Maximizing efficiency and security in large-scale automation rollouts with Automation Cloud.pptx

Welcome to the
UiPath Automation Cloud™
Best Practices Series
Maximizing efficiency and security in
large-scale automation rollouts with
Automation Cloud
Session 4
3
Daniel Buca
Sr. Product Manager – Identity,
UiPath
Today’s Speaker
4
What we will talk about today
01
02
03
04
User strategies when onboarding users to Automation Cloud
Getting your users in Automation Cloud
Securing Automation Cloud for your organization
Q&A / Open conversation
5
The need for user onboarding strategy
Defined user access control to ensure organizational security
When organizations are small, all the aspects can be handled
manually in a relatively short time
Need access to multiple products and features, it is hard to
manually handle all the aspects
......making it hard to manually handle all aspects of user control
As organizations grow, number of users increase and leads to
working from multiple locations
New challenges arise as the organization grows….
6
A few things to consider before
onboarding new users
What happens if a strategy is not
defined prior to onboarding the
users?
• Manual handling of permissions and license
allocation leading to wastage of time
• Admins become bottlenecks for various IT
processes
• Ad hoc and urgent security needs that could
have been avoided
• End up with a lot of repetitive and time-
consuming tasks
How to prepare before onboarding
users to Automation Cloud?
• Think about how the users are structured, in the
context of Automation Cloud
• Think about the products they need to use
• Understand how users should be grouped based on
what they need to do
• Identify what kind of restrictions you want to impose
on those that will use Automation Cloud
7
01. User strategies for Onboarding to
Automation Cloud
Need
Solution
1. Everyone needs access 2. Specific users get access to products
All users in the organization should have
basic access to Automation Cloud and
elevated permissions are given
individually at product level
The system should allow access to
everyone in the directory and allow
admins to assign roles and permissions
at product level
Need
Solution
The system should allow access to
everyone in the directory and
dynamically assign roles and
permissions when users sign in
All users should be allowed to sign in but
only some dynamic subsets of users
should be given permissions at product
level
8
01. User strategies when onboarding users
to Automation Cloud
Need
Solution
3. You need to control the context 4. Specific users can access the organization
Who should sign in is already solved; I
need to restrict access to Automation
Cloud to a set of predefined places
The system should allow admins to
define what the locations that are
considered and allow users to sign in
only if they access Automation Cloud
from the trusted locations
Need
Solution
The system should allow admins to
restrict access to everyone, except for a
list of predefined users.
By default, everyone should be denied
access, and one should be able to
control specifically who has access to
Automation Cloud
9
02. Getting your users in Automation Cloud
10
Directory Integration - Azure AD
If your organization is using Azure
Active Directory (Azure AD) or
Office 365, you can connect your
Automation Cloud organization
directly to the Azure AD tenant.
This allows, the users and groups
from your Azure AD tenant
to be addressable in Automation
Cloud for permission assignment.
Full documentation on setting up Azure AD directory integration for
SSO can be found here.
11
Directory Integration - Azure AD
Scalable access management
All existing users with UiPath user
accounts have their permissions
automatically migrated to their
connected Azure AD account
Users do not have to accept an
invitation or create a UiPath user
account to access the Automation
Cloud. They sign in with their
Azure AD account by selecting
the Enterprise SSO option or
using their organization-specific
URL
If the user is already signed-in to
Azure AD or Office 365, they are
automatically signed in
Directory groups (Azure AD
security groups or Office
365 groups), allow you to leverage
your existing organizational
structure to manage permissions
at scale. You no longer need to
configure permissions in
Automation Cloud services for
each user
If the user is already signed-in to
Azure AD or Office 365, they are
automatically signed in
Auditing Automation Cloud
access is simple. After you've
configured permissions in all
Automation Cloud services using
Azure AD groups, utilize your
existing validation processes
associated with Azure AD group
membership
All users and groups from Azure
AD are readily available for any
Automation Cloud service to
assign permissions
You can provide Single Sign-On
for users whose corporate
username differs from their email
address
Automatic user onboarding Simplified sign-in experience
12
Directory Integration - SAML
Connect Automation Cloud to any identity
provider (IdP) that uses the SAML 2.0
standard.
Compared to Azure AD integration, with
SAML users are not discoverable in
Automation Cloud before they are
provisioned.
Implement provisioning rules based on
SAML claims that allow assigning of users
directly to local groups and inherit any
permissions or license allocations from
that group.
Full documentation on setting up SAML can be found here.
.
13
Auto Provisioning for SAML Integration
Mapping users to groups
After setting up the SAML integration, define a set of rules
for assigning users to local groups when they sign in.
For one or more rules, specify to which group the users
will be automatically assigned to when users sign in, if the
rules match.
Rules can be defined based on:
• Claims (name of the claim)
• Relationship (various verbs such as:
is, is not, contains)
• Value: a value that you can define
14
03. Securing Automation Cloud for your
organization
15
Session Policies
Idle timeout
Automation Cloud has a
Session Policy that allows an
organization admin to define
how long a user can be
inactive prior to being forced
to re-authenticate.
Concurrent sessions
Automation Cloud has a
Session Policy that allows
organization admin to define
if a user could have multiple
sessions at the same time or
not.
16
IP Range Restrictions
User Location
Specific Location
IP Range List
Define a list of IP Ranges that are considered trusted and then enable the policy that
restricts any access from outside the trusted ranges
Trusted Environment
Users in contact with sensitive data, should be in trusted environments so only access
from offices should be allowed
Important to control from where users access Automation Cloud
Further, some organizations might want to restrict user access to only some of the offices
17
Restricting access to only selected users
The Concept
Defining the rules and activating the
restriction
Two ways users could get access to Automation Cloud:
Restrict everyone by default and define who
should be allowed
Allow everyone to sign in and manage their
level of access
Local or Directory Users
Local or Directory Groups
Admin can define who is part of the allowed list by
selecting:
18
Key Benefits
Simpler and Faster Provisioning
SAML integration - . auto provisioning rules (dynamic group mapping)
allows faster user sign ins
Secure User Account
Secure user account when using Single Sign On (SSO)
Easily manage permissions and license
allocation
Azure AD integration - reference users and groups from the
organization directory and all future users will benefit
Organization Level Security
Keep organization secure by using session policies and access
restriction policies, either IP based or explicit
19
Join us next week…
Session 5
Learn more about onboarding users to UiPath
Automation Cloud and securing the environment at:
Setting up Azure AD directory integration for
SSO
Setting up SAML Integration
An overview and comparison of all
authentication methods
20
Thank you!
1 sur 20

