# Configuration wizard

# ⏰ Getting started

## Introduction

Soffid provides you a 360° perspective of the identities of your organization employees, providers and customers:

- Identity governance to manage the identities life-cycle
- Access management identifies your users accessing applications, including multi-factor authentication
- Privileged access management tracks usage and access of service and system management accounts
- Identity risk and compliance

## Screen overview

<iframe allowfullscreen="allowfullscreen" height="314" src="https://www.youtube.com/embed/jTmFj1Ab8Pc?rel=0" width="560"></iframe>

# IGA

Identity Governance Administration

# Connect Soffid IdaaS to your on-premise network

## Description

In order to manage your information system, a component named Sync Server must be installed along with Soffid Console. You must choose one platform as your Sync Server Soffid host and follow the instructions.

Once you have run the corresponding scripts, Soffid will detect the new Sync server. You could check the new Sync server on the **[Synchronization servers page](https://bookstack.soffid.com/books/soffid-3-reference-guide/page/synchronization-servers).**

## Step-by-step

<span style="color: #a6d100; font-weight: bold; font-size: 18px;">1. </span>First, you must select the platform and click the Next button

[![image-1677150674570.png](https://bookstack.soffid.com/uploads/images/gallery/2023-02/scaled-1680-/image-1677150674570.png)](https://bookstack.soffid.com/uploads/images/gallery/2023-02/image-1677150674570.png)

<span style="color: #a6d100; font-weight: bold; font-size: 18px;">2. </span>You must follow the instructions depending on the previous selection.

<span style="color: #a6d100; font-weight: bold; font-size: 18px;">2.1. </span>Debian, Ubuntu, or any other Debian derivatives

[![image-1677150856900.png](https://bookstack.soffid.com/uploads/images/gallery/2023-02/scaled-1680-/image-1677150856900.png)](https://bookstack.soffid.com/uploads/images/gallery/2023-02/image-1677150856900.png)

<span style="color: #a6d100; font-weight: bold; font-size: 18px;">2.2. </span>Redhat, Centos, or Suse

[![image-1677150880354.png](https://bookstack.soffid.com/uploads/images/gallery/2023-02/scaled-1680-/image-1677150880354.png)](https://bookstack.soffid.com/uploads/images/gallery/2023-02/image-1677150880354.png)

<span style="color: #a6d100; font-weight: bold; font-size: 18px;">2.3. </span>Windows

[![image-1677150906931.png](https://bookstack.soffid.com/uploads/images/gallery/2023-02/scaled-1680-/image-1677150906931.png)](https://bookstack.soffid.com/uploads/images/gallery/2023-02/image-1677150906931.png)

<span style="color: #a6d100; font-weight: bold; font-size: 18px;">2.4. </span>Docker

[![image-1677150930165.png](https://bookstack.soffid.com/uploads/images/gallery/2023-02/scaled-1680-/image-1677150930165.png)](https://bookstack.soffid.com/uploads/images/gallery/2023-02/image-1677150930165.png)

<span style="color: #a6d100; font-weight: bold; font-size: 18px;">3. </span>Finally, Soffid will detect that the Sync Server has been successfully installed and you can click the Finish button.

[![image-1677151000904.png](https://bookstack.soffid.com/uploads/images/gallery/2023-02/scaled-1680-/image-1677151000904.png)](https://bookstack.soffid.com/uploads/images/gallery/2023-02/image-1677151000904.png)

# Create identities (manually, CSV file or authoritative source)

## Description

You need to register the identities to manage and protect them. This wizard allows you to choose the easiest way to do it.

## Step-by-step

<span style="color: #a6d100; font-weight: bold; font-size: 18px;">1. </span>First, you must select one option to register the identities. Soffid allows you three options.

[![image-1677151715487.png](https://bookstack.soffid.com/uploads/images/gallery/2023-02/scaled-1680-/image-1677151715487.png)](https://bookstack.soffid.com/uploads/images/gallery/2023-02/image-1677151715487.png)

<span style="color: #a6d100; font-weight: bold; font-size: 18px;">2. </span>You must follow the steps, depending on the selected option:

<span style="color: #a6d100; font-weight: bold; font-size: 18px;">2.1. </span>**Load from a CSV file**: this option allows you to load identities from a CSV file.

<span style="color: #a6d100; font-weight: bold; font-size: 18px;">2.1.1. </span>First of all, you need to pick up the CSV file.

[![image-1677151980079.png](https://bookstack.soffid.com/uploads/images/gallery/2023-02/scaled-1680-/image-1677151980079.png)](https://bookstack.soffid.com/uploads/images/gallery/2023-02/image-1677151980079.png)

<span style="color: #a6d100; font-weight: bold; font-size: 18px;">2.1.2. </span>Second, Soffid will display the file data to check contents

[![image-1677152756166.png](https://bookstack.soffid.com/uploads/images/gallery/2023-02/scaled-1680-/image-1677152756166.png)](https://bookstack.soffid.com/uploads/images/gallery/2023-02/image-1677152756166.png)

<span style="color: #a6d100; font-weight: bold; font-size: 18px;">2.1.3. </span>Then you must select the proper mapping for each CSV file column. And finally, click the Import Button and Soffid will add the identities to the platform.

[![image-1677152797214.png](https://bookstack.soffid.com/uploads/images/gallery/2023-02/scaled-1680-/image-1677152797214.png)](https://bookstack.soffid.com/uploads/images/gallery/2023-02/image-1677152797214.png)

<span style="color: #a6d100; font-weight: bold; font-size: 18px;">2.1.4. </span>Soffid will display the result of the process.

