Veritas Alta™ View Compliance and Governance User Guide
- Getting started
- Archive Overview
- Working with Dashboard
- Managing Configurations
- About Provisioning
- About Managed Tags
- About Account Management
- Managing Archive Collectors
- About Exchange Online Archiving
- About Bloomberg Archiving
- About Microsoft Teams Archiving
- About OneDrive for Business Archiving
- About Data Uploading
- About Alta Capture Services Archiving
- Managing Roles and Permissions
- Managing Policies
- Managing Authentication
- Managing Retention Policies
- Managing Email Continuity Services
- Managing Reports and Notifications
- Classification
- Managing Data Import
- AD FS Configuration Guide
- Alta Personal Archive Deployment for IBM Notes
- Archive Administration Updates in Previous Releases
Configuring AD FS to work with Veritas Alta Archiving
This section describes how to configure your Active Directory Federation Services (AD FS) environment to work with the Veritas Alta Archiving authentication service. After you configure your AD FS environment and the Veritas Alta Archiving authentication service, you can provide single sign-on access to Veritas Alta Personal Archive users.
For information about the supported AD FS versions, see the Veritas Alta Archiving Compatibility List.
Note:
These instructions apply to the provision of single sign-on access for Alta Personal Archive users only. For assistance with the provision for Alta eDiscovery and Veritas Alta View Compliance and Governance Management Console, contact Veritas Services & Support.
The following table describes the required steps to configure AD FS to work with the Veritas Alta Archiving authentication service.
Table: Steps to configure AD FS to work with the Veritas Alta Archiving authentication service
Action | Reference |
---|---|
Use the AD FS Management Console to add a relying party trust for Veritas Alta Archiving. | See Adding a relying party trust for Veritas Alta Archiving. |
Generate and export a token-signing certificate from the AD FS Management Console for upload in Veritas Alta View Compliance and Governance Management Console. |
These instructions do not provide information on how to set up your AD FS environment. Refer to the following Microsoft documentation for information on to set up your AD FS environment:
Veritas Alta Archiving honors the NotBefore and NotOnOrAfter conditions that are presented during Secure Assertion authentication and authorization exchanges.
We recommend that you review your SSO Authority/Identity Provider settings to understand the values that are presented to Veritas Alta Archiving during the SAML exchange. You need to ensure that the NotBefore and NotOnOrAfter values and drift values are configured in a way that is secure but that does not inadvertently cause authentication issues. Veritas Alta Archiving synchronizes with several external UTC time sources and we recommend that you do the same to minimize the drift between our networks. Refer to your Microsoft documentation for information about configuring these values in an AD FS environment.
For information on how to set a NotBeforeSkew condition to allow for time discrepancies, see the following article on our Support website: