mag administration training companion guide
Transcription
mag administration training companion guide
13241 Woodland Park Road, Suite 400 Herndon, VA 20171 USA 703.561.0500 MAG ADMINISTRATION TRAINING COMPANION GUIDE AUTHOR: EXOSTAR 1 DATE: JULY 2014 VERSION: 14.0 13241 Woodland Park Road, Suite 400 Herndon, VA 20171 USA 703.561.0500 MANAGED ACCESS GATEWAY 1 INTRODUCTION ..................................................................................................................................................3 1.1 SUMMARY .........................................................................................................................................................3 1.2 DOCUMENT OBJECTIVES ...................................................................................................................................3 2 MAG OVERVIEW ................................................................................................................................................3 2.1 ORGANIZATIONAL RESPONSIBILITIES AND ROLES ............................................................................................3 3 BASIC ADMINISTRATIVE FUNCTIONALITY .............................................................................................4 3.1 ACCESS THE MAG LOGIN PORTAL ...................................................................................................................4 3.2 THE HOME TAB .................................................................................................................................................6 3.2.1 My Applications Container .......................................................................................................................6 3.2.2 My Organization Container......................................................................................................................7 3.2.3 My Tasks Container ..................................................................................................................................7 3.2.4 Account Summary Container ....................................................................................................................7 3.2.5 Quick Links Container ..............................................................................................................................8 3.3 THE MY ACCOUNT TAB ....................................................................................................................................8 3.4 THE ADMINISTRATION TAB ..............................................................................................................................9 3.4.1 Add a New User ........................................................................................................................................9 3.4.2 Locate a User and Update their Account ...............................................................................................13 3.4.3 Reset One-Time Password ......................................................................................................................14 3.4.4 Suspend, Reactivate and Delete User Accounts .....................................................................................15 3.4.5 Reset Permanent Password ....................................................................................................................18 3.4.6 Subscribe to Application .........................................................................................................................19 3.5 THE REGISTRATION REQUESTS TAB ...............................................................................................................19 3.5.1 MAG Access Approvals ..........................................................................................................................20 3.5.2 Verify OTP ..............................................................................................................................................23 3.5.3 Application Access Approvals ................................................................................................................24 3.5.4 FIS Certificate Approvals .......................................................................................................................25 3.6 USER FUNCTIONALITY ....................................................................................................................................28 3.6.1 User Self-registration .............................................................................................................................28 3.6.2 Request Password Reset (Forgot Password)..........................................................................................33 2 13241 Woodland Park Road, Suite 400 Herndon, VA 20171 USA 703.561.0500 1 Introduction 1.1 Summary Exostar’s Managed Access Gateway (MAG) is a consolidated portal for registration, authentication, and account management for all applications and services hosted by Exostar. It can also serve as an authentication gateway for applications managed by external partners. MAG consolidates an organization’s user registration process and includes the day-to-day account management functions across Exostar’s community of customers and services. 