TSS End User Guide
TSS End User Guide
**Please ensure you are connected to Pulse prior to attempting access when
Offsite**
Table of Contents
First time Users: Download TOTP/MFA.......................................................................................................2
How to Use Thycotic....................................................................................................................................2
Login........................................................................................................................................................2
TOTP/MFA...........................................................................................................................................3
Existing Users...................................................................................................................................3
First Time Only or if you have selected “Lost your phone?”............................................................3
Secret Functionality.................................................................................................................................4
Find a TSS Secret..................................................................................................................................4
Favorite a TSS Secret...........................................................................................................................5
Check OUT a TSS Secret.......................................................................................................................6
Check IN a TSS Secret...........................................................................................................................7
Heartbeat Failure due to TSS Secret Lockout.......................................................................................7
Password Functions.............................................................................................................................8
Enable Copy/Paste...............................................................................................................................9
RDP Launcher....................................................................................................................................10
Service Accounts................................................................................................................................11
Static Service Accounts Password Rotation...................................................................................11
Thycotic Connection Manager...............................................................................................................12
Download and Install.........................................................................................................................12
Connection Manager launch..............................................................................................................12
Create new local storage file.........................................................................................................13
Main Screen Navigation.....................................................................................................................13
Configuration.................................................................................................................................13
Password Functions.......................................................................................................................15
Check-Out..................................................................................................................................16
Check-In.....................................................................................................................................16
Backing up “Local Connections”................................................................................................16
Upgrade Notification.........................................................................................................................17
1
Console Functionality........................................................................................................................18
Session Windows............................................................................................................................18
Login
1. Click on the link, to access TSS: https://pam.fss.aramark.com/secretserver
2. On the login screen below, enter your Standard Aramark ID in the “Username” field & your current
network password in the “Password” field then click “Login”
NOTE: This is NOT your TSS Account name that was given. Be aware if you have not received your tss
account you should wait until you do.
2
TOTP/MFA
Existing Users
1. Input your Pin Code & click “Log In”.
3. Click Next
4. Enter the Pin code from the Authenticator application and click “Verify Setup”.
Note: Pin will recycle every 30 seconds on your mobile app.
3
5. A two-factor reset code will display.
Secret Functionality
Find a TSS Secret
1. Click on “Secrets” then proceed to the “Filter Search or the “Global Secret Selector”.
2. “Filter Search” - You can enter any part of a name and it will list all secrets with the similar name.
4
3. “Global Secret Selector” – You can enter the ID or any part of a similar name.
Note: Use this only when you want to select and enter the secret.
a. Highlight over the TSS account you want to favorite, and you will see a STAR
b. Click it to make it turn into a Solid Star.
2. Now click on “Favorites”. You should see all Favorited Secrets.
5
Check OUT a TSS Secret
1. Once you have found the secret you want you will want to click on the Name.
3. You should now be within the secret and can perform your tasks such as:
a. Password Functions
b. RDP Launcher
c. Checking In your account manually
6
Check IN a TSS Secret
There are a couple of ways to check in your TSS account manually.
Note: You might do this after you are finished with the secret or if the account is locked and you need to
get it unlocked via a script on “Check In”.
1. The most common way is to let Thycotic Auto Check the secret in after the checkout time expires.
For most this time is 1 hour.
2. The second way is within the Secret you already have checked out. Click the drop down for Check In
option by clicking the time clock icon.
3. The third method is within Thycotic Connection manager if used or installed.
7
Password Functions
1. Within the Secret you will see its respective information.
2. Copy to your clipboard by simply highlighting over the respective field and selecting the copy icon.
3. These features are useful when having to manually apply to third party browsers or applications
such as SQL or Azure.
4. One last way to check out your password can be done without having to go into the Secret at all.
a. To do this
i. Find the secret in question
ii. Click in the empty space to the right of the Star of the secret
iii. Notice a new popup to the right
iv. Highlight over “Password” and select the copy Icon
8
Enable Copy/Paste
1. Select your “ID” bubble in the top right.
4. Scroll down and find “Allow Access to Clipboard” within the “Launcher Settings” section.
5. If an RDP session exists, you must terminate it and relaunch it to get the copy/paste to function.
9
RDP Launcher
Note: This will use Thycotic as a Gateway Server.
5. Once the RDP Session connects, Click “OK”, for Aramark’s usage Warning.
10
Service Accounts
Static Service Accounts Password Rotation
1. Find the intended Service account secret within Thycotic via the secret filter or by the secret
selector. See section Find a TSS Secret
2. Once found make sure you are inside the secret by clicking on the secrets name and enter the
comment for the intended function.
Note: Make sure you have scheduled Change Management for any production impact.
3. At the top of your secret page there is a “Change Password Now” field.
4. Make sure the default for “Next Password” is set to “Randomly Generated” then click “Change Password”.
Note: Make sure you do the change in a timely manner, or you will be forced to re-enter your comment.
5. Once the change occurs make sure the password has changed and is not waiting on a change.
You can validate this by going to the “RPC” tab and reviewing.
11
Thycotic Connection Manager
Download and Install
1. Download the Installer for your OS
a. Windows Installer File (MSI)
b. MAC Installer File (DMG)
2. Install and configure client – Full instructions on vendor site https://docs.thycotic.com/cmgr/current
a. Find and Double-click the MSI file to start the install process
b. Click Next to continue.
c. Leave the location to install Connection Manager as the default location.
d. Click Next to confirm the location and accessibility for the install.
e. Click Next again to start the installation. A progress bar will be displayed while the installation is
in progress.
f. Once the install has finished, click Finish.
g. The install is complete, and the Connection Manager icon will be added to the desktop for easy
access.
1.
a.
2. Enter the password you previously created and click “Start”.
12
Create new local storage file
Warning!! You can choose this however that will remove all existing connections.
1. Select “Create new local storage file”
2. Select “Yes” at the Warning popup to Continue
13
Configuration
1. Click in the area where you see the “Gear” and the word “Configuration” located at the bottom Left
14
5. Secret Server Connections – Step 3 of 3.
a. Select all Templates prefixed with “AramarkAD”
b. Uncheck all with +Svc.
6. Click “Finish”
15
Password Functions
1. You can Check-In your secret via Connection Manager by:
a. Click in the empty space to the right of the Star of the secret
b. Notice a new popup to the right
c. Highlight over “Password” and select the copy Icon
Check-Out
1. Check-Out automatically occurs when you start your Local Connection to a Server.
Check-In
1. You can Check-In your secret via Connection Manager by:
16
a. Click in the empty space to the right of the Star of the secret
b. Notice a new popup to the right
c. Click “Check-In
Backing up “Local Connections”
1. Right click on “Local connections” and Select “Export”
17
2. Open your windows Explorer and validate the new file exists.
Upgrade Notification
1. At any time, if prompted to upgrade your current version of Thycotic Connection Manager
Console Functionality
Session Windows
1. If you want to fully maximize a Session Window you can drag console window out of Connection
Manager window.
a. Click and drag the window tab out
18