Evidian Access CollectorThe Access Collector is a subset of Evidian Enterprise SSO. This module may be used when all you need is to collect effective user accesses to applications across your organisation. Behaviour of the access collector engineWhen end users launch an application that is detected by SSOEngine, Enterprise SSO base starts the account collect if it has not been done previously. If the account was already collected, nothing happens, and the SSO is not performed. The collected data is put in the LDAP. If a BadPassword window is detected in the collect context, the collected account is deleted or a new account is collected. The account will not be deleted if the BadPassword occurs at any other moment. Once the account has been collected, the Self Registration is deactivated for the application. Collected dataThe data collected in the LDAP provides the following information for each collected connection:
The password is never collected What to do with the collected dataThe collected data can be used to build your IT access policy and feed RBAC-oriented policy management tools such as Policy Manager. |
|||