[![image-1677152920695.png](https://bookstack.soffid.com/uploads/images/gallery/2023-02/scaled-1680-/image-1677152920695.png)](https://bookstack.soffid.com/uploads/images/gallery/2023-02/image-1677152920695.png)

<span style="color: #a6d100; font-weight: bold; font-size: 18px;">2.2. </span>**Configure an authoritative data source to always have up-to-date information**: this option allows you to configure an Active Directory agent, or a Relational database agent to load the identities.

Once the process will finish, you could check the new agent on the agent's page `Main Menu > Administration > Configuration > Integration engine > Agents`

<p class="callout info">For more information about the agents, you can visit [the Agents page](https://bookstack.soffid.com/books/soffid-3-reference-guide/page/agents).</p>

[![image-1677152049535.png](https://bookstack.soffid.com/uploads/images/gallery/2023-02/scaled-1680-/image-1677152049535.png)](https://bookstack.soffid.com/uploads/images/gallery/2023-02/image-1677152049535.png)

<span style="color: #a6d100; font-weight: bold; font-size: 18px;">2.2.1. </span>Active Directory

- To configure the AD connection you must fill in the required fields and click the Next button.
- Then Soffid will run the Authoritative load and the Reconcile process
- Finally, you could check the result on the [Scheduled tasks ](https://bookstack.soffid.com/books/soffid-3-reference-guide/page/scheduled-tasks)page.

[![image-1685436631243.png](https://bookstack.soffid.com/uploads/images/gallery/2023-05/scaled-1680-/image-1685436631243.png)](https://bookstack.soffid.com/uploads/images/gallery/2023-05/image-1685436631243.png)

<span style="color: #a6d100; font-weight: bold; font-size: 18px;">2.2.2. </span>Relational database (SQL)

[![image-1685436774882.png](https://bookstack.soffid.com/uploads/images/gallery/2023-05/scaled-1680-/image-1685436774882.png)](https://bookstack.soffid.com/uploads/images/gallery/2023-05/image-1685436774882.png)

<span style="color: #a6d100; font-weight: bold; font-size: 18px;">2.3. </span>**Register them manually**: this option browses to the **[User page](https://bookstack.soffid.com/books/soffid-3-reference-guide/page/users)** to register the identities manually

[![image-1677153597024.png](https://bookstack.soffid.com/uploads/images/gallery/2023-02/scaled-1680-/image-1677153597024.png)](https://bookstack.soffid.com/uploads/images/gallery/2023-02/image-1677153597024.png)

# Add applications

## Description

The wizard allows you to add Applications or **[Information Systems](https://bookstack.soffid.com/books/soffid-3-reference-guide/page/information-systems)** to Soffid as well. The wizard allows you to choose from an application list. Once you choose one of them, you must fill in the required fields to connect to this application. Then the Reconcile process will be launched.

## Step-by-step

<span style="color: #a6d100; font-weight: bold; font-size: 18px;">1. </span>First, you need to select the proper application to add. Soffid provides you a huge application list to configure.

[![image-1677497120165.png](https://bookstack.soffid.com/uploads/images/gallery/2023-02/scaled-1680-/image-1677497120165.png)](https://bookstack.soffid.com/uploads/images/gallery/2023-02/image-1677497120165.png)

<span style="color: #a6d100; font-weight: bold; font-size: 18px;">2. </span>Once you select the application, you must configure the connection parameters.

[![image-1685437011704.png](https://bookstack.soffid.com/uploads/images/gallery/2023-05/scaled-1680-/image-1685437011704.png)](https://bookstack.soffid.com/uploads/images/gallery/2023-05/image-1685437011704.png)

<span style="color: #a6d100; font-weight: bold; font-size: 18px;">3. </span>Then, Soffid allows you to choose the strategy to load accounts.

[![image-1685437664369.png](https://bookstack.soffid.com/uploads/images/gallery/2023-05/scaled-1680-/image-1685437664369.png)](https://bookstack.soffid.com/uploads/images/gallery/2023-05/image-1685437664369.png)

<span style="color: #a6d100; font-weight: bold; font-size: 18px;">4. </span>Then Soffid will run the reconcile process

[![image-1678090555705.png](https://bookstack.soffid.com/uploads/images/gallery/2023-03/scaled-1680-/image-1678090555705.png)](https://bookstack.soffid.com/uploads/images/gallery/2023-03/image-1678090555705.png)

<span style="color: #a6d100; font-weight: bold; font-size: 18px;">5. </span>Finally, the process ends.

[![image-1685437831278.png](https://bookstack.soffid.com/uploads/images/gallery/2023-05/scaled-1680-/image-1685437831278.png)](https://bookstack.soffid.com/uploads/images/gallery/2023-05/image-1685437831278.png)

# Design user life cycle workflows

## Description

When you select the option "Design user life cycle workflows", Soffid will browse to the BPM Editor page, where you could define new workflows or import existing workflows from a file.

<p class="callout info">For more information, you can visit [the BPM Editor book](https://bookstack.soffid.com/books/bpm-editor).</p>

## Screen overview

[![image-1676907389549.png](https://bookstack.soffid.com/uploads/images/gallery/2023-02/scaled-1680-/image-1676907389549.png)](https://bookstack.soffid.com/uploads/images/gallery/2023-02/image-1676907389549.png)

# IRC

Identity Risk & Compliance

# Create SoD matrix

## Description

The segregation of duties (SoD) is a fundamental element of internal controls, defined to prevent error and fraud. Segregation of duties ensures that at least two individuals are responsible for the separate parts of any task.

