Course Description:
This two day course provides an overview of the administrative responsibilities associated with an RSA SecurID system. The working principles behind RSA Authentication Manager software and RSA SecurID authenticators are discussed, including product architecture, time and event synchronization, using external Identity Sources and exploring all aspects of an administrative structure. Extensive hands-on labs reinforce the administrative tasks involved in managing a user population and token assignment. The subject matter in this course prepares students with the classroom component recommended for the RSA SecurID Certified Administrator certification.
Who Should Take This Course?
This course is intended for the following audience
- Help Desk and End User administrators responsible for administering RSA Authentication Manager
- System administrators, security analysts, or web security specialists who are interested in employing or integrating strong user authentication
- Network and security engineers who need the background of overall system operation to augment their work in the RSA SecurID Installation and Configuration course
Course Prerequisites
- A functional knowledge of operating system and networking fundamentals
- Familiarity with network of OS administration
- Familiarity with basic operations involving LDAP directory services
Course Fee: $1,795
Course Outline
Unit 1 - RSA SecurID Overview
- RSA Authentication Manager System Overview
- RSA SecurID System Components
- RSA SecurID System Architecture
- RSA Authentication Manager Functional Components
- System Communication
- Authentication Manager Licensing
- RSA SecurID Security Features
Unit 2 – RSA SecurID Authenticators
- RSA SecurID Authenticators
- Time Synchronization
- Event Synchronization
- On-Demand Authentication
- RSA SecurID Authenticator Types
Unit 3 – Planning Administrative Structure
- Authentication Manager Administrative Structure
- Realms
- Identity Sources
- Security Domains
- Users and User Groups
- Deploying Planning
- Administrative Case Study
Unit 4 – Policy Management
- Policies
- Exercise 4.1: Establishing a Password Policy
- Lockout Policy
- Exercise 4.2: Establishing a Lockout Policy
- Self-service Troubleshooting Policy
- Exercise 4.3: Establishing a Self-service Troubleshooting Policy
- Token Policy
- Exercise 4.4: Establishing a Token Policy
- Offline Authentication and Windows Password Integration
- Offline Authentication Policy
- Exercise 4.5: Establishing an Offline Authentication Policy
- Authentication Grades
Unit 5 – Identity Sources
- Identity Sources
- Exercise 5.1: Defining Identity Sources
- Identity Attributes
- Exercise 5.2: Configuring Identity Attributes
Unit 6 – Security Domains
- Security Domains
- Administrative Roles and Security Domains
- Exercise 6.1: Structuring Security Domains
Unit 7 – Managing Users and User Groups
- Users and User Groups
- Adding Users
- User Groups
- Bulk Operations
- Exercise 7.1: Adding Users
- Exercise 7.2: Adding User Groups
Unit 8 – Agent Operations
- Authentication Agents
- Authentication Agent Administration
- Adding an Agent and Testing Agent Authentication
- Exercise 8.1: Managing Authentication Agents
- Exercise 8.2: (optional) Enable Agent for IIS and Configure Protection for a Web Page
- Exercise 8.3: (optional) Generating an Agent Configuration File
Unit 9 – Authenticator Operations
- Authenticators
- The Token Screen
- Miscellaneous Token Operations
- Token Assignment
- Exercise 9.1: Importing RSA SecurID Token Records
- Exercise 9.2: Associating Authenticators with Users
- Exercise 9.3: Testing Authentication
- Exercise 9.4: (optional) Using an Emergency Access Tokencode
Unit 10 – Delegated Administration
- Administrative Elements
- Administrative Roles
- Exercise 10.1: Creating Administrators
- Exercise 10.2: (optional) Experiment with Administrative Roles, Permissions, and Scope
Unit 11 – Reports and Logs
- Authentication Manager Reporting
- Report Generation
- Exercise 11.1: Creating Reports
- Authentication Manager Logging
- Log Archiving
- Exercise 11.2: Log Operations
- Activity Monitor
- Exercise 11.3: (optional) Using the Activity Monitor
- Instrumentation (SNMP)
- Exercise 11.4: (optional) SNMP Configuration
Unit 12 – Credential Manager
- Credential Manager
- Credential Manager Configuration
- Other Credential Manager Concerns
- Exercise 12.1: Managing Credential Manager
Unit 13 – Managing Software Authenticators
- RSA SecurID Software Token Overview
- Comparing and Contrasting RSA SecurID Hardware and Software Tokens
- Deploying an RSA SecurID Software Token
- Exercise 13.1: Issuing an RSA SecurID Software Token
Unit 14 – Managing RADIUS Users
- Authentication Manager and RADIUS Server
- RADIUS Administration
Unit 15 – Managing Realm Trusts
- Realm Trust Relationships
- Establishing a Trusted Realm
- Namespace Collisions
Unit 16 – Troubleshooting
- Troubleshooting User Problems