IAM AD SSO least privileges to success

Roy Lam Lv1Posted 12 Apr 2022 18:01

I am checking the User Manual for IAM of the Domain SSO. In the document, it said we have to provide a Domain Admin Account to "obtain login information from the AD server and report the received information to the IAG for implementing SSO".

I am thinking that there should NOT be using Domain Admin privilege (the highest privilege) to perform such an operation. So what is the least privileges to work with the objective, Event Log Readers?

Please help.

Liew has solved this question and earned 10 coins.

Posting a reply earns you 2 coins. An accepted reply earns you 20 coins and another 10 coins for replying within 10 minutes. (Expired) What is Coin?

Enter your mobile phone number and company name for better service. Go

Good day! As long as the user have permission, you may use that user.
You need to grant user with enable remote permission, then in advanced you need to allow for the user to access namespace and subnamespaces. Lastly, assign user to Event Log Readers and Performance Log user in user account active directory.
Is this answer helpful?
Roy Lam Lv1Posted 21 Apr 2022 17:39
  
So what is the least privilege level? Must be Domain Administrator? Or could I use less powerful permission such as Network Operator?

I Can Help:

Change

Moderator on This Board

15
21
3

Started Topics

Followers

Follow

Board Leaders