<p class="callout info">You can find additional information by visiting **[the Segregation of Duties page](https://bookstack.soffid.com/books/soffid-3-reference-guide/page/segregation-of-duties-sod)**.</p>

## Step-by-step

<span style="color: #a6d100; font-weight: bold; font-size: 18px;">1. </span>First, you must select the Create SoD matrix and click the OK button.

[![image-1676992791359.png](https://bookstack.soffid.com/uploads/images/gallery/2023-02/scaled-1680-/image-1676992791359.png)](https://bookstack.soffid.com/uploads/images/gallery/2023-02/image-1676992791359.png)

<span style="color: #a6d100; font-weight: bold; font-size: 18px;">2. </span>Once you click the OK button, Soffid will browse to the Segregation of Duties page in order to add a new SoD

[![image-1677072359690.png](https://bookstack.soffid.com/uploads/images/gallery/2023-02/scaled-1680-/image-1677072359690.png)](https://bookstack.soffid.com/uploads/images/gallery/2023-02/image-1677072359690.png)

<span style="color: #a6d100; font-weight: bold; font-size: 18px;">3. </span>Finally you must save or Apply changes to save the SoD.

[![image-1677499985787.png](https://bookstack.soffid.com/uploads/images/gallery/2023-02/scaled-1680-/image-1677499985787.png)](https://bookstack.soffid.com/uploads/images/gallery/2023-02/image-1677499985787.png)

## Standard attributes<svg class="svg-icon" data-icon="link" role="presentation" viewbox="0 0 24 24" xmlns="http://www.w3.org/2000/svg"></svg>

- **Name**: name of the segregation separation of duties
- **Information System**: asset or application, from a functional point of view, on which the permissions are granted or revoked.
- **Type**: type of segregation 
    - **Trigger on all permissions**: no user can be assigned the roles added to the role list.
    - **Trigger on some permissions**: if you select that option, you have to fill in the number of roles that can not match. Soffid will not allow you to assign to a user more than the number indicated of the roles added to the role list.
    - **Query permissions matrix**: Soffid displays a matrix that allows you to select the risk between pairs of roles, those roles are the roles added to the role list.
- **Risk**: level of risk: 
    - **Low**.
    - **High**.
    - **Forbidden**: it is not allowed that one user to have assigned the roles defined on the role list.
    - **None**: there is no risk.
- **Role List**: list of roles to keep in mind on the segregation of duties.

# Schedule weekly risk report

## Description

The wizard allows you to schedule a new Weekly risk report. It is a document that provides an overview of the potential risks. The information in this document is related to the rules defined in the SoD.

<p class="callout info">For more information, you can visit [the Scheduled reports page](https://bookstack.soffid.com/books/reporting/page/scheduled-reports).</p>

## Step-by-step

<span style="color: #a6d100; font-weight: bold; font-size: 18px;">1. </span>First, you must select the Schedule weekly risk report and click the OK button.

[![image-1676993208396.png](https://bookstack.soffid.com/uploads/images/gallery/2023-02/scaled-1680-/image-1676993208396.png)](https://bookstack.soffid.com/uploads/images/gallery/2023-02/image-1676993208396.png)

<span style="color: #a6d100; font-weight: bold; font-size: 18px;">2. </span>Then, Soffid will browse to the configure report page and allows you to configure the Weekly risk report.

[![image-1676994262683.png](https://bookstack.soffid.com/uploads/images/gallery/2023-02/scaled-1680-/image-1676994262683.png)](https://bookstack.soffid.com/uploads/images/gallery/2023-02/image-1676994262683.png)

<span style="color: #a6d100; font-weight: bold; font-size: 18px;">3. </span>Finally you must accept the changes, and the report will be displayed on the Scheduled reports page

[![image-1677500269887.png](https://bookstack.soffid.com/uploads/images/gallery/2023-02/scaled-1680-/image-1677500269887.png)](https://bookstack.soffid.com/uploads/images/gallery/2023-02/image-1677500269887.png)

## Standard attributes

- **Report**: name of the report.
- **Schedule name**: identified name.
- **Month**: number of the month (1-12) when the task will be performed.
- **Day**: number of the day (1-31) when the task will be performed.
- **Hour**: hour (0-23) when the task will be performed.
- **Minute**: minute (0-59) when the task will be performed.
- **Day of week**: number of the day (0-7 where 0 means Sunday) of the week when the task will be performed.
- **Access Control List**: to prevent unauthorized usage. Will be granted to users, groups or roles.

For each value of month, day, hour, minute, or day of the week:

<div class="pointer-container" id="bkmrk-%C2%A0-1"><div class="pointer anim is-page-editable"><svg class="svg-icon" data-icon="link" role="presentation" viewbox="0 0 24 24" xmlns="http://www.w3.org/2000/svg"></svg><div class="input-group inline block"> <button class="button outline icon" data-clipboard-target="#pointer-url" title="Copy Link" type="button"><svg class="svg-icon" data-icon="copy" role="presentation" viewbox="0 0 24 24" xmlns="http://www.w3.org/2000/svg"></svg></button></div><svg class="svg-icon" data-icon="edit" role="presentation" viewbox="0 0 24 24" xmlns="http://www.w3.org/2000/svg"></svg></div></div>- \* means any month, day, hour, minute, or day of the week. e.g. \*/5 to schedule every five minutes.
- A single number specifies that unit value: 3
- Some comma separated numbers: 1,3,5,7
- A range of values: 1-5

# Design a recertification campaign

## Description

The wizard allows you to create a new recertification campaign. To be able to do this, Soffid has created two recertification policies, *All permissions* and *Critical permissions*.