1.2 Document Objectives This guide is intended to be used by MAG Administrators as a companion to the instructor led MAG Administrator training. The guide aims to provide the following: • An overview of the key functions of MAG • Definition of the primary organizational responsibilities and roles within MAG • Detailed steps to execute basic administrative functionality within MAG 2 MAG Overview Overview of MAG: • MAG is the consolidated portal for registration, authentication, and account management for all applications and services hosted by Exostar. It also serves as an authentication gateway for applications managed by external partners. • MAG consolidates an organization’s user registration process and includes the day-to-day account management functions across Exostar’s community of customers and services. Key Functions of MAG include: • Extending the basic concept of Web based Single-Sign-On (SSO) to support multiple applications. • Supporting authentication credentials of varying assurance levels such as username and password, Basic and Medium Level of Assurance digital certificates and OTP Hardware Tokens. • Facilitating an organizational approach to registration, account management and application access. MAG supports thousands of supplier accounts within the Aerospace and Defense industry. Organizations can subscribe to multiple applications and services offered by Exostar, while maintaining a single registration and User ID to access those approved services. • Provides organizational control over new user approval and access requests. 2.1 Organizational Responsibilities and Roles All organizations registered within MAG assume responsibility for account activities including: • New User Registration Requests – the organization approves or denies new user registration requests and assigns each user a role. 3 13241 Woodland Park Road, Suite 400 Herndon, VA 20171 USA 703.561.0500 • User Access to Application Subscriptions – the organization approves or denies user requests for access to each of your organization’s application subscriptions. There are several roles within MAG that are available to an organization. These roles include: • Users – all individuals who have a login to MAG are considered “users” of the system. • Organization Administrator (Org Admin) – an individual(s) from your organization who is designated to receive and process user registration requests. Org Admins verify that the user is an employee and provides the approvals for MAG enrollment. • Application Administrator (App Admin) – an individual(s) from your organization who is designated to approve access to a specific application or resource. App Admins are often referred to as the application owners. For example, your organization may have an application owner for Exostar’s ForumPass or SCP products. • FIS Administrator (FISA) – serves as application admin for FIS and also defines the level of certificate to be assigned to users. • Company Contact – individual within your organization who is listed as the contact person and who is responsible for the contract with Exostar. The Organization and Application Admin roles can be, and are often handled by the same person within an organization. 3 Basic Administrative Functionality This section provides the steps to login and execute many of the functions used by an administrator in the MAG login portal. 3.1 Access the MAG Login Portal Step 1 Login to MAG Action Open your Internet Explorer Browser and proceed to https://portal.exostar.com. To Login with Basic Credentials and/or with a Digital Certificate: Enter your User ID and Password and click Login. If you have forgotten your User ID or Password, you may click on the appropriate link. 2 4 13241 Woodland Park Road, Suite 400 Herndon, VA 20171 USA 703.561.0500 3 To Login with an Active OTP Hardware Token: Click on the Active One-Time Password Hardware Token, then enter your User ID, Password, OTP Token Code and click Login. All users must have previously logged in via “First Time Login” link. If they have not, they must click on the Establish your account link to start the first time login process. You are now logged in to the MAG Portal. Upon login, you will see that there are several tabs available to you within the portal. The default landing tab view in MAG is the Home tab. • Home tab contains several containers of information including My Applications, My Organization, My Tasks, Quick Links and Account Summary. Each of these sections is explained in greater detail in Section 3.2. • My Account tab allows users to edit their account profile, view organizational details, manage email address, password and security questions, manage certificates (if applicable) and functionality around OTP hardware tokens, and connect accounts. • Administration tab is available to Org and App Admins and is used for user management. New users will be created within this tab, and existing user profiles can be updated. In addition, you may subscribe to existing Exostar Applications. 5 13241 Woodland Park Road, Suite 400 Herndon, VA 20171 USA 703.561.0500 • 3.2 Registration Requests tab is used by Application Admins to grant application access to users, by Organization Admins to grant approval to users who self-register and to approve users for OTP Token use, and by FIS Administrators to grant approval for digital certificates. The Home Tab When a user logs in to the MAG portal, the Home tab is displayed and features a dashboard of information. In addition to providing application access, this screen will contain summary information about the user’s organization, MAG tasks, and account. Administrators for the Organization will see information on the approval tasks they have outstanding and account suspension information across their Organization’s application. 3.2.1 My Applications Container The My Applications Container will list those applications that your organization has subscribed to and the status of your account within each of those applications. If your Status is Active for an application, the Status column will allow you to click Open Application and gain access to that product. The +Expand All Sections will expand each of the remaining containers. Each container may also be expanded individually by clicking on the containers link. Note: When you expand sections in a given MAG session, those containers will be collapsed as you begin your next session. 