Getting Started
The Getting Started tasks guide you through the basic setup, configuration, and use of Local Security Solution.
Prerequisites for Getting Started tasks
- Notification Server 6.0 SP3, or later
- Local Security 6.1 SP1 installed on the Notification Server. See Installation (page 4)
Getting Started tasks
- Install the Local Security Agent on Computers (page 5)
- Perform Local User Inventory (page 6)
- Enable the Random Password Policy (page 6)
- View Data on Computers (page 7)
Exercise scenario
You are a system administrator. Your IT manager asked you to perform an inventory of defined local users and groups on all Windows Computers in your environment. Your manager also wants you to implement a random password generator policy for the Administrator user account to improve the management of these users and groups. Finally, you need to view the local users, groups, and password data on a computer.
Install the Local Security Agent on Computers
The Local Security Agent is software you can install on your managed computers, allowing the Local Security Solution to obtain defined local user and groups inventory and implement random password generation.
The Local Security Agent works with the Altiris Agent. Therefore, you must have the Altiris Agent installed before installing the Local Security Agent. For information on installing the Altiris Agent, see the Notification Server documentation.
The Local Security Agent gets installed on all computers in the All Windows Computers without Local User Security Agent Installed collection. This collection gets populated when the Altiris Agent communicates with the Notification Server after you have installed Local Security Solution. |
To install the Local Security Agent
- In the Altiris Console, click the Configuration tab.
- In the left pane, navigate to Configuration > Solutions Settings > Security Management > Local Security > Windows > Local Security Agent Rollout.
- Click Local Security Agent Install Altiris Local Security Solution Help
- In the right pane, select Enable
- Click the Applies To: pencil icon and select the collections you want this policy to apply to
- Select the scheduling option you want and click Apply.
Perform Local User Inventory
After the Local Security Agent has been installed, the solution performs a local user inventory. This inventory is gathered by the Local User Inventory Policy, which is enabled by default. You do not need to do anything for this policy to run. However, you may want to view this policy and its settings.
To view the Local User Inventory Policy
- Click the Configuration tab.
- In the left pane, select Configuration > Solutions Settings > Security Management > Local Security > Windows > Local Security Agent Configuration > Local User Inventory Policy.
Take note of the collection this policy applies to and the interval it is set to run. You can change the interval as needed. (If you make changes click Apply.)
Enable the Random Password Policy
The Random Password policy lets you generate random passwords for a defined collection.
To set up and use the Random Password policy
- In the Altiris Console, click the Tasks tab.
- In the left pane, navigate to Tasks > Security Management > Local User Security > Windows > Local User Tasks.
- Right-click Sample Random Password Policy for Administrators and select Clone.
- Give the new policy a unique name and click OK.
- In the left pane, select the new policy.
- In the right pane, select Enable.
For the purpose of this Getting Started exercise, you do not need to make any other changes to this policy.Note The Log password at server before change option ensures the password change request and subsequent change are never lost. However, there is additional overhead associated with selecting this option because of the added communication between Notification Server and managed computers.
- Click Apply.
View Data on Computers
After the required policies have been enabled and deployed, you can view users, groups, and password information for individual computers on the Altiris Console.
To view user, group, and password data on a computer
- In the Altiris Console, click the Configuration tab.
- In the left pane, select Configuration > Solutions Settings > Security Management > Local Security > Windows > Local Security Agent Uninstall > All Windows Computers with Local Security Agent Installed.
- In the right pane, double-click on a computer name to open Resource Manager.
- Click the Summaries tab.
- In the left pane, select Resource Manager > Local Security.
- Click All Local Groups to view the local groups on the computer. Double-click a local group to view inventory and associations for that group.
- Click All Local Users to view the local users on the computer. Double-click a local user to view inventory, events, and associations for that user.
- Click Local Accounts Diagram to view a diagram of all accounts found on the computer.
- Click Managed Local User Passwords to view user password change information on the computer. To view the managed password for a user, right- click the user name and select Show Managed Password.
Note - The amount of time you can view the password depends on how you configured the Password Disclosure Settings. For information, see Password Disclosure Settings on page 23.