Evidian Access Collector
The Access Collector is a subset of Evidian Enterprise SSO.
This module may be used when all you need is to collect effective user accesses to applications across your organisation.
Behaviour of the access collector engine
When end users launch an application that is detected by SSOEngine, Enterprise SSO base starts the account collect if it has not been done previously. If the account was already collected, nothing happens, and the SSO is not performed. The collected data is put in the LDAP.
If a BadPassword window is detected in the collect context, the collected account is deleted or a new account is collected. The account will not be deleted if the BadPassword occurs at any other moment.
Once the account has been collected, the Self Registration is deactivated for the application.
Collected data
The data collected in the LDAP provides the following information for each collected connection:
- Window identifier
- Application name
- Application identifier
The password is never collected
What to do with the collected data
The collected data can be used to build your IT access policy using tool such as Policy Creator One.
The IT access policy can then feed RBAC-oriented policy management tools such as Policy Manager.