6 13241 Woodland Park Road, Suite 400 Herndon, VA 20171 USA 703.561.0500 3.2.2 My Organization Container The My Organization Container provides a summary of user statuses within your organization as well as your Organization ID. Application Administrators will also have access to a list of user status by application subscription. The View Organization Details link will display the My Account tab > View Organization Details page. 3.2.3 My Tasks Container The My Tasks Container will provide a consolidated list of “to-do” items with a link directly to each of the tasks. This may include Organization, Application and FIS subscription requests as well as Password Expiration notices. Note: When Tasks are listed the color of the container title will change to red. By clicking on the individual Tasks, the system will direct you to the applicable page under the Administration or Registration Requests tab. 3.2.4 Account Summary Container The Account Summary Container provides a summary of your account and your role(s) within MAG. 7 13241 Woodland Park Road, Suite 400 Herndon, VA 20171 USA 703.561.0500 The View Account Details link will display the My Account tab > Edit Profile page. 3.2.5 Quick Links Container The Quick Links Container provides links to common support items such as Registration for MAG Training, Access to MAG Training Demos, MAG Self-Help Pages and Exostar’s Customer Support. 3.3 The My Account Tab The My Account tab allows users to edit their account profile, view organizational details, manage email address, password and security questions, manage certificates (if applicable) and functionality around OTP hardware tokens, and connect accounts. • Edit Profile allows you to update user profile information such as work address and phone number. • View Organization Details displays information about your organization including your Organization ID. Note: The Organization ID is required for users who are proceeding through the self-registration process. • Change Email allows you to update your email address. If you have a FIS certificate you will not be able to change your email address via this process, instead you must contact Exostar Customer Support. • Change Password allows you change your current password. Note: The application will require you to change your password every 180 days. 8 13241 Woodland Park Road, Suite 400 Herndon, VA 20171 USA 703.561.0500 • Change Security Questions allows you to change the security questions that you established for your account. • Manage Certificates allows you to manage any digital certificates that are tied to your account. Note: A user will only see this tab if they have a digital certificate. • Manage OTP allows you to purchase and/or register an OTP hardware token or Phone Based OTP. For additional information on OTP Hardware Tokens please visit the following link http://www.myexostar.com/myexostarAll.aspx?id=2028&ekmensel=c580fa7b_150_164_2028_4. • Connect Accounts allows you to use a single Exostar account to access multiple Exostar accounts that you own. 3.4 The Administration Tab When a user logs in as an Org Admin or App Admin, they have access to the Administration tab. An Org Admin will have access to the View Users, Add New User and Subscribe to Application pages. An App Admin will have access to the View Users page. The Administration tab provides the functionality to create new users and update existing user profiles. 3.4.1 Add a New User Note: Users can also be created by accessing the Self-Registration website at https://portal.exostar.com/userRegistration. For more information, see User Functionality section below. Step Creat ea New User 1 Action Login to MAG with an Org Admin account. Access the Administration tab. Click Add New User. 2 In the Add New User section complete all the required fields as denoted by the asterisk (*). One-Time Password: The one-time password will be used during the user’s first time login. It is 9 13241 Woodland Park Road, Suite 400 Herndon, VA 20171 USA 703.561.0500 your responsibility to communicate the one-time password to the user. Without this information the user WILL NOT be able to log in. Note: The password rules will display on the Add New User screen. Restricted Access: Restricted Access is applicable for the ForumPass application only. Only select ‘On’ if the user will have a Restricted profile within the ForumPass application. If unsure, please consult Exostar’s Customer Service Team. 3 In the Application Settings section of the page, select a Role for the new user. Roles include User, Organization Admin, Application Admin and both Organization Admin and Application Admin. If you select User, you must then designate the Application(s) the user should have access to. Note: The list of application options will include all applications to which the organization is subscribed. If Application Admin, or Organization Admin & Application Admin is selected, you must also designate the applications that this user will be authorized to administer. Be careful to select the correct applications. If not, the request will not be processed by Exostar. Note: The Sponsor Code fields that appear on the New User page as well as an existing User’s detail page are optional fields. You will be advised, by Exostar, if you need to complete these fields. If you have not received direction on this, then please leave the fields blank. Click on the ‘view more information’ link for additional information. 4 Click Continue. 5 Review and verify the information that you have entered. 