Recommandé

SC-900 Capabilities of Microsoft Identity and Access Management Solutions par
SC-900 Capabilities of Microsoft Identity and Access Management SolutionsSC-900 Capabilities of Microsoft Identity and Access Management Solutions
SC-900 Capabilities of Microsoft Identity and Access Management SolutionsFredBrandonAuthorMCP
193 vues30 diapositives
Secure Your Cloud Environment with Azure Active Directory (AD) par
Secure Your Cloud Environment with Azure Active Directory (AD)Secure Your Cloud Environment with Azure Active Directory (AD)
Secure Your Cloud Environment with Azure Active Directory (AD)WinWire Technologies Inc
373 vues24 diapositives
Automation Cloud Series - Mastering the Automation Cloud Admin experience_Ses... par
Automation Cloud Series - Mastering the Automation Cloud Admin experience_Ses...Automation Cloud Series - Mastering the Automation Cloud Admin experience_Ses...
Automation Cloud Series - Mastering the Automation Cloud Admin experience_Ses...Rohit Radhakrishnan
206 vues18 diapositives
Hitchhiker's Guide to Azure AD - SPS St Louis 2018 par
Hitchhiker's Guide to Azure AD - SPS St Louis 2018Hitchhiker's Guide to Azure AD - SPS St Louis 2018
Hitchhiker's Guide to Azure AD - SPS St Louis 2018Max Fritz
611 vues44 diapositives
Managing Cloud identities in Hybrid Cloud | Sysfore par
Managing Cloud identities in Hybrid Cloud | SysforeManaging Cloud identities in Hybrid Cloud | Sysfore
Managing Cloud identities in Hybrid Cloud | SysforeSysfore Technologies
41 vues4 diapositives
Azure AD Presentation - @ BITPro - Ajay par
Azure AD Presentation - @ BITPro - AjayAzure AD Presentation - @ BITPro - Ajay
Azure AD Presentation - @ BITPro - AjayAnoop Nair
2.7K vues42 diapositives

