Changes for page Globale Accounts
Last modified by Sabrina V. on 2026/10/08 09:59
From version 2.1
edited by Sabrina V.
on 2025/11/25 08:24
on 2025/11/25 08:24
Change comment:
There is no comment for this version
To version 3.1
edited by Sabrina V.
on 2026/10/08 09:59
on 2026/10/08 09:59
Change comment:
There is no comment for this version
Summary
-
Page properties (1 modified, 0 added, 0 removed)
Details
- Page properties
-
- Content
-
... ... @@ -2,7 +2,7 @@ 2 2 3 3 = Use of global accounts = 4 4 5 -Global accounts allow you to store user data in a central location, which you can access repeatedly. Global accounts can be stored in various places within the ACMPConsole, whenever you need to authenticate yourself to a client or the Active Directory, for example. Global accounts have the advantage that the data (domain, username and password) do not have to be changed at every point and they only have to be customised once when a change is made. All the necessary information is stored centrally and is available to you in the respective application areas.5 +Global accounts allow you to store user data in a central location, which you can access repeatedly. Global accounts can be stored in various places within the acmp Console, whenever you need to authenticate yourself to a client or the Active Directory, for example. Global accounts have the advantage that the data (domain, username and password) do not have to be changed at every point and they only have to be customised once when a change is made. All the necessary information is stored centrally and is available to you in the respective application areas. 6 6 7 7 Of course, you can also use specific installation accounts in addition to global accounts. Specific accounts must be set up individually each time and filled with the information. 8 8 ... ... @@ -12,15 +12,15 @@ 12 12 13 13 == Areas of application == 14 14 15 -Below you will find a location for the work within the ACMPConsole for the respective application areas, as well as a short description and possible notes.15 +Below you will find a location for the work within the acmp Console for the respective application areas, as well as a short description and possible notes. 16 16 17 -|(% style="width:416px" %)** ACMParea**|(% style="width:803px" %)**Description**|(% style="width:474px" %)**Note**17 +|(% style="width:416px" %)**acmp area**|(% style="width:803px" %)**Description**|(% style="width:474px" %)**Note** 18 18 |((( 19 19 **Distributed File Repositories** 20 20 21 21 22 22 (//System //>// Distributed File Repositories//) 23 -)))|When a new file repository is created, the ACMPServer accesses the file repository using the authentication of an account (account). This ensures that the stored user account has the required rights.|(((23 +)))|When a new file repository is created, the acmp Server accesses the file repository using the authentication of an account (account). This ensures that the stored user account has the required rights.|((( 24 24 Depending on the selected connection type, the user interface may look slightly different. Choose from the following file repository connection types: 25 25 26 26 * Network Share ... ... @@ -33,32 +33,32 @@ 33 33 **Settings for Active Directory** 34 34 35 35 36 -(//System //>// Settings //>// ACMPServer //>// Active Directory//)36 +(//System //>// Settings //>// acmp Server //>// Active Directory//) 37 37 )))|To read the information from the Active Directory, a user account with read access for all domains is required. If you want to use multiple domains, existing or newly added global accounts can also be used to make continuing domain queries.| 38 38 |((( 39 39 **Settings for the agent installation and network discovery account** 40 40 41 -(//System// > //Settings// > // ACMPAgent// > //General//)42 -)))|The user account stored here is used to distribute the ACMPAgent to the computers within your network. The account is also used for network detection, which is used in theACMPAgent Installation. Therefore, give this account sufficient rights for the Remote Procedure Call (RPC), which enables the call of functions for other address spaces.|The //Check rights on target computers //option allows you to ensure that all computers found in the network are first checked to see if the specified account has sufficient rights for installation. Tick the box if you want to use this check.41 +(//System// > //Settings// > //acmp Agent// > //General//) 42 +)))|The user account stored here is used to distribute the acmp Agent to the computers within your network. The account is also used for network detection, which is used in the acmp Agent Installation. Therefore, give this account sufficient rights for the Remote Procedure Call (RPC), which enables the call of functions for other address spaces.