This is Step 3 of the DSPM DRA Setup |
---|
Note |
---|
This information predates Quick Start Wizard. The instructions outlined in this document are now automated. You can skip this step.Click here to go to the next step: DSPM DRA - Enabling Data Risk & Control Features |
Initial setup
Login to https://DSPM_URL/auth/admin
Use default login and password admin/admin
Change the default login and password for admin
Select the Realm
master
in the top left cornerSelect
Users
in the left menuSelect
admin
user from the users table
d. Select Credentials
from the top menu
Select
Reset password
and follow the instructions in the modal window
Change realm to
gv
:In the top left corner select
gv
from a dropdown
Navigate to
Clients
in the left menu and selectDashboard
from the tableSelect
Root URL
andValid redirect URIs
for
Root URL
set the URL to refer to your DSPM URL ending with/ui
for
Valid redirect URIs
set the URL to refer to your DSPM URL ending with/ui/*
Select
Web origins
andAdmin URL
for
Web origins
set the URL to refer to your DSPM URL ending with/ui
for
Admin URL
set the URL to refer to your DSPM URL ending with/ui
Select
Front-channel logout URL
for
Front-channel logout URL
set the URL to refer to your DSPM URL ending with/auth/realms/gv/protocol/openid-connect/logout
Press
Save
at the bottom of the page
Configuring roles and groups
Importing permissions setup to Keycloak (which is the Identity and Access Management Engine used by our apps)
Select the realm
gv
→Realm Setting
→Partial Import
in the tool:In the popup Partial Import pop-up window click browse and provide these filesthis file: https://drive.google.com/file/d/1jkPOb6hSK50WeGONotP9cfAG-xtkM6je/view?usp=sharing. Make sure all the options are selected as in the screenshot below and set to SKIP for existing items and click Import button.
Next, select Partial Import again and add this file: https://drive.google.com/file/d/1hN2BL4qJX-8YmzU2gZqPWrpxl3Zy37uK/view?usp=sharing, then make . Make sure all the options in the popup are selected as in the picture screenshot below and set to SKIP for existing items and click Import button.
You should then see a positive confirmation window!:
Create a new user and assign roles
Make sure you operate in the
gv
realm (front top left corner)Navigate to
Users
and selectAdd user
Give a name to your user by setting
username
Select
Join Groups
Select two groups
Select
Join
Select
Create
Navigate to
Credentials
and pressSet password
Set and save a password in the modal window
Navigate to
Role mapping
Select
Assign role
Select
ADMIN
andUSER
from the list and pressAssign
Select
Assign role
againFrom a modal window dropdown select
Filter by clients
Add the following roles with a check-box:
realm-admin
view-users
DATA_REGISTERADMIN
AGENT_CONFIGURATION_WRITE
ANALYTICS_WRITE
COMPLIANCE_HUB_READ
DATACOMPLIANCE_RISKHUB_WRITE
ANALYTICSCONNECTIONS_WRITEPATTERN
DATA_MATCHINGREGISTER_WRITEREAD
DATA_REGISTER_WRITE
REPORTSDATA_RISK_WRITEUSER
DEPARTMENTS_MANAGEMENTFULL_WRITEREAD
ADMIN
DEPARTMENTS_PARTIALFULL_WRITE
USER
CONNECTIONS_WRITE
DEPARTMENTS_FULLPARTIAL_READ
DEPARTMENTS_FULLPARTIAL_WRITE
EXPLORE_PAGE_WRITE
COMPLIANCELANGUAGE_HUBSETTINGS_WRITE
AGENT_CONFIGURATIONPATTERN_MATCHING_WRITE
realm-admin
REPORTS_WRITE
TAGGING_WRITE
COMPLIANCE_HUB_READ
LANGUAGE_SETTINGSUSER
USER_MANAGEMENT_WRITEDEPARTMENTS_PARTIAL_READ
view-users
Press
Assign
Now, go to the Step 4, which is available via this link – Enabling DSPM DRA in Rancher-based deployment- Enabling Data Risk & Control Features |
---|