10 13241 Woodland Park Road, Suite 400 Herndon, VA 20171 USA 703.561.0500 Click Submit. You may click Modify and make any necessary changes or Cancel to cancel this transaction. 11 13241 Woodland Park Road, Suite 400 Herndon, VA 20171 USA 703.561.0500 6 The confirmation page is displayed. Note: This page will display the User ID which you should communicate, along with the one-time password, to the new user. In the case of users who will have access to SCP or ForumPass, there is a final step in the new user approval process. - SCP: the next step provides two account activation options: Activate Now, or Activate Later. - ForumPass: in the final step of the user approval process, the Exostar SP Admin provides account approval. Once this step is complete the user will have access to ForumPass. This may take up to 24-48 hours, but typically less. Note: If you are an Org and App Admin, the user’s application access will automatically be approved in MAG. (Remember that for ForumPass access the Exostar SP Admin will need to complete final approval step.) 7 The user will receive an email containing several pieces of important information including: a link to log in to MAG, the System Generated password that is required for first time login , their User ID, and the list of applications they have been granted access too. 12 13241 Woodland Park Road, Suite 400 Herndon, VA 20171 USA 703.561.0500 Remember – you MUST provide the user with the One-time Password which will be used during their first session. If the user has questions regarding his One-time Password, or requires a One-time Password reset, he should contact the Org Admin. 3.4.2 Locate a User and Update their Account Searches can be performed by using search criteria and/or filters. Once you locate a user, you may view and update their user profile, their user role, and the applications they have access to via the User’s Details page. A user’s details page contains two sections: • Edit User – where you can view and update the details of the individual’s profile. • Application Settings – where you can view and update a user role, application access and MAG access. You can also reset the user’s one-time password. Step 1 Find a Action Login to MAG as an Org or Add Admin. Access the Administration tab on the MAG portal. User Click View Users. 2 To search you can use search criteria to view the list of users within your Organization. - Click Search to list all users in your organization or - In the Search For field enter a name or partial name or role and select the field you would like to search on from the drop-down menu and click Search By clicking Search results are displayed. 3 Click on the applicable User ID to see the user’s profile information. 13 13241 Woodland Park Road, Suite 400 Herndon, VA 20171 USA 703.561.0500 4 In the User Profile section you may update any field, excluding the User ID. Note: Only Org Admins may update information in the User Profile section. Update a User’s Profile The Modify Email option allows you to update a user’s email address When an email address is modified by an Org Admin; the user receives an email containing an activation code and steps to follow in order to activate the new email address. The new email address is not reflected in MAG until the user completes the activation process. Note: If there is a digital certificate assigned to this user, the Modify Email option is not available. Make any necessary changes and click Submit. A dialog box will be displayed asking “Are you sure you want to submit the changes.” Click OK to proceed. The confirmation page is displayed. 5 3.4.3 Reset One-Time Password In the Application Settings section of the User Details page, an Org Admin can reset the user’s one-time password. 14 13241 Woodland Park Road, Suite 400 Herndon, VA 20171 USA 703.561.0500 Step 1 Action If a User account is not active, meaning the user has not completed the first time login in MAG, the Organization Admin can reset the user’s one-time password, if necessary. Note: Only an Org Admin may reset a user’s one-time password. Click Reset One-time Password. 2 Enter and confirm a new One-time password. Click Submit. A confirmation page is displayed. 3 The user will receive an email advising that the One-time password has been reset. The email will also contain a new system generated password. It is your responsibility to communicate the new one-time password to the user. Without this information the user WILL NOT be able to login. 3.4.4 Suspend, Reactivate and Delete User Accounts Additionally, on the User Details page in the Application Settings section, you may choose to suspend a user’s access to a specific application(s) or to MAG, and you may choose to permanently delete a user from the MAG database. You may also reactive user’s who were temporarily suspended. A user will be notified by email of the suspension or deletion actions. And they will be presented with an appropriate error message when they attempt to access the application. Conversely, if an account is re-enabled, the user will receive an email advising them of the reactivation. Important Note: If a user account is deleted from MAG, the account cannot be reactivated. 15 13241 Woodland Park Road, Suite 400 Herndon, VA 20171 USA 703.561.0500 Step Suspend Access to an Application 1 Action An Org or App Admin can Suspend a user’s access to an application. From the user’s profile page, click Suspend next to the appropriate application. The Suspend User Application dialog box will be displayed: Select the Reason and enter a Reason Note. Click Submit. By clicking Submit, the Edit User screen is displayed indicating user is Disabled. Reactivate Access to an Application 2 Click Return to User Profile. 