
Changingserverpolicysettings
Serverpolicysettingsincludevariouswaystomanageuserenrollment,credentials,andclientportaland
BIOSsettingsfortheLenovoHardwarePasswordManagerdevicesyoumanage.Thesettingsarechanged
fromtheThinkManagementconsole;itemsthataffectindividualdevicesarethenheldinapendingqueue
untilthenexttimeeachdeviceisbootedandrequestsanupdatedpolicy.
Tochangeserverpolicysettings:
1.ClickRemoteActionsandPolicySettingsinthetoolboxorclickT ools➙ThinkVantageHardware
PasswordManager➙RemoteActionsandPolicySettings.
2.ClickUpdateServerPolicySettingsonthetoolbar.
3.Makechangesonthefourtabsinthedialogbox,andthenclickOKwhenyouhavenished.
ThetabsintheServerPolicySettingsdialogboxaredescribedasbelow.
•General-Thistabliststhename,IPaddress,andUDPportoftheHardwarePasswordManagerserver
usedtoauthenticateHardwarePasswordManagerusers.TheStatusofPortalServicesectionshows
whethertheportalserviceontheHardwarePasswordManagerserverisrunning.Theportalservice
isaUDPserver,oneofthecomponentsontheHardwarePasswordManagerserver.Itisusedfor
communicationwiththeHardwarePasswordManagerdeviceBIOSwhentheuserlogsonusingthe
intranetaccountlogin.Youcanstart,stop,orrestarttheserviceasneededfromthisdialogbox.
SelectAllowuserstoenrollonmultipledevicesifyouwanttoalloweachintranetaccounttoenroll
onmultipleHardwarePasswordManagerdevices.Ifthischeckboxiscleared,oneintranetaccount
canonlybeenrolledononedevice.
SelectEnable“one-touch”registrationifyouwanttopre-registernewHardwarePasswordManager
deviceswithone-touchfeaturesfromLenovo.One-touchregistrationautomaticallyregistersthedevice
andcreatestheemergencyadminaccountwhentheuserlogsintoWindows.SeealsoChapter5
“Deployment”onpage25
.
SelectEnablerstuserloggedonamachineasadministratorifyouwanttherstenrolleduserto
haveadministratorprivilegesintheBIOS.
•Credentials-Thistabdeterminesthelengthofauto-generatedpasswordsandthenumberofpassword
backupstokeep.BackupsareencryptedandstoredintheHardwarePasswordManagerdatabase.
Bydefault,auto-generatedhardwarepasswords,aswellasemergencyadminaccountpasswords,
arebetween15and20characterslong.Youcanchangetheminimumandmaximumnumbersfor
bothtypesofpasswords.Youcanalsospecifyhowmanybackupstosaveforhardwarepasswords.
Themaximumpasswordlengthis64.
•ClientPortal-ThistabspecieswhichmenuitemsareenabledfordisplayontheClientPortalmenuon
managedHardwarePasswordManagerdevices.TheuseraccessestheportalfromtheWindowsStart
menu(Start➙AllPrograms➙ThinkVantage➙HardwarePasswordManager).TheClientPortal
menuitemsarealwaysselected.WhenyouperformtaskssuchasRemoveUserafteryouenterthe
intranetcredentialsthatcorrelatetotheUser,ServiceTech,andAdministratorroles,youwillgetanerror
messageifyoudonothavetheclientportalrights.UserslogintoHardwarePasswordManagerdevices
withanassignedrole,whichcorrelatestotheusergroupthattheuserbelongsto.(See“Managing
HardwarePasswordManagergroups”onpage12
foradescriptionofroles.)So,forexample,auser
mightseealloptionsontheClientPortalbutaServiceTechmighthavealimitedsetofoptionsavailable.
Ifausertriesanoptionthatisnotselectedforthatrole,anerrormessagewillbedisplayed.
•BIOS-ThistabspecieswhichmenuitemsareenabledfordisplayontheBIOSmenuofmanaged
HardwarePasswordManagerdevices,andallowsyoutospecifywhichBIOSversionsareexcludedfrom
HardwarePasswordManagerdevicemanagement.BIOSmenuitemsareselectedseparatelyforthethree
userroles:User,ServiceTech,andAdministrator.UserslogintoHardwarePasswordManagerdevices
withanassignedrole,whichcorrelatestotheusergroupthattheuserbelongsto.(See“Managing
Chapter3.ManagingHardwarePasswordManagerdeviceswithThinkManagementConsole17
Comentarios a estos manuales