s;return s=e.disableParentContext?"function"==typeof e.components?e.components(t):e.components||t:d(e.components),r.createElement(i.Provider,{value:s},e.children)}}}]);

Line numbers count LF bytes from the start of the resource, as the search results do. Vendor segments are library code the classifier recognised; they are stored but not indexed. Bytes are shown as Latin1 characters, one per byte.