Cloud Administration Console Dashboard
a month ago

Cloud Administration Console Dashboard

The dashboard displays the deployment setup status, publishing status of configuration changes, the validity of domain certificates, component status, number of protected resources, and a graph of identity router activity.

For more information, see:

Deployment Setup and Configuration Status

After you decide which resources you want to protect and select the appropriate setup path, the dashboard guides you through the first-time setup process and displays the required components for those resources. Select one setup path. You can choose to protect:

  • Applications. Web applications using the SSO Service on the identity router and cloud based portals
  • Note:  The IDR Portal applications are available only if Identity Router based portal is enabled.
  • Relying parties. Web applications protected by Cloud Access Service (CAS). These can be individual web applications or third-party SSO service.
  • RADIUS clients. Configure authentication for RADIUS clients such as VPNs.

After initial setup, you can return to the dashboard page to configure additional services at any time. In the Protected Resources section, click a resource to view the components you need to configure. See how it works.

If you do not need to configure your deployment for Applications, Relying Parties, or RADIUS clients, you can skip the Getting Started setup paths and go directly to the dashboard.

Monitor Uptime Status for CAS

To view the status of the pod hosting your company services, see Monitor Uptime Status for Cloud Access Service for instructions.

Usage Information

The Usage information dashboard displays licensing and authenticator usage information for the ‘Cloud’ users and their credentials information. The dashboard is updated from cached data once every hour.

FieldDescription

Total Users

Total number of unique Cloud licensed users.

  • All Cloud Users: Total count of Cloud users, including the following:

    • A user who has a registered credential (See Total Cloud Credentials ).

    • A user who has authenticated successfully in the last six months.

    • A user whose record is managed as part of the Unified Directory counts as Cloud user. Cloud users also include both the local and external users managed in the Unified Directory and does not include the users synchronized through the Active Directory (AD) or LDAP. For more information, see Unified Directory Identity Sources

A successful authentication is counted any time CAS authenticates the user to allow access to a protected resource. This includes the following situations:

  • When users authenticate to CAS based on the access policy that may or may not require them to provide additional registered credentials. For example, if a user authenticates to CAS or My Page using a password only based on the access policy, it will be a successful authentication.

  • When users authenticate through CAS to access resources protected by Authentication Agents, RADIUS, or any custom-built clients. These Authentication Agents can be connected directly to CAS or via Authentication Manager as a secure proxy.

Note:  The MFA licenses used are counted as part of the Cloud users count in the last six months.

Total Cloud Credentials

Total number of credentials (or authenticators) that are registered and managed in the CAS.

The following authenticators must be registered with CAS:

  • RSA Authenticator App

  • SID 700 hardware authenticators that are managed in the Cloud Administration Console

  • DS100 (OTP & FIDO) hardware authenticators

  • Third Party FIDO: Users who registered a third-party FIDO authenticator. OATH HOTP HW: Total number of third party OATH hardware authenticators using HOTP (event-based) OTP.

  • SMS/Voice Messages (Current Month): Number of messages sent in a given month. Resets to 0 on the first day of the month.

The following hardware authenticator information is displayed:

FieldDescription
Authenticator App
AndroidNumber of registered Authenticator apps on Android devices.
iOSNumber of registered Authenticator apps on iOS devices.
Windows Number of registered Authenticator apps on Windows devices.
macOS Number of registered Authenticator apps on macOS devices.
SID700

Assigned

Number of SID700 hardware authenticators in CAS that are assigned to users.

Available

Number of SID700 hardware authenticators in CAS that are not assigned to any user and are available for authentication.
Disabled Number of SID700 hardware authenticators that are disabled in CAS and cannot be used.
Expiring within 90 days Number of SID700 hardware authenticators in the Cloud Administration Consolethat will expire within the next 90 days.
ExpiredNumber of expired SID700 hardware authenticators in the CAS.
DS100 (OTP & FIDO)
FIDO Credentials Number of FIDO credentials that are enabled in CAS.
OTP CredentialsNumber of OTP credentials that are enabled in CAS.

CAS and Authentication Manager Unified Usage Dashboard

When a connection is established between CAS and Authentication Manager (supported for Authentication Manager 8.7 SP2), the Usage Information dashboard will display a unified view of total users and credentials of both CAS and on-premise Authentication Manager for your hybrid deployments.