Contenu connexe

Similaire à Maximizing efficiency and security in large-scale automation rollouts with Automation Cloud.pptx

Implementing zero trust architecture in azure hybrid cloud par
Implementing zero trust architecture in azure hybrid cloudImplementing zero trust architecture in azure hybrid cloud
Implementing zero trust architecture in azure hybrid cloudAjit Bhingarkar
95 vues8 diapositives
2018 November - AZUGDK - Azure AD par
2018 November - AZUGDK - Azure AD 2018 November - AZUGDK - Azure AD
2018 November - AZUGDK - Azure AD Peter Selch Dahl
289 vues30 diapositives
Preparing your enteprise for Hybrid AD Join and Conditional Access par
Preparing your enteprise for Hybrid AD Join and Conditional AccessPreparing your enteprise for Hybrid AD Join and Conditional Access
Preparing your enteprise for Hybrid AD Join and Conditional AccessJason Condo
4K vues28 diapositives
Azure from scratch part 2 By Girish Kalamati par
Azure from scratch part 2 By Girish KalamatiAzure from scratch part 2 By Girish Kalamati
Azure from scratch part 2 By Girish KalamatiGirish Kalamati
1.2K vues273 diapositives
Shared authority based privacy preserving authentication protocol in cloud co... par
Shared authority based privacy preserving authentication protocol in cloud co...Shared authority based privacy preserving authentication protocol in cloud co...
Shared authority based privacy preserving authentication protocol in cloud co...Adz91 Digital Ads Pvt Ltd
3.6K vues11 diapositives
Active Directory Proposal par
Active Directory ProposalActive Directory Proposal
Active Directory ProposalMJ Ferdous
6.8K vues6 diapositives

Similaire à Maximizing efficiency and security in large-scale automation rollouts with Automation Cloud.pptx(20)