<p class="callout info">For more information, you can visit **[the Recertification book](https://bookstack.soffid.com/books/recertification)**.</p>

<div class="pointer-container" id="bkmrk-%C2%A0-0"><div class="pointer anim is-page-editable"><svg class="svg-icon" data-icon="link" role="presentation" viewbox="0 0 24 24" xmlns="http://www.w3.org/2000/svg"></svg><div class="input-group inline block"> <button class="button outline icon" data-clipboard-target="#pointer-url" title="Copy Link" type="button"><svg class="svg-icon" data-icon="copy" role="presentation" viewbox="0 0 24 24" xmlns="http://www.w3.org/2000/svg"></svg></button></div><svg class="svg-icon" data-icon="edit" role="presentation" viewbox="0 0 24 24" xmlns="http://www.w3.org/2000/svg"></svg></div></div>## Step-by-step

<span style="color: #a6d100; font-weight: bold; font-size: 18px;">1. </span>First, you must select the Design a recertification campaign and click the OK button.

[![image-1676994032726.png](https://bookstack.soffid.com/uploads/images/gallery/2023-02/scaled-1680-/image-1676994032726.png)](https://bookstack.soffid.com/uploads/images/gallery/2023-02/image-1676994032726.png)

<span style="color: #a6d100; font-weight: bold; font-size: 18px;">2. </span>Then Soffid will browse the New recertification campaign

[![image-1677073016957.png](https://bookstack.soffid.com/uploads/images/gallery/2023-02/scaled-1680-/image-1677073016957.png)](https://bookstack.soffid.com/uploads/images/gallery/2023-02/image-1677073016957.png)

<span style="color: #a6d100; font-weight: bold; font-size: 18px;">3. </span>In this step you must write a campaign name and select a template.

<span style="color: #a6d100; font-weight: bold; font-size: 18px;">3.1. </span>Complete access review

<span style="color: #a6d100; font-weight: bold; font-size: 18px;">3.1.1. </span>Write a name, select the Complete access review, and click the Next button

[![image-1677501842688.png](https://bookstack.soffid.com/uploads/images/gallery/2023-02/scaled-1680-/image-1677501842688.png)](https://bookstack.soffid.com/uploads/images/gallery/2023-02/image-1677501842688.png)

<span style="color: #a6d100; font-weight: bold; font-size: 18px;">3.1.2. </span>Select the group or groups to apply the campaign and click the Next button

[![image-1677502241149.png](https://bookstack.soffid.com/uploads/images/gallery/2023-02/scaled-1680-/image-1677502241149.png)](https://bookstack.soffid.com/uploads/images/gallery/2023-02/image-1677502241149.png)

<span style="color: #a6d100; font-weight: bold; font-size: 18px;">3.1.3. </span>Select the Information systems to apply the campaign and click the Finish button

[![image-1677502349343.png](https://bookstack.soffid.com/uploads/images/gallery/2023-02/scaled-1680-/image-1677502349343.png)](https://bookstack.soffid.com/uploads/images/gallery/2023-02/image-1677502349343.png)

## Standard attributes

- **Name**: name to identify the campaign.
- **Template**: select the policy that will be applied. That has to be defined previously on the [Recertification policies page](https://bookstack.soffid.com/books/recertification/page/recertification-policies "Recertification policies").
- **Groups**: list of user groups where the campaign will be applied. You can choose one or more.
- **Information Systems**: list of information systems where the campaign will be applied. You can choose one or more.

# Create advanced authorization rules

## Description

This wizard allows you to browse the XACML Policy Management page to create new policies to add more complex and restricted rules to the authorizations.

<p class="callout info">For more information, you can visit [the XACML page](https://bookstack.soffid.com/books/xacml).</p>

<div class="pointer-container" id="bkmrk-%C2%A0-0"><div class="pointer anim is-page-editable"><svg class="svg-icon" data-icon="link" role="presentation" viewbox="0 0 24 24" xmlns="http://www.w3.org/2000/svg"></svg><div class="input-group inline block"> <button class="button outline icon" data-clipboard-target="#pointer-url" title="Copy Link" type="button"><svg class="svg-icon" data-icon="copy" role="presentation" viewbox="0 0 24 24" xmlns="http://www.w3.org/2000/svg"></svg></button></div><svg class="svg-icon" data-icon="edit" role="presentation" viewbox="0 0 24 24" xmlns="http://www.w3.org/2000/svg"></svg></div></div>## Screen overview

[![image-1676994068147.png](https://bookstack.soffid.com/uploads/images/gallery/2023-02/scaled-1680-/image-1676994068147.png)](https://bookstack.soffid.com/uploads/images/gallery/2023-02/image-1676994068147.png)

## Screen overview

<iframe allowfullscreen="allowfullscreen" height="314" src="https://www.youtube.com/embed/C3LMc4rrEQI?ref=0" width="560"></iframe>

## Related objects

- [Policy set](https://bookstack.soffid.com/books/xacml/page/policy-set "Policy set")
- [Policy](https://bookstack.soffid.com/books/xacml/page/policy "Policy")
- [Policy set reference](https://bookstack.soffid.com/books/xacml/page/policy-set-reference "Policy set reference")
- [Policy reference](https://bookstack.soffid.com/books/xacml/page/policy-reference "Policy reference")

# PAM

Privileged Access Management

# Discover your assets

## Description

Soffid allows you to configure the network discovery tool in a way to run the process to identify any asset present in your network.