3 The Application Settings section shows the user status as Suspended. To reinstate access to the application, click Activate. A warning message will appear asking if you are sure you want to activate access to the application. Click OK to proceed, or Cancel to exit. 16 13241 Woodland Park Road, Suite 400 Herndon, VA 20171 USA 703.561.0500 4 Step 1 By clicking OK, the Edit User screen is displayed indicating the user is Enabled. Action Only an Organization Admin can Suspend a user’s access to MAG. Suspend Access to MAG From the user’s profile page, click Suspend. The Suspend User dialog box will be displayed: Select the Reason and enter a Reason Note. Click Submit. 2 The Edit User screen is displayed indicating user is Disabled. Click Return to User Profile. 3 The Application Settings section shows the status as User Suspended. To reinstate access to MAG, click Enable User Access. 4 The Edit User screen is displayed indicating user is Enabled. 17 13241 Woodland Park Road, Suite 400 Herndon, VA 20171 USA 703.561.0500 Step 1 Delete an Account in MAG Action Only an Organization Admin can Delete a user’s access to MAG. Note: This function is used when an account is to be permanently deactivated in the database. The user will need to re-register for a new account to regain access to MAG. This is not used to suspend access to an application. From a user’s profile page, click Delete User. 2 The Edit User screen is displayed. Select the Reason and enter a Reason Note. Note: This is a permanent operation and cannot be undone. Click Submit. 3 The confirmation page is displayed. 3.4.5 Reset Permanent Password Additionally, on the User Details page in the Application Settings section, you may choose to Reset a User’s Permanent Password. 18 13241 Woodland Park Road, Suite 400 Herndon, VA 20171 USA 703.561.0500 If you select Reset Permanent Password MAG will automatically reset the user’s password. Note: There is no warning dialogue box to ensure you want to perform this function. The user will receive an email with the following information – Dear Teresa Cambetes, Follow these instructions to complete your password reset request for your Exostar account: - Go to https://portal.exostar.com - Enter your User ID and the following system-generated password in the Password field: System-Generated Password: 2296-6469-2146-2373 Once the user enters the system generated password, they will be prompted to choose a new password for their account. 3.4.6 Subscribe to Application The last link available to Organization Admins under the Administration tab is Subscribe to Application. This page allows an Organization Admin to see applications to which they are not already subscribed, and the Admin shall be able to click ‘Subscribe to Application’ to initiate the subscription request. If an Organization has an FIS subscription and they would like to request an upgrade to Medium Level of Assurance they can click Upgrade Organization to Medium Level Assurance. Step 1 3.5 Action Access the Administration tab on the MAG portal. Click Subscribe to Application. Note: Only an Org Admin can subscribe or upgrade applications. The Registration Requests Tab The Registration Requests tab will list all pending user requests – which include requests for MAG access, OTP Hardware Token activation and requests for application access. These requests will be listed in four links: • Verify will display all users who have self-registered and are pending MAG access approval. These approvals are handled by Org Admins. • Verify OTP will display all the users who have requested activation of their OTP Hardware token. These approvals are handled by the Org Admin assigned as the OTP Hardware token authorizer. • Authorize will display all users who have been approved in MAG by the Organization Admin and are pending application access. These approvals are handled by the App Admin. 19 13241 Woodland Park Road, Suite 400 Herndon, VA 20171 USA 703.561.0500 • Authorize FIS link will display all users who have requested a FIS certificate and are awaiting approval. These approvals are handled by the FIS Admins. Note: The links available will depend upon your role. For example, the Org Admin only role will not show the Authorize or Authorize FIS links. 3.5.1 MAG Access Approvals An Organization Admin will receive an email advising them when there is a new user MAG access request. The Verify link will display all users who have been through the self-registration process and are awaiting MAG approval. An Org Admin will verify the user’s registration information and confirm employment status prior to approval. 20 13241 Woodland Park Road, Suite 400 Herndon, VA 20171 USA 703.561.0500 Step MAG Access Approval by Org Admin Action 1 When a user completes the self-registration process, the Org Admin will receive an email notifying them that there is a pending user request. 2 Login to MAG as an Org Admin and access the Registration Requests tab. Click Verify to view the list of pending users who went through the self-registration process. 3 All pending requests will be listed. Click the Request Id link associated with the request you wish to approve. 4 Review the User Registration Request information. 21 13241 Woodland Park Road, Suite 400 Herndon, VA 20171 USA 703.561.0500 Click Next. 5 Complete all required fields confirming that you validate user employment. Click Next. If you select to Deny the request for access, you will be required to enter Comments to address the reason for denial. The user will receive an email advising them that the access was denied and the email will include these comments. Note: If you are the Org and App Admin the user request for application access is completed at this time. However, if you are only the Org Admin, the application access request must be completed by the App Admin. See New User Added By Org Admins steps above to complete the application approval process. 