Implementing zero trust architecture in azure hybrid cloud par Ajit Bhingarkar
Implementing zero trust architecture in azure hybrid cloudImplementing zero trust architecture in azure hybrid cloud
Implementing zero trust architecture in azure hybrid cloud
Ajit Bhingarkar95 vues
Preparing your enteprise for Hybrid AD Join and Conditional Access par Jason Condo
Preparing your enteprise for Hybrid AD Join and Conditional AccessPreparing your enteprise for Hybrid AD Join and Conditional Access
Preparing your enteprise for Hybrid AD Join and Conditional Access
Jason Condo4K vues
Azure from scratch part 2 By Girish Kalamati par Girish Kalamati
Azure from scratch part 2 By Girish KalamatiAzure from scratch part 2 By Girish Kalamati
Azure from scratch part 2 By Girish Kalamati
Girish Kalamati 1.2K vues
Shared authority based privacy preserving authentication protocol in cloud co... par Adz91 Digital Ads Pvt Ltd
Shared authority based privacy preserving authentication protocol in cloud co...Shared authority based privacy preserving authentication protocol in cloud co...
Shared authority based privacy preserving authentication protocol in cloud co...
Active Directory Proposal par MJ Ferdous
Active Directory ProposalActive Directory Proposal
Active Directory Proposal
MJ Ferdous6.8K vues
Hitchhiker's Guide to Azure AD - SPSKC par Max Fritz
Hitchhiker's Guide to Azure AD - SPSKCHitchhiker's Guide to Azure AD - SPSKC
Hitchhiker's Guide to Azure AD - SPSKC
Max Fritz539 vues
Salesforce admin training 2 par HungPham381
Salesforce admin training 2Salesforce admin training 2
Salesforce admin training 2
HungPham381142 vues
The Disadvantages And Disadvantages Of A Single Sign-On On... par Lori Bowie
The Disadvantages And Disadvantages Of A Single Sign-On On...The Disadvantages And Disadvantages Of A Single Sign-On On...
The Disadvantages And Disadvantages Of A Single Sign-On On...
Lori Bowie4 vues
okta | Top 8 Identity and Access Management Challenges with Your SaaS Applica... par Abhishek Sood
okta | Top 8 Identity and Access Management Challenges with Your SaaS Applica...okta | Top 8 Identity and Access Management Challenges with Your SaaS Applica...
okta | Top 8 Identity and Access Management Challenges with Your SaaS Applica...
Abhishek Sood541 vues
Identity and Data protection with Enterprise Mobility Security in ottica GDPR par Jürgen Ambrosi
Identity and Data protection with Enterprise Mobility Security in ottica GDPRIdentity and Data protection with Enterprise Mobility Security in ottica GDPR
Identity and Data protection with Enterprise Mobility Security in ottica GDPR
Jürgen Ambrosi385 vues
Azure Active Directory par Sovelto
Azure Active DirectoryAzure Active Directory
Azure Active Directory
Sovelto4.6K vues
EMS-HPT Template-v.1.0 par Huy Pham
EMS-HPT Template-v.1.0EMS-HPT Template-v.1.0
EMS-HPT Template-v.1.0
Huy Pham503 vues
Tech Module 4 - Microsoft Teams admin and gov.pptx par eco80080
Tech Module 4 - Microsoft Teams admin and gov.pptxTech Module 4 - Microsoft Teams admin and gov.pptx
Tech Module 4 - Microsoft Teams admin and gov.pptx
eco8008015 vues
SPTechCon Boston 2013 - Introduction to Security in Microsoft Sharepoint 2013... par AntonioMaio2
SPTechCon Boston 2013 - Introduction to Security in Microsoft Sharepoint 2013...SPTechCon Boston 2013 - Introduction to Security in Microsoft Sharepoint 2013...
SPTechCon Boston 2013 - Introduction to Security in Microsoft Sharepoint 2013...
AntonioMaio22K vues
BlackBerry Workspaces: Authentication and Identity Connectors par BlackBerry
BlackBerry Workspaces: Authentication and Identity ConnectorsBlackBerry Workspaces: Authentication and Identity Connectors
BlackBerry Workspaces: Authentication and Identity Connectors
BlackBerry345 vues
JoTechies - Cloud identity par JoTechies
JoTechies - Cloud identityJoTechies - Cloud identity
JoTechies - Cloud identity
JoTechies146 vues
Oracle Enterprise Manager Security A Practitioners Guide par Courtney Llamas
Oracle Enterprise Manager Security A Practitioners GuideOracle Enterprise Manager Security A Practitioners Guide
Oracle Enterprise Manager Security A Practitioners Guide
Courtney Llamas2.5K vues

Plus de Rohit Radhakrishnan

UiPath Devops.pptx par
UiPath Devops.pptxUiPath Devops.pptx
UiPath Devops.pptxRohit Radhakrishnan
358 vues12 diapositives
UiPath Test Suite_final.pptx par
UiPath Test Suite_final.pptxUiPath Test Suite_final.pptx
UiPath Test Suite_final.pptxRohit Radhakrishnan
105 vues16 diapositives
DU PPT (1).pptx par
DU PPT (1).pptxDU PPT (1).pptx
DU PPT (1).pptxRohit Radhakrishnan
159 vues47 diapositives
UiPath Test Manager Connect Webinar UiPath Planview.pptx par
UiPath Test Manager Connect Webinar UiPath Planview.pptxUiPath Test Manager Connect Webinar UiPath Planview.pptx
UiPath Test Manager Connect Webinar UiPath Planview.pptxRohit Radhakrishnan
132 vues25 diapositives
uipath_insights_upgrade.pptx par
uipath_insights_upgrade.pptxuipath_insights_upgrade.pptx
uipath_insights_upgrade.pptxRohit Radhakrishnan
135 vues15 diapositives
UiPath Marketplace - HyperHack 2023.pptx par
UiPath Marketplace - HyperHack 2023.pptxUiPath Marketplace - HyperHack 2023.pptx
UiPath Marketplace - HyperHack 2023.pptxRohit Radhakrishnan
103 vues34 diapositives

