This document describes how to create a segregated parameter for devices on the Segura® Platform.
Requirements
A previously created global remote session setting. More information in How to configure a remote session.
When creating a new segregation for devices, you can select between System default, which follows the configurations made in the global parametrization, and Yes or No, which override the global parametrization. Changes affect only the devices included in the new segregated parameter.
Create a new parameter
To understand the meaning of each parameter, see System parameters - Remote session.
-
On the Segura® Platform, in the navigation bar, hover over the Products menu and select PAM Core.
-
In the side menu, select Access control > Segregated parameters.
-
In the upper-right corner, click the dropdown menu and select New segregation for devices.
-
In the Device segregated parameters screen, on the General tab, complete the mandatory fields identified with an asterisk:
- Name *: enter the parameter name.
- Status *: set to Enabled by default.
-
On the Remote session tab, complete the mandatory fields identified with an asterisk.
- Enable use of personal credentials? *
- Enable file transfer for download? *
- Enable file transfer for upload? *
AttentionThe Enable file transfer parameter was divided into 2 parameters: Enable file transfer for download * and Enable file transfer for upload *. If you select Yes for either parameter, both download and upload will be enabled. To completely disable file transfer, select No for both parameters.
- Enable Ctrl+Alt+Del? *
- Enable copy and paste? *
- Ignore certificate errors? *
- Enable SUDO automation in Linux sessions? *
- Enable triggers for file transfer? *
- Enable RAIL over RDP? *
- Enable wallpaper in RDP sessions? *
- SSH terminal type
- Include hostname in local login in RDP sessions? *
- Convert /r/n to /n on SSH sessions when using the browser? *
- Color depth
InfoIn the Color depth field, you can select the color depth used by each connectivity type, such as
HTTP/HTTPS,RDP,VNC, andX11 Forward. Options range from 8 to 32 bits.- RDP drive letter *
- Keyboard layout *
- Session text language (OCR) *
AttentionAfter selecting the Keyboard layout * and Session text language (OCR) * for an RDP session through Web Proxy on Windows devices, make the same adjustments inside the session in the Windows settings.
- Number of simultaneous user sessions (zero indicates unlimited) *
- Enable support for SSH domain credentials? *
- Mask for connection string when using SSH domain credentials *
- Connection banner: enter the message to be displayed at the beginning of a session.
-
On the Record tab, complete the following fields:
- Enable user input recording? *
- Enable session recording? *
- Indexing session texts? *
- Enable input text index import? *
- Enable output text index import? *
- Enable livestream in real time? *
- Enable use of macro in session? *
- Enable the download of the session video? *
-
On the Security tab, complete the following fields:
- Force multi-factor authentication to view password? *
- Force multi-factor authentication to start a session? *
- Ignore the 'Trust this computer' option to view password? *
- Ignore the 'Trust this computer' option to start a session? *
- Force secure connection (SSL) on password change executions? *
- Enable password change after session opening? *
- Force certificate authentication for the RDP Proxy? *
- Force certificate authentication for the SSH/Telnet Proxy? *
- Enable command auditing during the session? *
- Session idle time *
- RDP safe mode *
- Enable IP filters with permission to start session
- Allowed IPs to start session (available only if the previous option is enabled).
-
On the Devices tab:
- Click + Add to open the device selection modal.
- In the modal, search for the devices you want to associate.
- Select the desired devices and click Add/Remove selected.
InfoDevice selection is performed per page. The modal displays up to 100 devices per page. For volumes above 100 devices, use the Batch import option. More information in How to bulk import devices into a segregated parameter.
-
On the Review tab, click Save in the lower-right corner.
After saving, a confirmation message will be displayed. The parameters for devices are now configured and ready for use.