Account management
An account is an organization that subscribes to a SAS service. An account includes account management features, such as billing and contact information, service details, token inventory, authentication connections, and so on.
In SAS, each account is managed by a Virtual Server that has the same name.
You view and manage all of your accounts and their Virtual Servers independently. While you will likely standardize on a few service offerings, this independence means that you can customize your service for individual accounts without affecting any other account’s service. This includes pricing, billing, branding, and more.
SAS does not obligate you to manage all aspects of an account’s service. In fact, you can allow some or all of your accounts to manage their own Virtual Server.
Virtual Service Provider and Subscriber accounts
Accounts are created in a multi-tier, multi-tenant structure that accommodates just about any hierarchy, reporting structure, business structure, security segregation, or other delineation.
Within the account hierarchy, parent accounts manage child accounts, and child accounts cannot access their parent account. The account type determines whether you can create child accounts. There are two types of accounts:
-
Virtual Service Providers create and manage child accounts. The child accounts can be Virtual Service Providers or Subscriber accounts.
Virtual Service Providers can also distribute tokens to their child accounts and to users.
The top-level, or root, account is sometimes referred to as the service provider, but it is functionally the same as a Virtual Service Provider.
-
Subscriber accounts cannot create child accounts, and therefore they are always child accounts.
You can use Virtual Service Providers to create additional sales channels that resell your service under your banner or under their brand. However, Virtual Service Providers are not limited to being resellers. They can also be large, complex accounts that need to independently extend and manage the service that they deliver to many subsidiaries or cost centers, accommodate multiple LDAPs and user data sources, or share access to protected resources across organizational boundaries.
Account Managers and Operators
Accounts and Virtual Servers are managed by users who are assigned a particular role. A role is a collection of permissions that grants access to the various tabs and features on the SAS console.
There are two basic types of roles: Account Managers and Operators. For both Operators and account managers, you can create roles and customize the permissions to allow or deny access to the various tabs and features on the SAS console. For example, you can create roles that have only view access, or roles that have access to only specific tabs, such as reports.
The same user can have both an account manager role for managing child accounts for the Virtual Service Provider, and an Operator role for managing the Virtual Server for a child account.
Account Managers
Account Managers are users in a Virtual Service Provider account who create and manage accounts. Account managers can perform account management for child accounts, and Operator functions for their own Virtual Server if they also have an Operator role.
They can access the account management tabs and features, such as account details, services, token allocations, and so on.
Operators
Operators are users in either Virtual Service Provider or subscriber accounts who manage Virtual Servers. They can access only the Virtual Server tabs and features, such as users, tokens, policies, and so on. Operators cannot view or manage account information, such as the account details, services, or token allocations (unless they also have an account manager role).
There are two types of Operators:
-
Internal Operators are users in a Virtual Server that are assigned the Operator role. They manage their own Virtual Server for their account (either Virtual Service Provider or Subscriber). They cannot view or manage any other Virtual Server.
-
External Operators are users in a Virtual Service Provider account who are delegated as Operators for a child account. They manage the Virtual Server for that child account.
Account Manager or Operator enrollment
A tenant account must already be activated for the organization before an account manager or Operator can start using STA. When an account is activated, it has an inventory of tokens and at least one account manager or Operator is assigned.
The assigned account manager or Operator receives an email with instructions for completing their enrollment. They must enroll a one-time password (OTP) token that is assigned to them and activate their logon credentials.
After they activate their credentials, they can log on and create additional Operators, configure server settings, and so on, according to the access permissions that are defined for their assigned role.
Account management on the SAS console
Account Managers and Operators have different views of the SAS console. Account Managers have an additional row of tabs for account management that is not available in the Operator view of the SAS console.
For Account Managers, who always belong to a Virtual Service Provider, the SAS console includes an additional row of tabs for managing the service and all accounts:
-
Dashboard is where you view alerts, subscriber metrics, and the token inventory.
-
On-Boarding is where you manage your accounts and add accounts, which involves configuring the service type, token allocations, Operators, authentication nodes, and so on.
-
Virtual Servers lists the Virtual Servers for your accounts and provides access to the same tabs and features that Operators see on the console.
-
Administration is where you create Account Managers, customize Account Manager role, generate and deliver services alerts, and so on.
Operators cannot access these tabs unless they also have an account manager role.
The name of the Virtual Server.
These Virtual Server tabs provide access to manage the account’s users, tokens, reports, policies, and so on.
Shortcuts provide quick access to popular tasks, such as creating an account or a user. You can collapse or expand the Shortcuts area. There are different shortcuts for each Virtual Server tab.
The view of the SAS console can also differ based on the access permissions that are defined for a role. For example, account managers might not have access permissions for the Virtual Servers tab. Operators might not have access permissions for some tabs or features on the SAS console, or for the STA Access Management console.
Manage account details and services
On the On-Boarding tab, you can create accounts, view a list of all your accounts, or select a specific account and view the details. The On-Boarding tab provides different views of your accounts, depending on whether you are viewing a list of accounts or a selected account.
The account list includes the following information:
-
Account: Click the account name to configure the account details and services.
-
Custom #1: The optional description can distinguish between similar accounts.
-
Account — Name of the account on the Virtual Server.
-
Account Owner — Name of the account owner.
-
Class: The account type is either Service Provider (Virtual Service Provider) or Subscriber.
-
Activated: The date and time when the service was set to Active in the Services module.
-
Expires: The date and time when the service ends and users are unable to log in to the account is set in the Services module.
-
Billing: The billing period is configured in the Services module.
-
Capacity: The maximum number of users who can authenticate against the Virtual Server is set in the Allocation module. This value is reduced each time inventory is allocated to an account.
-
Unused: The total unused capacity. Capacity is consumed when an authentication method is assigned to a user, or when a Virtual Service Provider allocates capacity to an account that it manages.
-
Status: The state of the service: Active or Disabled, as set in the Services module. It will be Active unless the current date is greater than the Expires date or the services have been deactivated in the Services module.
-
Remove: Click to remove an account. Before you can remove an account, all inventory must be revoked (that is, capacity, rental, and unused must be 0).
When you select an account, the account details and service configuration options are displayed.
Search for an account
- Click On-Boarding > List Accounts (shortcut) or On-Boarding > Account (module).
- Type all or part of the Account name and/or Custom #1 name assigned to the account in the fields provided in the Search section.
- Click Search to display the results or click Clear to empty the search fields.
- To display account details, click the account name hyperlink in the list of search results.
Manage Virtual Servers
The Virtual Servers tab lists all the Virtual Servers that you can manage.
Accounts with management delegated to the service provider are listed on the Virtual Servers tab but not on the On-Boarding tab. On the Virtual Servers tab, the Management column lists the name of the delegating organization.
To manage an account on the Virtual Server:
- Click Virtual Servers. The Manage module displays.
-
Click the Account name from the Managed Account List.
The Virtual Servers tabs, which are available to you for the selected account display.
When you select a Virtual Server, you see the same tabs on the SAS console as an Operator who has the same permissions.