22 13241 Woodland Park Road, Suite 400 Herndon, VA 20171 USA 703.561.0500 Confirmation is presented and user is active in MAG. 6 3.5.2 Verify OTP An Organization Admin who has activated and been approved with an OTP Hardware Token will have the ability to approve users within their organization for OTP Hardware use. The Org Admin will receive an email advising when there is a new user OTP Hardware Token request. The Verify OTP link will display all users who have requested OTP Hardware Token approval. Step Verify OTP by Org Admin 1 Action Login to MAG as an Organization Admin and access the Registration Requests tab. Click Verify OTP to view the list of pending users. Note: To action the requests in this queue, you must be logged into MAG with either an OTP Hardware Token or another type of acceptable credential. 2 All pending requests will be listed. Click the Request Id link associated with the request you wish to approve. 3 If the user is approved, select Approve from the drop-down menu. If you would like to add comments on this request you may do so. Click Next. If you select to Deny the request for application access, you must enter Comments addressing the reason for denial. The user will receive an email advising them that the access was denied and the email will include those comments. 4 The confirmation page is displayed and the user request for an OTP Hardware Token has been approved. 23 13241 Woodland Park Road, Suite 400 Herndon, VA 20171 USA 703.561.0500 3.5.3 Application Access Approvals An Application Admin will receive an email advising when there is a new user application access request. The Authorize link will display all users who have been added to the MAG database by the Organization Admin and are pending application approval. Step Application Access Approval by App Admin 1 Action Login to MAG as an Application Admin and access the Registration Requests tab. Click Authorize to view the list of pending users entered by the Org Admin. 2 All pending requests will be listed. Click the Request Id link associated with the request you wish to approve. 3 Review the Application Request information. Click Next. 4 If the user is approved for access in this application, select Approve from the drop-down menu. If you would like to add comments on this request you may do so. 24 13241 Woodland Park Road, Suite 400 Herndon, VA 20171 USA 703.561.0500 Click Next. If you select to Deny the request for application access, you must enter Comments addressing the reason for denial. The user will receive an email advising them that the access was denied and the email will include those comments. 5 Confirmation page is displayed and the user is approved in the application. Reminder for ForumPass users: in the final step of the user approval process, the Exostar SP Admin provides account approval. Once this step is complete the user will have access to ForumPass. This may take up to 24-48 hours, but typically less. 3.5.4 FIS Certificate Approvals A FIS Administrator will receive an email advising when there is a new user digital certificate request. The Authorize FIS link will display all users who have requested a FIS certificate and are awaiting approval. Step Individual FIS Certificate Approval by FIS Admin 1 Action Login to MAG as a FIS Admin and access the Registration Requests tab. Click Authorize FIS to view the list of pending users entered by the Org Admin. 2 All pending requests will be listed. Click the Request Id link associated with the request you wish to view. Note: For users who have self-registered, the FISA has the option to approve/deny multiple user requests at a time. This process is documented in the following section. 25 13241 Woodland Park Road, Suite 400 Herndon, VA 20171 USA 703.561.0500 3 In the Products & Services section, you must first select the Partner/Application that the user needs the FIS Certificate for, the Assurance Level (either Basic or Medium). If you select Basic, another drop down menu will appear requesting you to select Certificate Usage. Note: If you need additional assistance determining whether to choose a Basic or Medium Level digital certificate, please click View More Information. Note: In the Certificate Usage drop down - if the purpose of the user’s Basic Certificate is use with ForumPass, then the FISA MUST approve the user for only Identity. SecureEmail is project specific and is only used for certificates for email encryption. Your organization will have received specific instructions if you are to use SecureEmail. Using the drop down menu select Software for the certificate type. Select the Certificate Validity Period. For a Basic Certificate there is only one option which is 1 year. For a Medium Certificate you may choose 1 year or 3 years. Select Request Reason, the user’s reason for needing this digital certificate. 4 In the FIS Administrator Action section you must choose whether to Approve or Deny the certificate request. Select Approve, then click Next. If you select to Deny the request for the certificate, you must enter Comments addressing the reason for denial. The user will receive an email advising them that the request was denied and the email will include those comments. Note: You also have the ability to select Cancel, such that you will be able to cancel out and go back to the respective request queue. 26 13241 Woodland Park Road, Suite 400 Herndon, VA 20171 USA 703.561.0500 5 Step Multiple FIS Certificate Approvals by FIS Admin 1 Confirmation page is displayed and the user is approved for the certificate. Action Login to MAG as a FIS Admin and access the Registration Requests tab. Click Authorize FIS to view the list of pending users. 