Plus de Rohit Radhakrishnan(20)

UiPath Test Manager Connect Webinar UiPath Planview.pptx par Rohit Radhakrishnan
UiPath Test Manager Connect Webinar UiPath Planview.pptxUiPath Test Manager Connect Webinar UiPath Planview.pptx
UiPath Test Manager Connect Webinar UiPath Planview.pptx
DevDive_UnleashthFullPotentialofAutomationwithGenAI.pptx par Rohit Radhakrishnan
DevDive_UnleashthFullPotentialofAutomationwithGenAI.pptxDevDive_UnleashthFullPotentialofAutomationwithGenAI.pptx
DevDive_UnleashthFullPotentialofAutomationwithGenAI.pptx
UiPath Automation Cloud Robots - Best Practises session 2.pptx par Rohit Radhakrishnan
UiPath Automation Cloud Robots - Best Practises session 2.pptxUiPath Automation Cloud Robots - Best Practises session 2.pptx
UiPath Automation Cloud Robots - Best Practises session 2.pptx
UiPath Automation Cloud - Best Practises session1.pptx par Rohit Radhakrishnan
UiPath Automation Cloud - Best Practises session1.pptxUiPath Automation Cloud - Best Practises session1.pptx
UiPath Automation Cloud - Best Practises session1.pptx
UiPath 2022.10 Release – Updates with StudioX, Activities and Robot Assistant... par Rohit Radhakrishnan
UiPath 2022.10 Release – Updates with StudioX, Activities and Robot Assistant...UiPath 2022.10 Release – Updates with StudioX, Activities and Robot Assistant...
UiPath 2022.10 Release – Updates with StudioX, Activities and Robot Assistant...
UiPath 2022.10 Release – Updates with StudioX, Activities and Robot Assistant... par Rohit Radhakrishnan
UiPath 2022.10 Release – Updates with StudioX, Activities and Robot Assistant...UiPath 2022.10 Release – Updates with StudioX, Activities and Robot Assistant...
UiPath 2022.10 Release – Updates with StudioX, Activities and Robot Assistant...

Dernier

WITS Deck par
WITS DeckWITS Deck
WITS DeckW.I.T.S.
36 vues22 diapositives
Amine el bouzalimi par
Amine el bouzalimiAmine el bouzalimi
Amine el bouzalimiAmine EL BOUZALIMI
6 vues38 diapositives
ATPMOUSE_융합2조.pptx par
ATPMOUSE_융합2조.pptxATPMOUSE_융합2조.pptx
ATPMOUSE_융합2조.pptxkts120898
35 vues70 diapositives
Cracking the Code Decoding Leased Line Quotes for Connectivity Excellence.pptx par
Cracking the Code Decoding Leased Line Quotes for Connectivity Excellence.pptxCracking the Code Decoding Leased Line Quotes for Connectivity Excellence.pptx
Cracking the Code Decoding Leased Line Quotes for Connectivity Excellence.pptxLeasedLinesQuote
5 vues8 diapositives
cis5-Project-11a-Harry Lai par
cis5-Project-11a-Harry Laicis5-Project-11a-Harry Lai
cis5-Project-11a-Harry Laiharrylai126
9 vues11 diapositives
The Dark Web : Hidden Services par
The Dark Web : Hidden ServicesThe Dark Web : Hidden Services
The Dark Web : Hidden ServicesAnshu Singh
22 vues24 diapositives

Dernier(13)

