Skip to main content

Hello team, could someone please share the prerequisites what we required to further onboard and the key information we need to request from the customer regarding this Azure? Below, I have outlined the relevant scenarios.

 

Customer Mentioned: This is an Cloud SaaS Password Safe, Users are in Azure EntraID and servers are Domain-Joined.

 

I have collected these below KB's :

  1. Configuration SAML Azure EntraID - https://beyondtrustcorp.service-now.com/csm?id=kb_article_view&sys_kb_id=dd8ff4a91b019e946fe95287624bcb37
  2. EntraID FA MA - https://beyondtrustcorp.service-now.com/csm?id=kb_article_view&sys_kb_id=aad9352747511e50b77b3ddbd36d4384
  3. Attached Asset requirement sheet.

Thansk!

In addition to the two articles you’ve posted above, you may also find the following guides helpful:

 

Create and configure groups for Role-Based Access \ Add an Entra ID Group:
https://docs.beyondtrust.com/bips/docs/role-based-access#add-an-entra-id-group

Entra ID SAML single sign-on:
https://docs.beyondtrust.com/bips/docs/entra-id

SAML using Entra ID App:
https://docs.beyondtrust.com/bips/docs/saml-entra-id

Configure Functional Account Requirements in Entra ID:
https://docs.beyondtrust.com/bips/docs/bi-configuration

Create and edit directory credentials \ Create an Entra ID credential:
https://docs.beyondtrust.com/bips/docs/authentication-directory-credentials#create-an-entra-id-credential

Use an Entra ID Smart Rule:
https://docs.beyondtrust.com/bips/docs/work-with-smart-rules-cloud#use-an-entra-id-smart-rule


Hello ​@SugunaRajalakshmi 

We don’t have any documentation specific to onboarding Entra ID joined assets 

Please have a look at our documentation on adding assets to Password Safe.

https://docs.beyondtrust.com/bips/docs/bi-cloud-assets

The workflow is:

Add Asset.

Add the functional account.

Add the asset managed systems

Configure managed system settings (Smart Rule)

Add the managed accounts

Setup Role Based Access to managed accounts.

If you  have any additional questions please let me know. 


I have a related question.

The BT doco conflicts, one area it suggests choosing the Entra App from the list of Enterprise Apps and another states ‘’Create you own’. From memory, the claims in the existing BeyondTrust Enterprise App need removing/readding - so is there a suggestion of which to use?

Also, utilizing EntraID user mapping - is this the recommended from BeyondTrust?

Previously I have been told to utilise Mapping=None in PWS, create an SSO_Users group as a literal group claim, and ensure ALL users are added to both this SSO_Users group and their relevant RBAC groups. Which goes against what the doco suggests (and the concept of the user mappings).


Reply