DSPM DRA - Setting up access to the platform
This is Step 3 of the DSPM DRA Setup |
---|
This information predates Quick Start Wizard. The instructions outlined in this document are now automated. You can skip this step.
Click here to go to the next step: DSPM DRA - Enabling Data Risk & Control Features
Initial setup
Login to https://DSPM_URL/auth/admin
Use default login and password admin/admin
Change the default login and password for admin
Select the Realm
master
in the top left cornerSelect
Users
in the left menuSelect
admin
user from the users tableAdmin user location
d. Select Credentials
from the top menu
Select
Reset password
and follow the instructions in the modal windowReset the password flow
Change realm to
gv
:In the top left corner select
gv
from a dropdownChange realm
Navigate to
Clients
in the left menu and selectDashboard
from the tableSelect DashboardSelect
Root URL
andValid redirect URIs
for
Root URL
set the URL to refer to your DSPM URL ending with/ui
for
Valid redirect URIs
set the URL to refer to your DSPM URL ending with/ui/*
Root URL
andValid redirect URIs
Select
Web origins
andAdmin URL
for
Web origins
set the URL to refer to your DSPM URL ending with/ui
for
Admin URL
set the URL to refer to your DSPM URL ending with/ui
Web origins
andAdmin URL
Select
Front-channel logout URL
for
Front-channel logout URL
set the URL to refer to your DSPM URL ending with/auth/realms/gv/protocol/openid-connect/logout
Front-channel logout URL
Press
Save
at the bottom of the page
Configuring roles and groups
Importing permissions setup to Keycloak (which is the Identity and Access Management Engine used by our apps)
Select the realm
gv
→Realm Setting
→Partial Import
in the tool:In the Partial Import pop-up window click browse and provide this file: https://drive.google.com/file/d/1jkPOb6hSK50WeGONotP9cfAG-xtkM6je/view?usp=sharing. Make sure all the options are selected as in the screenshot below and set to SKIP for existing items and click Import button.
Next, select Partial Import again and add this file: https://drive.google.com/file/d/1hN2BL4qJX-8YmzU2gZqPWrpxl3Zy37uK/view?usp=sharing. Make sure all the options are selected as in the screenshot below and set to SKIP for existing items and click Import button.
You should then see a positive confirmation window:
Create a new user and assign roles
Make sure you operate in the
gv
realm (top left corner)Navigate to
Users
and selectAdd user
Creating a new userGive a name to your user by setting
username
Create a user flowSelect
Join Groups
Select two groups
Select
Join
Assign GroupsSelect
Create
Navigate to
Credentials
and pressSet password
Set user’s passwordSet and save a password in the modal window
Set the password
Navigate to
Role mapping
Select
Assign role
Assign rolesSelect
ADMIN
andUSER
from the list and pressAssign
Assign rolesSelect
Assign role
againFrom a modal window dropdown select
Filter by clients
Change the filterAdd the following roles with a check-box:
ADMIN
AGENT_CONFIGURATION_WRITE
ANALYTICS_WRITE
COMPLIANCE_HUB_READ
COMPLIANCE_HUB_WRITE
CONNECTIONS_WRITE
DATA_REGISTER_READ
DATA_REGISTER_WRITE
DATA_RISK_WRITE
DEPARTMENTS_FULL_READ
DEPARTMENTS_FULL_WRITE
DEPARTMENTS_PARTIAL_READ
DEPARTMENTS_PARTIAL_WRITE
EXPLORE_PAGE_WRITE
LANGUAGE_SETTINGS_WRITE
PATTERN_MATCHING_WRITE
realm-admin
REPORTS_WRITE
TAGGING_WRITE
USER
USER_MANAGEMENT_WRITE
view-users
Assign Roles
Press
Assign
Now, go to the Step 4, which is available via this link – DSPM DRA - Enabling Data Risk & Control Features |
---|
Classified as Getvisibility - Partner/Customer Confidential