ATPMOUSE_융합2조.pptx par kts120898
ATPMOUSE_융합2조.pptxATPMOUSE_융합2조.pptx
ATPMOUSE_융합2조.pptx
kts12089835 vues
Cracking the Code Decoding Leased Line Quotes for Connectivity Excellence.pptx par LeasedLinesQuote
Cracking the Code Decoding Leased Line Quotes for Connectivity Excellence.pptxCracking the Code Decoding Leased Line Quotes for Connectivity Excellence.pptx
Cracking the Code Decoding Leased Line Quotes for Connectivity Excellence.pptx
The Dark Web : Hidden Services par Anshu Singh
The Dark Web : Hidden ServicesThe Dark Web : Hidden Services
The Dark Web : Hidden Services
Anshu Singh22 vues
40th TWNIC Open Policy Meeting: APNIC PDP update par APNIC
40th TWNIC Open Policy Meeting: APNIC PDP update40th TWNIC Open Policy Meeting: APNIC PDP update
40th TWNIC Open Policy Meeting: APNIC PDP update
APNIC106 vues
40th TWNIC Open Policy Meeting: A quick look at QUIC par APNIC
40th TWNIC Open Policy Meeting: A quick look at QUIC40th TWNIC Open Policy Meeting: A quick look at QUIC
40th TWNIC Open Policy Meeting: A quick look at QUIC
APNIC109 vues
40th TWNIC OPM: On LEOs (Low Earth Orbits) and Starlink Download par APNIC
40th TWNIC OPM: On LEOs (Low Earth Orbits) and Starlink Download40th TWNIC OPM: On LEOs (Low Earth Orbits) and Starlink Download
40th TWNIC OPM: On LEOs (Low Earth Orbits) and Starlink Download
APNIC112 vues
Penetration Testing for Cybersecurity Professionals par 211 Check
Penetration Testing for Cybersecurity ProfessionalsPenetration Testing for Cybersecurity Professionals
Penetration Testing for Cybersecurity Professionals
211 Check49 vues

Maximizing efficiency and security in large-scale automation rollouts with Automation Cloud.pptx