|The //Check rights on target computers //option allows you to ensure that all computers found in the network are first checked to see if the specified account has sufficient rights for installation. Tick the box if you want to use this check. 43 43 |((( 44 -**Use of a global account in the network (install ACMPAgent on selected computers)**44 +**Use of a global account in the network (install acmp Agent on selected computers)** 45 45 46 -(//Client Management //>// Agent Distribution //>// Network //>// Push ACMPAgent to selected computers//)47 -)))|Using the action //Install ACMPAgent on selected computers //you can select machines or entire domains or workgroups by highlighting them in the console beforehand. Initiate the installation and select a global or specific account that has sufficient rights.|As soon as you open the window, the //Use specific account //option is displayed as the preselected installation account.46 +(//Client Management //>// Agent Distribution //>// Network //>// Push acmp Agent to selected computers//) 47 +)))|Using the action //Install acmp Agent on selected computers //you can select machines or entire domains or workgroups by highlighting them in the console beforehand. Initiate the installation and select a global or specific account that has sufficient rights.|As soon as you open the window, the //Use specific account //option is displayed as the preselected installation account. 48 48 |((( 49 49 **Use of a global account on the network (install ACMP Agent on a specific computer)** 50 50 51 -(//Client Management //>// Agent Distribution //>// Network //>// Push ACMPAgent to specific computer//)52 -)))|Use // ACMPAgent Install on specific computer //to install the Client on a single machine. To do this, you need to know the network name and enter it manually.|As soon as you open the window, the //Use specific account //option is displayed as the preselected installation account.51 +(//Client Management //>// Agent Distribution //>// Network //>// Push acmp Agent to specific computer//) 52 +)))|Use //acmp Agent Install on specific computer //to install the Client on a single machine. To do this, you need to know the network name and enter it manually.|As soon as you open the window, the //Use specific account //option is displayed as the preselected installation account. 53 53 |((( 54 54 **Use of a global account in the network (Install in IP range)** 55 55 56 56 (//Client Management //>// Agent Distribution //>// Network //>// Push to IP range//) 57 -)))|If you want to install the ACMPAgent on all devices in a specific IP range, you can enter a valid IPv4 address here (including start and end IP).|As soon as you open the window, the //Use specific account //option is displayed as the preselected installation account.57 +)))|If you want to install the acmp Agent on all devices in a specific IP range, you can enter a valid IPv4 address here (including start and end IP).|As soon as you open the window, the //Use specific account //option is displayed as the preselected installation account. 58 58 |((( 59 -**Display settings for the display in the ACMPKiosk**59 +**Display settings for the display in the acmp Kiosk** 60 60 61 -(//Client Management //>// ACMPKiosk //>// Add //> //Content selection for Kiosk Select entry > Wizard Page „Visibility“//61 +(//Client Management //>// acmp Kiosk //>// Add //> //Content selection for Kiosk Select entry > Wizard Page „Visibility“// 62 62 )))|When adding a new Kiosk entry, you can define the environment settings for displaying an entry and thus determine its visibility. The global account is only available for selected options.|((( 63 63 You can also access a global account based on the following criteria: 64 64 ... ... @@ -71,7 +71,7 @@ 71 71 |((( 72 72 **Adding a new product in Licence Management** 73 73 74 -(//Licence Management //>// Products //>// Add //>// Wizard page Product metric „Metric type: User CAL/ Device CAL //>// Next //>// Automatic consumers //>// Add a LDAP Query (Computer) or ( ACMPQuery (Clients)//)74 +(//Licence Management //>// Products //>// Add //>// Wizard page Product metric „Metric type: User CAL/ Device CAL //>// Next //>// Automatic consumers //>// Add a LDAP Query (Computer) or (acmp Query (Clients)//) 75 75 )))|Add a user-based LDAP Query for the new product in the Licence Management. This stores the account for searching the Active Directory, which you can then access.