2 All pending requests will be listed. The FIS Admin has the ability to approve/deny multiple requests at one time. Place a checkmark in each box that you would like to process together. From the drop-down menu select Approve Selected Requests or Deny Selected Requests. Select Approve Selected Requests and click Apply. Note: The FIS Admin shall be able to approve/deny a maximum of 30 requests at a time. If the FIS Admin selects Deny Selected Requests, a Deny Comments page will be displayed. The comments entered will be returned, via email, to each individual user. 3 The Approve Confirmation will be displayed. Select Yes to Continue or No to Cancel. 27 13241 Woodland Park Road, Suite 400 Herndon, VA 20171 USA 703.561.0500 Select Yes. 4 3.6 The Approve Results will be displayed indicating you have successfully approved the requests. User Functionality In this section, we will provide steps to complete two common functions performed by MAG users: the process of User Self-registration, and Requesting a Password Reset. 3.6.1 User Self-registration Users can initiate the process by which their account is created in MAG and the application access is granted by going through the User Self-registration process. Step User Self Registration 1 Action Go to https://portal.exostar.com/userRegistration . The Self-registration process occurs in several steps: First, working in the MAG portal, you must complete the first two steps: 2 Complete all required Organization Information and Personal Information fields. Notes: • After you enter the Organization ID, click Verify Organization to populate the next two fields. • All required fields are denoted by *. • You will need to use the One-time password when logging into MAG for the first time • It is recommended that you use your organization domain email address, not a personal email address. 28 13241 Woodland Park Road, Suite 400 Herndon, VA 20171 USA 703.561.0500 Click Next to continue. 3 Next, select the application(s) to which you would like access. The products and services that are listed on this page are based on selections made by your organization. 29 13241 Woodland Park Road, Suite 400 Herndon, VA 20171 USA 703.561.0500 Place a check mark next to each application that you would like to request access to. Click Next to continue. 4 If you requested access to the Federated Identity Service (FIS), you will be required to complete additional information regarding your requested certificate. Complete all required fields, then click Next to continue. Note: You may click on the links to obtain additional information on certificate types. 5 The Submission Confirmation page will be displayed and your request has been sent to your Administrator. 30 13241 Woodland Park Road, Suite 400 Herndon, VA 20171 USA 703.561.0500 Note: The reference number is provided and should be used if you need to contact Customer Service for support with MAG related issues or questions. 6 You will receive an email confirming that your request has been received. The Application Admin also receives an email advising of your pending request. At this point, there is no action required on your part. Your Organization Administrator will process your request. 7 Once your request has been approved by your Org and App Admin, you will receive an Exostar Account Created Notification email. This email is very important as it contains your user ID and system generated password which are both required for your first time login. 8 Click on the URL provided in the email. The First Time Login page is displayed. Enter your user ID, one-time password (created during your registration) and the system generated password provided to you via the account notification email. Click Continue. 9 You are prompted to create a new password. Enter and Re-enter the new password. 31 13241 Woodland Park Road, Suite 400 Herndon, VA 20171 USA 703.561.0500 Click Submit. 10 You are prompted to provide Password Reset Secrets. These will be used if you should ever need to request a password reset in the future. Choose questions from the drop-down menu and provide appropriate answers. Please ensure you remember these ‘secrets’ for future use. Click Submit to continue. 11 You have successfully modified your password and you will be automatically redirected to the MAG Account Page. 12 Your MAG Dash Board window has two tabs: Home tab –contains several containers of information including My Applications, My Organization, My Tasks, Quick Links and Account Summary. Each of these sections is explained in greater detail in Section 3.2. My Account tab – allows you to manage your account information relating to MAG. 32 13241 Woodland Park Road, Suite 400 Herndon, VA 20171 USA 703.561.0500 Note: Listed applications will show a status of Pending until you are granted application access by the appropriate administrator. Once you have access, your account status will indicate Active. 3.6.2 Request Password Reset (Forgot Password) To reset the MAG password, a user can access the MAG portal (https://portal.exostar.com) and request a password reset. To reset your password, follow the steps outlined below. Step Action 1 From the MAG login page, select the Forgot Password link. 2 Enter your User ID. Click Continue. 3 You will then be prompted to select and answer two of your security questions that you established during your first time login. Click Continue. 33 13241 Woodland Park Road, Suite 400 Herndon, VA 20171 USA 703.561.0500 If you cannot remember your security questions and answers you can select Forgot Security Questions/Answers? – Follow these steps to reset your password – and follow that workflow to reset your password. 4 Enter your New Password and Re-enter new password and click Continue. 5 You will receive confirmation that your password has been reset and will automatically be redirected to the MAG Applications tab. 34