This documentation supports the 22.1 version of BMC Helix Single Sign-On, which is available only to BMC Helix customers (SaaS). 

To view an earlier version, select the version from the Product version menu.

Configuring settings for BMC Helix SSO administrators

As a tenant administrator, you can configure settings such as for BMC Helix SSO administrators.

To configure the maximum session time for administrators

  1. In the BMC Helix SSO Admin Console, select General > Basic.
  2. In the Max Admin Session Time field, set the time after which the admin session expires.

    When this value is selected, time constraints are automatically enforced. By default, one hour is set.

    Important

    The minimum value is 1 minute, and the maximum value is 1 year.

  3. Click Save.

To enable the lockout functionality for BMC Helix SSO administrators

By default, the account lockout functionality is disabled for the BMC Helix SSO Admin Console. You can set the number of login attempts for BMC Helix SSO administrator accounts before the accounts get locked out.  

  1. In the BMC Helix SSO Admin Console, select General > Basic.
  2. In the Admin Lockout Threshold field, enter the number of login attempts for administrators. 
    By default, the value is set to 0.

To disable interactive self-help for administrators in the BMC Helix SSO Admin Console

By default, the interactive self-help is enabled for BMC Helix SSO. The Self-Help menu is displayed on the right of any page in the BMC Helix SSO Admin Console. Click the Self-Help menu to view the available options, and then follow the instructions displayed on the screen to perform a desired action.


You can disable the self-help from being displayed in the BMC Helix SSO Admin Console. 

  1. In the BMC Helix SSO Admin Console, select General > Basic.
  2. Clear the Enable Interactive Help check box. 
  3. Click Save.
  4. To apply the changes, log out from the BMC Helix SSO Admin Console, and log in again.

To enable audit records on the BMC Helix SSO server

By default, audit is disabled for both administrator and end-user actions. You can enable audit records on the BMC Helix SSO server. The following screenshot shows the Audit section in the BMC Helix SSO Admin Console:

  1. In the BMC Helix SSO Admin Console, select General > Advanced.
  2. In the Audit section, select the appropriate option:
    - To enable audit records for administrator actions, select the Admin events check box.
    - To enable audit records for end-user actions, select the End-user events check box.
  3. Click Save.

When you enable audit logging, the Audit tab in the BMC Helix SSO Admin Console displays all actions performed by the administrator, end user, or both. By default, the Audit tab shows all logged administrator, end-user actions, or actions of both for the last day. You can get audit actions for a certain date and one session. For more information, see Reviewing audit records.  

To update the retention policy

By default, all logged audit actions are stored in the database for the last 120 days. You can change the number of days in the Retention policy field only if you have the administrator rights and enable administrator events audit or end-user events audit. The Retention policy option is enabled by default.

Important

The Retention policy option is available only for the SaaS tenant. To enable the Retention policy option, you must select the Admin events or End-user events check box, or both.

To change the number of days for logging audit records in the database, perform one or more of the following actions:

TaskSteps to perform

To configure the retention policy for audit logs

  1. In the Retention policy field, set a value to specify the number of days the audit logs are saved on the BMC Helix SSO server.

  2. Click Save.

To disable the retention policy

  1. In the Retention policy field, set 0 to save logs forever.

  2. Click Save.

To delete old audit logs

  1. In the Retention policy field, set a relatively small value, for example, one day.
  2. Click Save.
    All audit records older than the specified number of days are automatically deleted in 24 hours after the BMC Helix SSO server start.

Where to go from here

Configuring authentication for BMC Helix SSO administrators

Was this page helpful? Yes No Submitting... Thank you

Comments