
ThistablistsanyRemoveUseractionsthathavebeenperformedontheuser,includingthenameofthe
devicefromwhichtheuserwasremovedandthedateandtimeofthelaststatuschange.
Removingauser’saccesstoaHardwarePasswordManagerdevice
AfterauserhasbeenenrolledonaHardwarePasswordManagerdevice,youcanremovethatenrollment
iftheusershouldnolongerhaveaccesstothedevice.Toremoveauser,createaremoteactionthatis
appliedtoeachdeviceyouspecify.ThenexttimewhenthedeviceisconnectedtotheHardwarePassword
Managerservertoupdateitspolicy,theuserwillberemovedfromthelistofusersforthatdevice.
ToremoveauserfromaHardwarePasswordManagerdevice:
1.ClickHPMEnrolledUsersinthetoolbox(orclickTools➙ThinkVantageHardwarePassword
Manager➙HPMEnrolledUsers).
2.Intheuserlist,selecttheuser(s).
3.ClickRevokeuseronthetoolbar.
4.IntheCreateRemoteActiondialogbox,clearthecheckboxforoneormoredevicesfromwhich
youwanttoremovetheuser.
5.ClickOK.
ManagingHardwarePasswordManagergroups
HardwarePasswordManagergroupslinkusergroups(asdenedintheLDAPserver)withHardware
PasswordManagerdevices.HardwarePasswordManagergroupsareusefulbecausetheyallowmultiple
userstoaccessoneormoredeviceswithoutindividuallyenrollingeachuseroneachdevice.Whena
deviceisaddedtoagroup,allmembersofthatgrouphavetheaccesstothedeviceandcanusean
intranetaccounttologintothedevice.
WhenyouopentheHPMGroupstool,groupsarelistedintheLDAPtreeview.Eachgroupiscreatedonyour
LDAPserver;youcannotcreateagroupinThinkManagementConsole.However,youcaneditgroups(dene
thegrouprole)anddragdevicesintogroupstoassociatethosedeviceswiththemembersofthegroups.
Intranetaccountgroupsaredistinguishedbytheroledenedfortheusersinthegroup:
•User:anenduserofaHardwarePasswordManagerdevice.
•ServiceTech:anITtechnician,authorizedwithlimitedaccesstothedeviceforservicing.Accesscanbe
limitedtoatimeframe(duration),orthetechniciancanbeauthorizedwithacertainnumberoflogins.
•Administrator:anadministrativeuserauthorizedtoaccessdevices.
Forexample,allmembersofagroupthatisdenedwiththeServiceTechrolecanlogintodevicesinthe
groupforaspeciednumberoftimes.Iftheroleisdenedsotheusercanonlylogintothedevicetwo
times,accesstothedeviceexpiresfortheuserafterthesecondlogin.
ToeditaHardwarePasswordManagergroup:
1.ClickHPMGroupsinthetoolbox(orclickT ools➙ThinkVantageHardwarePasswordManager➙
HPMGroups).
2.IntheLDAPtreeview,clickagroupnameandclickEditIntranetAccountGrouponthetoolbar.Most
itemsintheEditIntranetAccountGroupdialogboxarenoteditable.Y oucanselecttheroleforthe
group;ifyouselectServiceTech,youcanlimittheaccesstoHardwarePasswordManagerdevices.
3.Selecttherolefromthecombobox.
4.SelectWithexpirationifyouwanttolimittheaccesstothedeviceforaperiodoftimeoraspecic
numberoflogins.(ThisappliesonlytoServiceTechusers.)
12HardwarePasswordManagerDeploymentGuide
Komentarze do niniejszej Instrukcji