<p class="callout info">For more information, you can visit [the Network discovery page](https://bookstack.soffid.com/books/pam-deployment/page/network-discovery).</p>

## Step-by-step

<span style="color: #a6d100; font-weight: bold; font-size: 18px;">1. </span>Once you select the Discover you assets option, Soffid will display the form to fill in.

<span style="color: #a6d100; font-weight: bold; font-size: 18px;">2. </span>You need to register your network data and click the Next button.

[![image-1677074814027.png](https://bookstack.soffid.com/uploads/images/gallery/2023-02/scaled-1680-/image-1677074814027.png)](https://bookstack.soffid.com/uploads/images/gallery/2023-02/image-1677074814027.png)

<span style="color: #a6d100; font-weight: bold; font-size: 18px;">3. </span>You need to register an account. You can choose to register a new one or to use an existing account.

<span style="color: #a6d100; font-weight: bold; font-size: 18px;">3.1. </span>If you select the *Register a new account* option, you must fill in the Login name and the password and click the Apply changes button

[![image-1677075386016.png](https://bookstack.soffid.com/uploads/images/gallery/2023-02/scaled-1680-/image-1677075386016.png)](https://bookstack.soffid.com/uploads/images/gallery/2023-02/image-1677075386016.png)

<span style="color: #a6d100; font-weight: bold; font-size: 18px;">3.2. </span>If you select *Use an existing account*, you must select an existing account in the system and click the Apply changes button.

[![image-1677663289187.png](https://bookstack.soffid.com/uploads/images/gallery/2023-03/scaled-1680-/image-1677663289187.png)](https://bookstack.soffid.com/uploads/images/gallery/2023-03/image-1677663289187.png)

<span style="color: #a6d100; font-weight: bold; font-size: 18px;">4. </span>Soffid display this message to indicate the network discovery is in process

[![image-1678181171257.png](https://bookstack.soffid.com/uploads/images/gallery/2023-03/scaled-1680-/image-1678181171257.png)](https://bookstack.soffid.com/uploads/images/gallery/2023-03/image-1678181171257.png)

<span style="color: #a6d100; font-weight: bold; font-size: 18px;">5. </span>If you click the Finish button, Soffid will display the Network discovery monitoring.

[![image-1678181285472.png](https://bookstack.soffid.com/uploads/images/gallery/2023-03/scaled-1680-/image-1678181285472.png)](https://bookstack.soffid.com/uploads/images/gallery/2023-03/image-1678181285472.png)

# Publish accounts in the password vault

## Description

This wizard allows you to publish some accounts in the password vault in order to save and manage these accounts and their password.

<p class="callout info">For more information, you can visit [the Password vault page](https://bookstack.soffid.com/books/soffid-3-reference-guide/page/password-vault).</p>

## Step-by-step

<span style="color: #a6d100; font-weight: bold; font-size: 18px;">1. </span>Once you select the *Public accounts in the password vault* option, Soffid will display the following wizard

<span style="color: #a6d100; font-weight: bold; font-size: 18px;">2. </span>You must select the accounts you want to publish and click the Next button.

[![image-1677665161084.png](https://bookstack.soffid.com/uploads/images/gallery/2023-03/scaled-1680-/image-1677665161084.png)](https://bookstack.soffid.com/uploads/images/gallery/2023-03/image-1677665161084.png)

<span style="color: #a6d100; font-weight: bold; font-size: 18px;">3. </span>Then, Soffid will configure the password vault.

[![image-1677665252320.png](https://bookstack.soffid.com/uploads/images/gallery/2023-03/scaled-1680-/image-1677665252320.png)](https://bookstack.soffid.com/uploads/images/gallery/2023-03/image-1677665252320.png)

<span style="color: #a6d100; font-weight: bold; font-size: 18px;">4. </span>When you click the Finish button, Soffid will browse to the Password vault page. On this page, you could check and update the permissions.

[![image-1677665399042.png](https://bookstack.soffid.com/uploads/images/gallery/2023-03/scaled-1680-/image-1677665399042.png)](https://bookstack.soffid.com/uploads/images/gallery/2023-03/image-1677665399042.png)

[![image-1677665440094.png](https://bookstack.soffid.com/uploads/images/gallery/2023-03/scaled-1680-/image-1677665440094.png)](https://bookstack.soffid.com/uploads/images/gallery/2023-03/image-1677665440094.png)

# Create monitoring and recording policies

## Description

PAM policy is a subset of cybersecurity policies that deal with privileged access. This determines which users can have privileged access to specific systems, when, and for how long.

You can check the policies in the following menu option: `Main Menu > Administration > Configuration > Security settings > PAM policies`

<p class="callout info">For more information, you can visit [the PAM policies page.](https://bookstack.soffid.com/books/pam-deployment/page/pam-policies)</p>

## Step-by-step

<span style="color: #a6d100; font-weight: bold; font-size: 18px;">1. </span>Once you click the *Create monitoring and recording policies* option, Soffid will create a default policy.

[![image-1678104384200.png](https://bookstack.soffid.com/uploads/images/gallery/2023-03/scaled-1680-/image-1678104384200.png)](https://bookstack.soffid.com/uploads/images/gallery/2023-03/image-1678104384200.png)

<span style="color: #a6d100; font-weight: bold; font-size: 18px;">2. </span>When you click the Ok button, Soffid will browse to the created policy and allows you to update the default configuration.