|The assignment of consumers is done via the product metric. To assign a global account, you must select either User CAL or Device CAL. 76 76 |((( 77 77 **Client Command //UI Interaction //(UI Automation) oder Client Command //Shell execute Command//** ... ... @@ -89,7 +89,7 @@ 89 89 90 90 == Manage global accounts == 91 91 92 -To use a global account, you must be in one of the areas of the ACMPConsole described above. It is not possible to access the global accounts from anywhere else. Depending on the user interface you are using, you can either use an existing global account or add a new account. Access partially determines which options are available. For example, the Active Directory allows you to use multiple domains. These are managed by global accounts so that multiple domains can be queried.92 +To use a global account, you must be in one of the areas of the acmp Console described above. It is not possible to access the global accounts from anywhere else. Depending on the user interface you are using, you can either use an existing global account or add a new account. Access partially determines which options are available. For example, the Active Directory allows you to use multiple domains. These are managed by global accounts so that multiple domains can be queried. 93 93 94 94 == Add global accounts == 95 95 ... ... @@ -97,12 +97,12 @@ 97 97 You can add a global account in the areas using the //Add //button. 98 98 {{/aagon.infobox}} 99 99 100 -If you want to access an account via the Active Directory (//System //>// Settings //>// ACMPServer //>// Active Directory//), the action field is called //Link//. Click //Add//. A new window opens with the properties of the login information. Enter the domain, username and password that you want to use. Then decide whether you want to use encryption for the global account. You can only choose from the two options //None //and //SSL/TLS//. If you select the latter, the transmitted data will be encrypted. Additional information can be stored under the description. For example, you can use a short sentence to describe which special rights or access the domain should have (e.g. it is an account with reading rights). Tick the box under //Use static IPs //if you want to enable this option. This activates the section below: The //domain controller// and //global catalog IPs//.100 +If you want to access an account via the Active Directory (//System //>// Settings //>// acmp Server //>// Active Directory//), the action field is called //Link//. Click //Add//. A new window opens with the properties of the login information. Enter the domain, username and password that you want to use. Then decide whether you want to use encryption for the global account. You can only choose from the two options //None //and //SSL/TLS//. If you select the latter, the transmitted data will be encrypted. Additional information can be stored under the description. For example, you can use a short sentence to describe which special rights or access the domain should have (e.g. it is an account with reading rights). Tick the box under //Use static IPs //if you want to enable this option. This activates the section below: The //domain controller// and //global catalog IPs//. 101 101 102 102 The main purpose of the two IP types is to exclude a level in the network communication, since otherwise the IP would be found and addressed on a machine. By storing the IP address, the domain controller or global catalog is addressed directly: 103 103 104 -* Domain Controller IP: If it is not possible for the ACMPServer to reach the domain controller by name, you can store the static IP address here.105 -* Global Catalog IP: If the ACMPServer cannot access the Global Catalog by name, you can enter the static IP address here.104 +* Domain Controller IP: If it is not possible for the acmp Server to reach the domain controller by name, you can store the static IP address here. 105 +* Global Catalog IP: If the acmp Server cannot access the Global Catalog by name, you can enter the static IP address here. 106 106 107 107 With the activation of the option ‘Use static IPs’, the DNS queries are not used for communication, but the configured static IPs. It makes sense to use a static IP (Domain Controller IP or Global Catalog IP) if, for example, the domain controller cannot be resolved by Windows' own mechanisms. Otherwise, you can leave the field disabled. 108 108 ... ... @@ -109,5 +109,5 @@ 109 109 [[Properties of the credentials>>image:67_Globale Accounts_Eigenschaften der Anmeldeinformationen_337.png]] 110 110 111 111 {{aagon.infobox}} 112 -Please note that you can only use LDAPS in ACMPif both the server and the console are in the same domain, otherwise the certificates will not be transferred. If you are in a workgroup, LDAP may work, but not the encrypted variant (LDAPS), because a domain is required for this.112 +Please note that you can only use LDAPS in acmp if both the server and the console are in the same domain, otherwise the certificates will not be transferred. If you are in a workgroup, LDAP may work, but not the encrypted variant (LDAPS), because a domain is required for this. 113 113 {{/aagon.infobox}}

