Skip to content

Security Consideration for Resources

The table below describes the security considerations for the resources (file, network and database) that an integration uses. The Recommended Strategy column refers to the user that IMan runs as, set with the IMan Permissions Function.

Resource Security Implication Recommended Strategy
Applications Using Windows/Active Directory Authentication IMan needs sufficient access to any application that uses Windows authentication, for example a LAN- or WAN-based webservice. Create or configure a local or domain user (depending on location of application to IMan) with sufficient access to the application.
Connectors Needing File Resources (Sage 300, Sage 50) Connectors such as Sage 300 and Sage 50 have file resources that IMan must be able to access. See ‘File Resources’ below.
Connectors Using Windows Authentication (Sage 200) A connector that uses Windows authentication, such as Sage 200, must be able to authenticate as a Windows user with sufficient rights. See ‘Applications Using Windows/Active Directory Authentication’
Databases Databases that use Windows credentials, for example SQL Server accessed with Integrated Security, must allow the relevant access. Create local or domain user (depending on location of database to IMan) with sufficient access to the database.
File Resources Integrations with a file based component require sufficient rights to read or write to that location. If the files are local, Local System has access to them by default. Where permissions have been set explicitly, either allow access to Local System or create a user (local or domain) with read and write rights to the required locations. If the files are on a remote server, create a domain user with read and write rights to the required locations.
Proxies & Internet Based Resources IMan has limited support for internet-based resources (FTP, email and webservices) that need proxy authentication. To reach these resources, the proxy must support transparent authentication. For example, Microsoft Internet Security and Acceleration Server supports domain-user authentication. Configure the proxy to allow direct internet access from the server, or use a proxy that supports transparent authentication.