The Usage Information dashboard will provide a predefined list view of the following:

FieldDescription

Total Users

Total number of unique Cloud licensed users

The chart represents the total number of Cloud-only, on-prem only, and hybrid users.

  • All Cloud Users: Total count of Cloud users, including the following:

    • A user who has a registered credential (See Total Cloud Credentials ).

    • A user who has authenticated successfully in the last six months.

    • A user whose record is managed as part of the Unified Directory. Cloud users also include both the local and external users managed in the Unified Directory and does not include the users synchronized through the Active Directory (AD) or LDAP. For more information, see Unified Directory Identity Sources.

  • Hybrid Users: Total count of users existing in both CAS and on-prem Authentication Manager.

  • On-Prem Users: Total count of users with registered credentials in Authentication Manager.

Note:  The MFA licenses used are counted as part of the Cloud users count in the last six months.

Total Cloud Credentials

Total number of credentials (or authenticators) that are registered and managed in CAS.

The following authenticators must be registered with CAS:

  • Authenticator App

  • SID 700 hardware authenticators that are managed in the Cloud Administration Console

  • DS100 (OTP and FIDO) hardware authenticators

  • Third Party FIDO: Users who registered a third-party FIDO authenticator. OATH HOTP HW: Total number of third party OATH hardware authenticators using HOTP (event-based) OTP.

  • SMS/Voice Messages (Current Month): Number of messages sent in a given month. Resets to 0 on the first day of the month.

Total On-Prem Credentials

Total count of credentials (or authenticators) that are registered and managed in the on-prem Authentication Manager.

  • Hardware Authenticator: Total number of assigned hardware authenticators.

  • Software Authenticator: Total number of assigned software authenticators.

  • ODA: Total number of on-demand authentication (ODA) services.

  • Fixed Access Code: Total number of assigned passcodes.

The following information is displayed for the on-premise credentials:

FieldDescription
Hardware Authenticator

Assigned

Number of hardware authenticators that are assigned to users.

Available

Number of hardware authenticators that are not assigned to any user and are available for authentication.
Expiring within 90 days Number of hardware authenticators that will expire within the next 90 days.
ExpiredNumber of expired hardware authenticators.
Software Authenticator

Assigned

Number of software authenticators that are assigned to users.

Available

Number of software authenticators that are not assigned to any user and are available for authentication.
Expiring within 90 days Number of software authenticators that will expire within the next 90 days.
ExpiredNumber of expired software authenticators.
ODA 
EnabledNumber of on-demand authentication (ODA) services that are enabled.
Fixed Access Code 
AssignedNumber of fixed passcodes that are assigned to users.

Publish Status

Use the Publish Status to determine if there are pending configuration changes to be published, or if another administrator recently published changes to the identity routers and CAS. This section displays the following:

  • Date and time that configuration changes were last published.
  • Status message indicating whether all configuration settings in the Cloud Administration Console are synchronized (published) to the identity routers CAS.

Certificates

You can monitor the status of the domain certificates in your deployment, and plan for renewal of expiring certificates. This section displays the following:

  • Date each certificate became valid.
  • Expiration date for each certificate.
  • Remaining time until each certificate expires.

System Status - Identity Routers

The dashboard displays the status of all identity routers in your deployment.

Status ColorMeaning
GreenRegistered and Active
RedRegistered and Distressed (not connected to CAS)
WhiteDisabled or not registered

The dashboard indicates whether identity sources are configured.

Status ColorMeaning
GreenSuccessfully configured
RedNot configured

System Status - SMS/Voice OTPs

If your deployment has enabled SMS OTPs or Voice OTPs, the dashboard displays the total number of OTPs sent for both authentication methods in one calendar month. The total includes OTPs that users might not have received for various reasons, for example, if CAS has an incorrect phone number for the user, or the user did not answer a Voice call. The number is automatically updated every month.

Note:  The month is based on Coordinated Universal (UTC) time, which may differ slightly from your local time zone.

Protected Resources

The dashboard indicates how many applications, service providers, and RADIUS clients have been added to the deployment.

Note:  The IDR Portal Applications section is available only if Identity Router based portal is enabled.