Skip to main content

Quickstart guide for administrators

When the subscription is created, the administrators have to realize the initial Vault setup.

Then, the work concerns mainly the user lifecycle management: create or delete users, unlocking those who need help and finally check the product status and logs.

Trustelem management

Initial setup

The first step when a customer acquire Enterprise Vault is to configured Trustelem. The goal is to define which users will have access to Entreprise Vault and how. These actions are performed by Trustelem administrators.

There are therefore 4 main steps in the setup.

Note: Trustelem administration page should always be secured using multi-factor authentication. To do so you need to enroll a 2nd factor for the admin accounts, then enable multi-factor using the option "Authentication level for Trustelem admin console" on Security settings > General.

Subscription management

When the initial setup is done, Trustelem administration page is still usefull for:

  • Managing changes in the setup (new users, new 2nd factors, new enrolment process...)
  • Managing user password lost
  • Managing advanced features (silent authentication, self-service password reset, siem integration, API automations...)
    More information about Trustelem are available here: https://trustelem-doc.wallix.com/books/trustelem-administration
  • Auditing the authentication

Entreprise Vault setup

Entreprise Vault administration access-rule

To access Entreprise Vault administration page, a Trustelem user must have access to the Entreprise Vault administration application.
By default, the subscription administrator is in the group "Entreprise Vault Admin" which has the access to this app.
To add new Entreprise Vault administrators, the users must be affected to this group.

Entreprise Vault administration page

As said in the previous point, the Entreprise Vault administration is done through an application. So, to access this app the administrators must use their Trustelem dashboard: https://your_domain.trustelem.com.

Manage users

As a reminder, users creation is done through Trustelem admin page and not with Entreprise Vault admin app.

On the Entreprise Vault admin app you can manage:

  • The deletion of Entreprise Vault users in the Entreprise Vault data base.
    It will not remove the user in Trustelem
    It will delete all the associated Items
  • The obligation for users to change their master password at the next connection
  • The change of user encryption keys

More information are available here: provide the LINK

Manage organization policies

On the Entreprise Vault admin app you can manage the settings applying to the entire company.
You can define rules for the logs, the security, the recovery...

More information are available here: provide the LINK

Audit the vault

On the Entreprise Vault admin app you can audit user's items, and share vault's items.

More information are available here: provide the LINK