Password monitoring agents¶
The Password monitoring agents module lists the workstations on which a Systancia Access agent is installed, and lets an administrator adjust the configuration of each one: activation, applied computer policy, and authority level used when rotating domain-account passwords. Deploying and uninstalling an agent is done from the module of the resource concerned; this one only covers the configuration of agents already installed.
Module availability
This module is only available when the vault mode selected in the general options is Systancia Access.
The three agent types¶
The type is set at deployment time and can be read in the Type column:
| Type | Role |
|---|---|
| Agent mode | Periodically detects and lists the local and service accounts on the machine, and applies password rotation according to the local account policy assigned to the workstation. |
| Password rotation tool mode | The workstation applies the rotation policies of domain accounts, that is, accounts shared between several machines. |
| Combined mode | The workstation provides both the agent mode and the password rotation tool mode. |
Agent list¶
The window opens on the paged list of agents; when empty, it displays No agent for password monitoring available. A leading icon distinguishes three states: agent enabled and online, agent enabled but offline, and agent disabled.
| Column | Description |
|---|---|
| Name | Name of the workstation on which the agent is installed, preceded by the state icon. |
| Type | Agent mode, Password rotation tool mode or Combined mode. |
| Computer policy | Name of the local account policy applied to this workstation. |
| Authority level | Standard or Master (see below). |
| Last activity | Date of the last activity reported by the agent. |
A search field filters the list by name substring. The number of rows per page is configurable (15, 25, 50).
Edit an agent¶
Select an agent in the list and click the Properties icon, or double-click the row. The window is titled Edit agent for password monitoring.
| Field | Description |
|---|---|
| Name | Workstation name. Plain displayed text. |
| Enable agent | Includes or excludes the workstation from the password rotation mechanism. Checked by default. |
| Agent type | Plain displayed text: the type is not changed here. ⓘ In Agent mode, the Authority level is automatically disabled — an agent that does not rotate domain accounts has no authority to exert. |
| Computer policy | Mandatory, read-only. A workstation carries only one policy. The icon to the right of the field — whose tooltip reads Select a computer policy — opens the policy list of the Password policies module. |
| Authority level | Two values, Master and Standard, the latter selected by default. Only has an effect on agents in Password rotation tool mode or Combined mode. |
Authority levels:
| Level | Effect |
|---|---|
| Standard (default) | The workstation is not allowed to control (stop, start, restart) services or scheduled tasks on the remote workstation while rotating passwords for domain accounts. |
| Master | The workstation is allowed to control (stop, start, restart) services or scheduled tasks on the remote workstation while rotating passwords for domain accounts. |
Click Validate to save.
Neither add nor delete from this module
The toolbar carries only the Edit action: no add or delete agent button is exposed there. Deploying and uninstalling a Systancia Access agent is done from the module of the resource concerned; this module is limited to configuring agents already installed.