[![image-1678106829891.png](https://bookstack.soffid.com/uploads/images/gallery/2023-03/scaled-1680-/image-1678106829891.png)](https://bookstack.soffid.com/uploads/images/gallery/2023-03/image-1678106829891.png)

# Create MFA policies

## Description

This wizard allows you to configure the access control rules for Soffid Console. By default, an OTP will be required to access to the Password vault or application menu.

You can check the configuration in the following menu option: `<span class="link" id="bkmrk-main-menu">Main Menu</span><span id="bkmrk-%C2%A0%3E%C2%A0"> > </span><span class="link" id="bkmrk-administration">Administration</span><span id="bkmrk-%C2%A0%3E%C2%A0-0"> > </span><span class="link" id="bkmrk-configuration">Configuration</span><span id="bkmrk-%C2%A0%3E%C2%A0-1"> > </span><span class="link" id="bkmrk-security-settings">Security settings</span><span id="bkmrk-%C2%A0%3E%C2%A0-2"> > </span>Authentication`

<span id="bkmrk--2"></span>

<p class="callout info">For more information, you can visit [the Two-factor authentication (2FA) book](https://bookstack.soffid.com/books/two-factor-authentication-2fa-VsJ) and the [Second Factor Authentication configuration](https://bookstack.soffid.com/link/164#bkmrk-second-factor-authen)</p>

## Step-by-step

<span style="color: #a6d100; font-weight: bold; font-size: 18px;">1. </span>Once you select the *Create monitoring and reporting policies* option, Soffid will launch the following wizard

[![image-1677142847903.png](https://bookstack.soffid.com/uploads/images/gallery/2023-02/scaled-1680-/image-1677142847903.png)](https://bookstack.soffid.com/uploads/images/gallery/2023-02/image-1677142847903.png)

<span style="color: #a6d100; font-weight: bold; font-size: 18px;">2. </span>If you click the Apply now button, Soffid will browse to the Authentication page, allowing you to configure the Second Factor Authentication.

[![image-1677146097093.png](https://bookstack.soffid.com/uploads/images/gallery/2023-02/scaled-1680-/image-1677146097093.png)](https://bookstack.soffid.com/uploads/images/gallery/2023-02/image-1677146097093.png)

<span style="color: #a6d100; font-weight: bold; font-size: 18px;">3. </span>To confirm the changes, you must click the Confirm changes button.

# AM

Access Management & SSO

# Create identities (manually, CSV file, or authoritative source)

{{@718}}

# Add applications

## Description

This wizard allows you to add a new Service Provider, that is, to configure an application that relies on an Identity Provider (IdP) to authenticate users and provide access to its services.

To be able to add new applications (SP), you must install the Federation Addon.

## Step-by-step

<span style="color: #a6d100; font-weight: bold; font-size: 18px;">1. </span>If you have not previously installed the Federation Addon, the first time you select the *Add application* option, Soffid will require to **install the Federation Addon**.

[![image.png](https://bookstack.soffid.com/uploads/images/gallery/2025-02/scaled-1680-/aJAQxBVokVmm6ZZX-image.png)](https://bookstack.soffid.com/uploads/images/gallery/2025-02/aJAQxBVokVmm6ZZX-image.png)

When you click the OK button, Soffid will browse to the Soffid Download Area where you can find the Federation Addon. To install Federation Addon you can follow the steps [How to install Federation in Soffid?](https://bookstack.soffid.com/books/federation-guide/page/how-to-install-federation-in-soffid)

<span style="color: #a6d100; font-weight: bold; font-size: 18px;">2. </span>Once you select the *Add applicatio*n option, Soffid will display the wizard to register the Identity Provider, if it does not exist previously.

[![image-1706615738719.png](https://bookstack.soffid.com/uploads/images/gallery/2024-01/scaled-1680-/image-1706615738719.png)](https://bookstack.soffid.com/uploads/images/gallery/2024-01/image-1706615738719.png)

<span style="color: #a6d100; font-weight: bold; font-size: 18px;">3. </span>You must select the application you want to add.

[![image-1678779815350.png](https://bookstack.soffid.com/uploads/images/gallery/2023-03/scaled-1680-/image-1678779815350.png)](https://bookstack.soffid.com/uploads/images/gallery/2023-03/image-1678779815350.png)

<span style="color: #a6d100; font-weight: bold; font-size: 18px;">3.1. </span>Soffid app:

<span style="color: #a6d100; font-weight: bold; font-size: 18px;">3.1.1. </span>The Finish step will be displayed.

[![image-1678779871340.png](https://bookstack.soffid.com/uploads/images/gallery/2023-03/scaled-1680-/image-1678779871340.png)](https://bookstack.soffid.com/uploads/images/gallery/2023-03/image-1678779871340.png)

<span style="color: #a6d100; font-weight: bold; font-size: 18px;">3.1.1. </span>If you click the Finish button, Soffid will display the Service Provider page.

[![image-1677671303079.png](https://bookstack.soffid.com/uploads/images/gallery/2023-03/scaled-1680-/image-1677671303079.png)](https://bookstack.soffid.com/uploads/images/gallery/2023-03/image-1677671303079.png)

<span style="color: #a6d100; font-weight: bold; font-size: 18px;">3.2. </span>AWS app:

<span style="color: #a6d100; font-weight: bold; font-size: 18px;">3.2.1 </span>Soffid will download the proper certificate.

[![image-1677672235598.png](https://bookstack.soffid.com/uploads/images/gallery/2023-03/scaled-1680-/image-1677672235598.png)](https://bookstack.soffid.com/uploads/images/gallery/2023-03/image-1677672235598.png)

<span style="color: #a6d100; font-weight: bold; font-size: 18px;">3.2.2 </span>Once, you download the certificate, Soffid will display the Configure application step. You must follow the indicated steps at this point and click the Next button.

