<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Separate AD user for each application in Product Forum</title>
    <link>https://community.blueprism.com/t5/Product-Forum/Separate-AD-user-for-each-application/m-p/57097#M11161</link>
    <description>Hi!&lt;BR /&gt;&lt;BR /&gt;I have troubles finding a good and secure structure for setting up a Blue Prism infrastructure where the IT-department wants a separate AD-user for each application the robot is using. At the same time they also want to set up Blue Prism with single sign on.&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;What is the most elegant way to solve this problem?&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;I have tried to see if I can use comand line params to launch applications from Blue Prism. However, this is not very secure do to the fact that Blue Prism then has to send the credentials for the user into the comand line.&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;It would also not be optimal for each process to log into the machine for each time it is going into a new system. For us developing it will also not be optimal.&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;Thanks!&lt;BR /&gt;Edda&lt;BR /&gt;&lt;BR /&gt;------------------------------&lt;BR /&gt;Edda Burheim&lt;BR /&gt;Senior Consultant&lt;BR /&gt;AVO consulting&lt;BR /&gt;------------------------------&lt;BR /&gt;</description>
    <pubDate>Tue, 18 Jun 2019 12:15:00 GMT</pubDate>
    <dc:creator>EddaBurheim</dc:creator>
    <dc:date>2019-06-18T12:15:00Z</dc:date>
    <item>
      <title>Separate AD user for each application</title>
      <link>https://community.blueprism.com/t5/Product-Forum/Separate-AD-user-for-each-application/m-p/57097#M11161</link>
      <description>Hi!&lt;BR /&gt;&lt;BR /&gt;I have troubles finding a good and secure structure for setting up a Blue Prism infrastructure where the IT-department wants a separate AD-user for each application the robot is using. At the same time they also want to set up Blue Prism with single sign on.&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;What is the most elegant way to solve this problem?&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;I have tried to see if I can use comand line params to launch applications from Blue Prism. However, this is not very secure do to the fact that Blue Prism then has to send the credentials for the user into the comand line.&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;It would also not be optimal for each process to log into the machine for each time it is going into a new system. For us developing it will also not be optimal.&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;Thanks!&lt;BR /&gt;Edda&lt;BR /&gt;&lt;BR /&gt;------------------------------&lt;BR /&gt;Edda Burheim&lt;BR /&gt;Senior Consultant&lt;BR /&gt;AVO consulting&lt;BR /&gt;------------------------------&lt;BR /&gt;</description>
      <pubDate>Tue, 18 Jun 2019 12:15:00 GMT</pubDate>
      <guid>https://community.blueprism.com/t5/Product-Forum/Separate-AD-user-for-each-application/m-p/57097#M11161</guid>
      <dc:creator>EddaBurheim</dc:creator>
      <dc:date>2019-06-18T12:15:00Z</dc:date>
    </item>
    <item>
      <title>RE: Separate AD user for each application</title>
      <link>https://community.blueprism.com/t5/Product-Forum/Separate-AD-user-for-each-application/m-p/57098#M11162</link>
      <description>It sounds like you're trying to launch via the runas command? You can bypass the callback for a user's password and supply it in the same go by using PSExec from the PSTools package. The only thing with this is that you still have to store the credentials someplace, which even though they're encrypted, may violate security policies if you aren't using dedicated service accounts.&lt;BR /&gt;&lt;BR /&gt;------------------------------&lt;BR /&gt;Ami Barrett&lt;BR /&gt;Lead RPA Software Developer&lt;BR /&gt;Solai &amp;amp; Cameron&lt;BR /&gt;America/Chicago&lt;BR /&gt;------------------------------&lt;BR /&gt;</description>
      <pubDate>Tue, 18 Jun 2019 15:26:00 GMT</pubDate>
      <guid>https://community.blueprism.com/t5/Product-Forum/Separate-AD-user-for-each-application/m-p/57098#M11162</guid>
      <dc:creator>AmiBarrett</dc:creator>
      <dc:date>2019-06-18T15:26:00Z</dc:date>
    </item>
  </channel>
</rss>

