Skip to main content
Skip table of contents

How to enable access to applications

General

With VISULOX Access Management it is possible to assign controlled access to the IT infrastructure for internal and external employees, administrators and IT service providers.

This is limited to defined times or time periods and always booked under their own individual reference numbers.

Prerequisites

For this example setup two users have to be registered in VISULOX PORTAL with the following settings:

UserRoleeMailSMSApplicationOther
MasterSupervisor<supervisor>@company.com-VISULOX Cockpit-
MillerUser<user>@company.com-VLX Jump Shell-

Supervisor Master enables and configures the access.

User Miller logs into VISULOX PORTAL and starts applications.

Supervisor Master: Enable access to applications for Miller

  1. Creating a new Access Policy in the Cockpit:

    A unique name for the policy must be entered: "POL-ACC".

    "Allowed" has to be selected to enable access for user Miller.

    A valid Ticket ID has to be entered: "A-1234".

    A comment for the policy can be entered as well.


    Selecting the Application Policy mode:


    • Example 1: Application access is allowed
    • Example 2: Application access is not allowed



  2. Setting the filter:

    Access will only be enabled for the  "VLX Jump Shell" application from user "Miller" in this example.

    It is also possible to set a filter for the Remote IP address or the Access point (not used in this example).

    It is possible to choose a time profile and a time zone from a dropdown list of pre-configured entries.

    The start and end time of the access can be chosen as well.

    The default values are fine for this example (always, Germany, 7days from now).

  3. On the Notification page, a notification script can be selected, which displays a "Send request" button if the session is locked.
    This makes only sense for an additional denied policy and is not used in this example. It is also possible to setup a request script,
    which allows to send mails to the requester and approver, who can allow, reject the request via mail.

Example 1: Miller starts an application with access allowed

User Miller starts the "VLX Jump Shell" application from his Workspace.

The application is not locked, working is possible.

Example 2: Miller starts an application with access not allowed

User Miller starts the "VLX Jump Shell" application from his Workspace.

The application is locked.


If a denied Access Policy with a notification script matches, a notification will be sent to the supervisor by clicking the "Send request" button.

If a denied Access Policy with a request script matches, mails are sent to the requester and the approver, who can allow, reject this request via mail.

The session can also be ended with the "End session" button.

Access check list with additional tests

FeatureExpected behaviourComment
Application access is allowed
  • User can start applications
  • Screen is not locked, working is possible

Application access is not allowed
  • User can start applications
  • Application is locked
  • User can enter a message for the supervisor and send it with the button "Send request"

Disabled
  • Application Policy has no effect, the next Policy, that matches will be used

Filter settings
  • User/group mask: all registered users get access to applications
  • Application mask: all registered applications are available for the access
  • Remote IP mask: all users connecting from the registered IP get access to applications
  • Access point mask: all users connecting over the registered access point get access to applications

Time frame
  • Time profile: different profiles are available e.g. alway, never, working hours, etc
  • Access is not allowed, if an application is started outside of the time profile
  • Time zone: different time zones can be selected for the access
  • Start/end time: start and end time for the access
  • Access is not allowed before or after the set start/end time

Notification
Events
  • All information about the access is displayed in the Cockpit

Related articles:

JavaScript errors detected

Please note, these errors can depend on your browser setup.

If this problem persists, please contact our support.