  • 1. Welcome to the UiPath Automation Cloud™ Best Practices Series
  • 2. Maximizing efficiency and security in large-scale automation rollouts with Automation Cloud Session 4
  • 3. 3 Daniel Buca Sr. Product Manager – Identity, UiPath Today’s Speaker
  • 4. 4 What we will talk about today 01 02 03 04 User strategies when onboarding users to Automation Cloud Getting your users in Automation Cloud Securing Automation Cloud for your organization Q&A / Open conversation
  • 5. 5 The need for user onboarding strategy Defined user access control to ensure organizational security When organizations are small, all the aspects can be handled manually in a relatively short time Need access to multiple products and features, it is hard to manually handle all the aspects ......making it hard to manually handle all aspects of user control As organizations grow, number of users increase and leads to working from multiple locations New challenges arise as the organization grows….
  • 6. 6 A few things to consider before onboarding new users What happens if a strategy is not defined prior to onboarding the users? • Manual handling of permissions and license allocation leading to wastage of time • Admins become bottlenecks for various IT processes • Ad hoc and urgent security needs that could have been avoided • End up with a lot of repetitive and time- consuming tasks How to prepare before onboarding users to Automation Cloud? • Think about how the users are structured, in the context of Automation Cloud • Think about the products they need to use • Understand how users should be grouped based on what they need to do • Identify what kind of restrictions you want to impose on those that will use Automation Cloud
  • 7. 7 01. User strategies for Onboarding to Automation Cloud Need Solution 1. Everyone needs access 2. Specific users get access to products All users in the organization should have basic access to Automation Cloud and elevated permissions are given individually at product level The system should allow access to everyone in the directory and allow admins to assign roles and permissions at product level Need Solution The system should allow access to everyone in the directory and dynamically assign roles and permissions when users sign in All users should be allowed to sign in but only some dynamic subsets of users should be given permissions at product level
  • 8. 8 01. User strategies when onboarding users to Automation Cloud Need Solution 3. You need to control the context 4. Specific users can access the organization Who should sign in is already solved; I need to restrict access to Automation Cloud to a set of predefined places The system should allow admins to define what the locations that are considered and allow users to sign in only if they access Automation Cloud from the trusted locations Need Solution The system should allow admins to restrict access to everyone, except for a list of predefined users. By default, everyone should be denied access, and one should be able to control specifically who has access to Automation Cloud
  • 9. 9 02. Getting your users in Automation Cloud
  • 10. 10 Directory Integration - Azure AD If your organization is using Azure Active Directory (Azure AD) or Office 365, you can connect your Automation Cloud organization directly to the Azure AD tenant. This allows, the users and groups from your Azure AD tenant to be addressable in Automation Cloud for permission assignment. Full documentation on setting up Azure AD directory integration for SSO can be found here.
  • 11. 11 Directory Integration - Azure AD Scalable access management All existing users with UiPath user accounts have their permissions automatically migrated to their connected Azure AD account Users do not have to accept an invitation or create a UiPath user account to access the Automation Cloud. They sign in with their Azure AD account by selecting the Enterprise SSO option or using their organization-specific URL If the user is already signed-in to Azure AD or Office 365, they are automatically signed in Directory groups (Azure AD security groups or Office 365 groups), allow you to leverage your existing organizational structure to manage permissions at scale. You no longer need to configure permissions in Automation Cloud services for each user If the user is already signed-in to Azure AD or Office 365, they are automatically signed in Auditing Automation Cloud access is simple. After you've configured permissions in all Automation Cloud services using Azure AD groups, utilize your existing validation processes associated with Azure AD group membership All users and groups from Azure AD are readily available for any Automation Cloud service to assign permissions You can provide Single Sign-On for users whose corporate username differs from their email address Automatic user onboarding Simplified sign-in experience
  • 12. 12 Directory Integration - SAML Connect Automation Cloud to any identity provider (IdP) that uses the SAML 2.0 standard. Compared to Azure AD integration, with SAML users are not discoverable in Automation Cloud before they are provisioned. Implement provisioning rules based on SAML claims that allow assigning of users directly to local groups and inherit any permissions or license allocations from that group. Full documentation on setting up SAML can be found here. .
  • 13. 13 Auto Provisioning for SAML Integration Mapping users to groups After setting up the SAML integration, define a set of rules for assigning users to local groups when they sign in. For one or more rules, specify to which group the users will be automatically assigned to when users sign in, if the rules match. Rules can be defined based on: • Claims (name of the claim) • Relationship (various verbs such as: is, is not, contains) • Value: a value that you can define
  • 14. 14 03. Securing Automation Cloud for your organization
  • 15. 15 Session Policies Idle timeout Automation Cloud has a Session Policy that allows an organization admin to define how long a user can be inactive prior to being forced to re-authenticate. Concurrent sessions Automation Cloud has a Session Policy that allows organization admin to define if a user could have multiple sessions at the same time or not.
  • 16. 16 IP Range Restrictions User Location Specific Location IP Range List Define a list of IP Ranges that are considered trusted and then enable the policy that restricts any access from outside the trusted ranges Trusted Environment Users in contact with sensitive data, should be in trusted environments so only access from offices should be allowed Important to control from where users access Automation Cloud Further, some organizations might want to restrict user access to only some of the offices
  • 17. 17 Restricting access to only selected users The Concept Defining the rules and activating the restriction Two ways users could get access to Automation Cloud: Restrict everyone by default and define who should be allowed Allow everyone to sign in and manage their level of access Local or Directory Users Local or Directory Groups Admin can define who is part of the allowed list by selecting:
  • 18. 18 Key Benefits Simpler and Faster Provisioning SAML integration - . auto provisioning rules (dynamic group mapping) allows faster user sign ins Secure User Account Secure user account when using Single Sign On (SSO) Easily manage permissions and license allocation Azure AD integration - reference users and groups from the organization directory and all future users will benefit Organization Level Security Keep organization secure by using session policies and access restriction policies, either IP based or explicit
  • 19. 19 Join us next week… Session 5 Learn more about onboarding users to UiPath Automation Cloud and securing the environment at: Setting up Azure AD directory integration for SSO Setting up SAML Integration An overview and comparison of all authentication methods