Versions Compared

Key

  • This line was added.
  • This line was removed.
  • Formatting was changed.

This is Step 3 of the DSPM DRA Setup

Note

This information predates Quick Start Wizard. The instructions outlined in this document are now automated. You can skip this step.

Click here to go to the next step: DSPM DRA - Enabling Data Risk & Control Features

Initial setup

  1. Login to https://DSPM_URL/auth/admin

  2. Use default login and password admin/admin

  3. Change the default login and password for admin

    1. Select the Realm master in the top left corner

    2. Select Users in the left menu

    3. Select admin user from the users table

      SCR-20240604-pdxw.png

d. Select Credentials from the top menu

  1. Select Reset password and follow the instructions in the modal window

    SCR-20240604-pesf.pngImage Modified
  1. Change realm to gv:

    1. In the top left corner select gv from a dropdown

      image-20240604-162326.pngImage Modified
  2. Navigate to Clients in the left menu and select Dashboard from the table

    SCR-20240604-pamf.pngImage Modified
  3. Select Root URL and Valid redirect URIs

    1. for Root URL set the URL to refer to your DSPM URL ending with /ui

    2. for Valid redirect URIs set the URL to refer to your DSPM URL ending with /ui/*

      SCR-20240604-paro.pngImage Modified
  4. Select Web origins and Admin URL

    1. for Web origins set the URL to refer to your DSPM URL ending with /ui

    2. for Admin URL set the URL to refer to your DSPM URL ending with /ui

      SCR-20240604-pavo.pngImage Modified
  5. Select Front-channel logout URL

    1. for Front-channel logout URL set the URL to refer to your DSPM URL ending with /auth/realms/gv/protocol/openid-connect/logout

      SCR-20240604-pays.pngImage Modified
  6. Press Save at the bottom of the page

Configuring roles and groups

  1. Importing permissions setup to Keycloak (which is the Identity and Access Management Engine used by our apps)

    1. Select the realm gvRealm SettingPartial Importin the tool:

      SCR-20240604-ogak-20240604-150915.png
    2. In the popup Partial Import pop-up window click browse and provide these filesthis file: https://drive.google.com/file/d/1jkPOb6hSK50WeGONotP9cfAG-xtkM6je/view?usp=sharing. Make sure all the options are selected as in the screenshot below and set to SKIP for existing items and click Import button.

      KC-PermisImport.pngImage Added

      Screenshot 2024-06-10 at 12.39.34.pngImage Added

    3. Next, select Partial Import again and add this file: https://drive.google.com/file/d/1hN2BL4qJX-8YmzU2gZqPWrpxl3Zy37uK/view?usp=sharing, then make . Make sure all the options in the popup are selected as in the picture screenshot below and set to SKIP for existing items and click Import button.

      SCR-20240605-kqqf-20240605-104621.pngImage RemovedKC-RBACImport.pngImage Added

      You should then see a positive confirmation window!:

      Screenshot 2024-06-10 at 12.45.44.pngImage Added


Create a new user and assign roles

  1. Make sure you operate in the gv realm (front top left corner)

  2. Navigate to Users and select Add user

    SCR-20240604-pbgm.png
  3. Give a name to your user by setting username

    SCR-20240604-pbkp.png
  4. Select Join Groups

    1. Select two groups

    2. Select Join

      SCR-20240604-pbpz.png
    3. Select Create

  5. Navigate to Credentials and press Set password

    SCR-20240604-pbte.png
    1. Set and save a password in the modal window

      SCR-20240604-pbxk.png
  6. Navigate to Role mapping

    1. Select Assign role

      SCR-20240604-pcbx.png
    2. Select ADMIN and USER from the list and press Assign

      SCR-20240604-pcen.png
    3. Select Assign role again

      1. From a modal window dropdown select Filter by clients

        SCR-20240604-pchc.png
      2. Add the following roles with a check-box:

      3. realm-admin

      4. view-users

      5. DATA_REGISTER

        1. ADMIN

        2. AGENT_CONFIGURATION_WRITE

        3. ANALYTICS_WRITE

        4. COMPLIANCE_HUB_READ

        5. DATACOMPLIANCE_RISKHUB_WRITE

        6. ANALYTICSCONNECTIONS_WRITEPATTERN

        7. DATA_MATCHINGREGISTER_WRITEREAD

        8. DATA_REGISTER_WRITE

        9. REPORTSDATA_RISK_WRITEUSER

        10. DEPARTMENTS_MANAGEMENTFULL_WRITEREAD

        11. ADMIN

        12. DEPARTMENTS_PARTIALFULL_WRITE

        13. USER

        14. CONNECTIONS_WRITE

        15. DEPARTMENTS_FULLPARTIAL_READ

        16. DEPARTMENTS_FULLPARTIAL_WRITE

        17. EXPLORE_PAGE_WRITE

        18. COMPLIANCELANGUAGE_HUBSETTINGS_WRITE

        19. AGENT_CONFIGURATIONPATTERN_MATCHING_WRITE

        20. realm-admin

        21. REPORTS_WRITE

        22. TAGGING_WRITE

        23. COMPLIANCE_HUB_READ

        24. LANGUAGE_SETTINGSUSER

        25. USER_MANAGEMENT_WRITEDEPARTMENTS_PARTIAL_READ

        26. view-users

          SCR-20240604-pckq.png
      6. Press Assign

Now, go to the Step 4, which is available via this link – Enabling DSPM DRA in Rancher-based deployment- Enabling Data Risk & Control Features