MicroStrategy ONE

Configuring Administrator Accounts for the Lenel® OnGuard® Server

Perform the following procedure to create and test user accounts on the Lenel OnGuard server that are required for the setup of the MicroStrategy Identity adapter.

If you require further assistance with setting up Lenel OnGuard, please contact your certified Lenel system integrator. MicroStrategy is unable to provide technical support beyond what is required for the proper function of the MicroStrategy Identity adapter.

  1. Create the administrator:
    1. On the server where Lenel OnGuard is installed, go to Start > Administrative Tools > Computer Management.
    2. In Computer Management, go to System Tools > Local Users and Groups > Users.
    3. Right-click on the Users folder, select New Users…, and create a new user.
    4. In the Computer Management window, choose System Tools > Administrative Tools > Groups.
    5. In the pane on the right, right-click on Administrators, select Add to Group…, and in the choose the user that you just created.
  2. Enable remote access for the administrator:
    1. In the Computer Management window, choose Services and Applications, right-click on WMI Control and select Properties.
    2. In the WMI Control Properties window, select the Security tab and click the Security button.
    3. Select Authenticated Users and ensure that all permissions are allowed.
  3. Add the local directory in Lenel:
    1. Launch the System Administrator application for Lenel.
    2. Select the Directories tab on the bottom row and click the Add button in the bottom-left corner.
    3. Select Windows Local Accounts and click OK.
    4. In the Name field, enter the directory name. Example: OnGuard Local Directory.
    5. Next to the Hostname field, click the Browse… button and choose the current Windows domain. Then select the Enable single sign-on check box.
    6. Select the Authentication tab and choose the Current Windows account radio button.
    7. Click OK.
  4. Add the corporate directory in Lenel:
    1. In System Administration, under the Directories tab, click the Ad button in the bottom-left corner.
    2. Select Microsoft Active Directory and click OK.
    3. In the Name field, enter the directory name. Example: OnGuard Corporate Directory.
    4. Next to the Hostname field, click the Browse… button and choose the corporate domain (Example: corp.example.com). Then select the Enable single sign-on check box.
    5. Select the Authentication tab on the right and choose Current Windows account.
    6. Click OK.
  5. Create the user account in OnGuard:
    1. Back in System Administration, select the Directories tab on the bottom row. Click the Add button.
    2. Enter a name for the user. Click the Link… button on the right.
    3. From the Directory drop-down, select the local directory created in step 3.
    4. Click the Search button. Select the Windows user(s) you want to associate with the Lenel user.
    5. From the Directory drop-down, select the corporate directory created in step 4.
    6. Type in a search parameter and click the Search button. Select the corporate user(s) you want to associate with the Lenel user. Click OK.
    7. Select the Internal Account tab on the right. Set a name and password for the user.
    8. Select the Permission Groups tab on the right. Choose the highest permissions for each category.
    9. In the Segment Access, Area Access Manager Levels, and Monitor Zone Assignment tabs on the right, select all available options.
  6. Verify user login to OnGuard:
    1. In the icon bar at the top of System Administration, find the login/logout icon, which is the key icon on the left.
    2. Click the key icon to log out, which should gray-out most of the other icons.
    3. Click the key icon to log in. The Log On to System Administration dialog box should indicate that OnGuard is logging in as the current Windows account.
  7. Verify WMI connectivity to OnGuard:
    1. Download and install WMI CIM Studio, which is part of WMI tools.
    2. Launch the WMI CIM Studio application by choosing Start > All Programs > WMI Tools > WMI CIM Studio. The application will open in Internet Explorer by default.
    3. In the Connect to namespace dialog box, click the icon on the right to browse for the namespace.

    4. In the Browse For Namespace dialog box, the machine name should be double backslashes followed by the IP address of the OnGuard machine (Example: \\10.23.45.67). The starting namespace should be root\onguard. Click the Connect button.

    5. In the WMI CIM Studio Login dialog box, leave the box cleared for Login as current user. Type the local user domain and account (for example: onguard\demo-OnGuard) with the Lenel account password. Click OK.

    6. When login succeeds, an onguard folder appears in the Browse For Namespace dialog box. Click OK to open the folder.

    7. The list of Lenel classes appears. This verifies that the user account has access to read data from Lenel OnGuard.