[![image-1677672319865.png](https://bookstack.soffid.com/uploads/images/gallery/2023-03/scaled-1680-/image-1677672319865.png)](https://bookstack.soffid.com/uploads/images/gallery/2023-03/image-1677672319865.png)

<span style="color: #a6d100; font-weight: bold; font-size: 18px;">3.2.2 </span>Then, you must upload the metadata of your service provider and click the Finish button.

[![image-1677672438056.png](https://bookstack.soffid.com/uploads/images/gallery/2023-03/scaled-1680-/image-1677672438056.png)](https://bookstack.soffid.com/uploads/images/gallery/2023-03/image-1677672438056.png)

<span style="color: #a6d100; font-weight: bold; font-size: 18px;">3.3. </span>Google workplace app:

<span style="color: #a6d100; font-weight: bold; font-size: 18px;">3.3.1 </span>Soffid will download the proper certificate.

[![image-1677672235598.png](https://bookstack.soffid.com/uploads/images/gallery/2023-03/scaled-1680-/image-1677672235598.png)](https://bookstack.soffid.com/uploads/images/gallery/2023-03/image-1677672235598.png)

<span style="color: #a6d100; font-weight: bold; font-size: 18px;">3.3.2 </span>Once, you download the certificate, Soffid will display the Configure application step. You must follow the indicated steps at this point, fill in the Domain, and click the Next button.

[![image-1677682975815.png](https://bookstack.soffid.com/uploads/images/gallery/2023-03/scaled-1680-/image-1677682975815.png)](https://bookstack.soffid.com/uploads/images/gallery/2023-03/image-1677682975815.png)

<span style="color: #a6d100; font-weight: bold; font-size: 18px;">3.3.3 </span>Then, you must click the Finish button.

[![image-1677683080657.png](https://bookstack.soffid.com/uploads/images/gallery/2023-03/scaled-1680-/image-1677683080657.png)](https://bookstack.soffid.com/uploads/images/gallery/2023-03/image-1677683080657.png)

<span style="color: #a6d100; font-weight: bold; font-size: 18px;">3.3.4 </span>Finally, Soffid will browse to the Service Provider page where you can finish the Service provider configuration.

[![image-1677683851230.png](https://bookstack.soffid.com/uploads/images/gallery/2023-03/scaled-1680-/image-1677683851230.png)](https://bookstack.soffid.com/uploads/images/gallery/2023-03/image-1677683851230.png)

<span style="color: #a6d100; font-weight: bold; font-size: 18px;">3.4. </span>Microsoft 365 app:

<span style="color: #a6d100; font-weight: bold; font-size: 18px;">3.4.1. </span>When you select this option, Soffid will display the Configure application step. You must follow the indicated steps at this point, and click the Next button.

[![image-1677683934770.png](https://bookstack.soffid.com/uploads/images/gallery/2023-03/scaled-1680-/image-1677683934770.png)](https://bookstack.soffid.com/uploads/images/gallery/2023-03/image-1677683934770.png)

<span style="color: #a6d100; font-weight: bold; font-size: 18px;">3.4.2 </span>Then, you must click the Finish button.

[![image-1677683080657.png](https://bookstack.soffid.com/uploads/images/gallery/2023-03/scaled-1680-/image-1677683080657.png)](https://bookstack.soffid.com/uploads/images/gallery/2023-03/image-1677683080657.png)

<span style="color: #a6d100; font-weight: bold; font-size: 18px;">3.4.3 </span>Finally, Soffid will browse to the Service Provider page where you can finish the Service provider configuration.

[![image-1677684047850.png](https://bookstack.soffid.com/uploads/images/gallery/2023-03/scaled-1680-/image-1677684047850.png)](https://bookstack.soffid.com/uploads/images/gallery/2023-03/image-1677684047850.png)

<span style="color: #a6d100; font-weight: bold; font-size: 18px;">3.5. </span>OpenID app:

<span style="color: #a6d100; font-weight: bold; font-size: 18px;">3.5.1. </span>When you select this option, Soffid will display the Configure application step. You must configure your Service Provider, and click the Next button.

[![image-1677684651700.png](https://bookstack.soffid.com/uploads/images/gallery/2023-03/scaled-1680-/image-1677684651700.png)](https://bookstack.soffid.com/uploads/images/gallery/2023-03/image-1677684651700.png)

<span style="color: #a6d100; font-weight: bold; font-size: 18px;">3.5.2. </span>Then Soffid will return you the Client id and Client secret

[![image-1677684676985.png](https://bookstack.soffid.com/uploads/images/gallery/2023-03/scaled-1680-/image-1677684676985.png)](https://bookstack.soffid.com/uploads/images/gallery/2023-03/image-1677684676985.png)

<span style="color: #a6d100; font-weight: bold; font-size: 18px;">3.5.3 </span>Then, you must click the Finish button.

[![image-1677683080657.png](https://bookstack.soffid.com/uploads/images/gallery/2023-03/scaled-1680-/image-1677683080657.png)](https://bookstack.soffid.com/uploads/images/gallery/2023-03/image-1677683080657.png)

<span style="color: #a6d100; font-weight: bold; font-size: 18px;">3.5.4 </span>Finally, Soffid will browse to the Service Provider page where you can finish the Service provider configuration.

[![image-1677684869231.png](https://bookstack.soffid.com/uploads/images/gallery/2023-03/scaled-1680-/image-1677684869231.png)](https://bookstack.soffid.com/uploads/images/gallery/2023-03/image-1677684869231.png)

<span style="color: #a6d100; font-weight: bold; font-size: 18px;">3.6. </span>SAML 2.0 app:

<span style="color: #a6d100; font-weight: bold; font-size: 18px;">3.6.1 </span>Soffid will download the metadata XML file.

[![image-1677686059860.png](https://bookstack.soffid.com/uploads/images/gallery/2023-03/scaled-1680-/image-1677686059860.png)](https://bookstack.soffid.com/uploads/images/gallery/2023-03/image-1677686059860.png)

<span style="color: #a6d100; font-weight: bold; font-size: 18px;">3.5.2 </span>Once, you download the metadata file, Soffid will display the steps to follow.

[![image-1677686120040.png](https://bookstack.soffid.com/uploads/images/gallery/2023-03/scaled-1680-/image-1677686120040.png)](https://bookstack.soffid.com/uploads/images/gallery/2023-03/image-1677686120040.png)

<span style="color: #a6d100; font-weight: bold; font-size: 18px;">3.5.3 </span>Then, you have to upload the metadata file generated by the Service Provider

[![image-1677686216222.png](https://bookstack.soffid.com/uploads/images/gallery/2023-03/scaled-1680-/image-1677686216222.png)](https://bookstack.soffid.com/uploads/images/gallery/2023-03/image-1677686216222.png)

# Create MFA policies

## Description

This wizard will help you to configure multi-factor authentication in order to expand security. This process requires users to provide two or more forms of identification before being granted access to a system or application.

<p class="callout info">For more information, you can visit [the Two-factor authentication (2FA) book](https://bookstack.soffid.com/books/two-factor-authentication-2fa-VsJ).</p>

## Step-by-step

<span style="color: #a6d100; font-weight: bold; font-size: 18px;">1. </span>If you have not previously installed the Federation Addon, the first time you select the *Create MFA policies* option, Soffid will require to **install the Federation and the OTP Addons**.

[![image.png](https://bookstack.soffid.com/uploads/images/gallery/2025-02/scaled-1680-/9gfTecsUY1WjDknX-image.png)](https://bookstack.soffid.com/uploads/images/gallery/2025-02/9gfTecsUY1WjDknX-image.png)

<span style="color: #a6d100; font-weight: bold; font-size: 18px;">2. </span>Frist, you must select the authentication factor to use

[![image-1677146953516.png](https://bookstack.soffid.com/uploads/images/gallery/2023-02/scaled-1680-/image-1677146953516.png)](https://bookstack.soffid.com/uploads/images/gallery/2023-02/image-1677146953516.png)

<span style="color: #a6d100; font-weight: bold; font-size: 18px;">3. </span>Second, you must select the delivery method to use. If you select the second option, you have to select the users to whom the instructions will be sent.

[![image-1677147051712.png](https://bookstack.soffid.com/uploads/images/gallery/2023-02/scaled-1680-/image-1677147051712.png)](https://bookstack.soffid.com/uploads/images/gallery/2023-02/image-1677147051712.png)

<span style="color: #a6d100; font-weight: bold; font-size: 18px;">4. </span>Next, you must select which users will have the second authentication factor activated.

[![image-1677147755823.png](https://bookstack.soffid.com/uploads/images/gallery/2023-02/scaled-1680-/image-1677147755823.png)](https://bookstack.soffid.com/uploads/images/gallery/2023-02/image-1677147755823.png)

<span style="color: #a6d100; font-weight: bold; font-size: 18px;">5. </span>Finally, the changes will be applied and the process will be finished.

[![image-1677147905326.png](https://bookstack.soffid.com/uploads/images/gallery/2023-02/scaled-1680-/image-1677147905326.png)](https://bookstack.soffid.com/uploads/images/gallery/2023-02/image-1677147905326.png)

# Create adaptive authentication rules

## Description

Adaptive authentication rules are a set of security policies and mechanisms that adjust authentication requirements. These rules determine the strength of authentication required for each user, based on factors such as their location, device, past login behavior, and other risk indicators.

<p class="callout info">For more information, you can visit the [Condition for Adaptive authentication page](https://bookstack.soffid.com/books/federation/page/condition-for-adaptive-authentication).</p>

## Step-by-step

<span style="color: #a6d100; font-weight: bold; font-size: 18px;">1. </span>If you have not previously installed the Federation Addon, the first time you select the *Create MFA policies* option, Soffid will require to **install the Federation and the OTP Addons**.

[![image.png](https://bookstack.soffid.com/uploads/images/gallery/2025-02/scaled-1680-/Hrp87gsNIs26JsAl-image.png)](https://bookstack.soffid.com/uploads/images/gallery/2025-02/Hrp87gsNIs26JsAl-image.png)

<span style="color: #a6d100; font-weight: bold; font-size: 18px;">2. </span>You must select the *Create adaptive authentication rules* and then click the Ok button.

[![image-1678097740662.png](https://bookstack.soffid.com/uploads/images/gallery/2023-03/scaled-1680-/image-1678097740662.png)](https://bookstack.soffid.com/uploads/images/gallery/2023-03/image-1678097740662.png)

<span style="color: #a6d100; font-weight: bold; font-size: 18px;">3. </span>Then, Soffid will browse to the Adaptive authentication window, where you could configure it

[![image-1678098184254.png](https://bookstack.soffid.com/uploads/images/gallery/2023-03/scaled-1680-/image-1678098184254.png)](https://bookstack.soffid.com/uploads/images/gallery/2023-03/image-1678098184254.png)