JIT for computers configuration - Idemeum Docs

JIT for computers settings

Navigate to Care settingsJIT access to configure how you want JIT accounts to be managed for your customer / organization.

Technician login mode

individual | shared

Choose how you want technicians to login into workstations - with individual accounts or one shared account per organization / customer tenant. Default is individual accounts as that is required by security frameworks.

Domain computers login mode

local | domain | prompt to choose

Choose how technicians login to domain computers. By default local admin account is used.

Choose OU for JIT domain accounts

OU string

For domain JIT computer accounts you can choose the Organization Unit (OU) container where these accounts will be created.

Account password length

12 | 16 | 24

Choose the password length for created JIT admin accounts.

Enable login via TOTP

on | off

By default technicians login by scanning a QR-code with idemeum mobile app. You can also provide an option to login with OTP even when the computer is not offline. Technicians retrieve the OTP from the mobile app and enter it into the login screen.

Enable push notifications for login

on | off

Enable the option to send a push notification to a mobile app instead of scanning a login QR-code. Technicians enter their email address and then approve a notification on their mobile app.