Security Compliance

Create SEM Console users with domain credentials

This article describes how to create SEM Console users from an Active Directory User or Group.

First published date

10/9/2018 1:44 PM

Last published date

10/9/2018 1:44 PM

Overview

This article describes how to create Security Event Manager (formerly Log & Event Manager) Console users from an Active Directory User or Group.
 

Note: Starting with SEM version 5.4, the Build > Users component of the SEM Console can authenticate a login using Microsoft Active Directory.

Note: SEM versions 6.3.x and later will still use the Directory Service Query Connector, but this connector will only be used to query groups for use by Rules and nDepth searches. So the reference to Configuring the Directory Service Query Connector (for SEM 6.3.x) does not apply to users logging in with AD credentials. On SEM 6.3.x and later, SSO (single sign on) will need to be configured to use AD credentials for the console login. Local user account can still be used to login to SEM if it has not been disabled during the SSO configuration.

Product section

Security Event Manager

Resolution

Create a SEM Console user from an Active Directory user:

  1. Open your SEM GUI Console and authenticate to your SEM appliance.
  2. Configure the Directory Service Query connector on your SEM appliance if you have not done so.
  3. Click the Build tab, and then select Users.
  4. Click the plus icon, and then select Directory Service User.
  5. Select the Organizational Unit and Group where you want to add the user.
  6. Select the user you want to add from the Available Users column, and then click Select User.
  7. Select a SEM role in the User Information form. Click View Role to see details about each role.
  8. Enter a user description if you want. If you change the Description field, your changes only apply to the SEM user account and not to the Active Directory account.
  9. Click Save.

Create SEM Console users from an Active Directory group:

  1. Open your SEM Console and authenticate to your SEM appliance.
  2. Configure the Directory Service Query connector on your SEM appliance if you have not done so. 
  3. Click the Build tab, and then select Users.
  4. Click the plus icon, and then select Directory Service Group.
  5. Select the Organizational Unit where you want to add the group.
  6. Select the group you want to add from the Available Groups column, and then click Select Group.
  7. Select a SEM role in the User Information form. Click View Role to see details about each role.
    Note: If you want members of this group to have different SEM user roles, change their roles individually after you complete this procedure.
  8. Enter a description for these users if you want. If you change the Description field, your changes only apply to the SEM user accounts and not to the Active Directory accounts.
  9. Click Save.