Skip to main content

Migrate provider settings

In Axidian Access 8.2 and higher, the authentication provider settings are located in the Management Console. When you update from earlier versions, you can transfer the provider settings that were previously defined in policies and in the registry with the EA.Settings.Migration.Tool utility. This utility also allows you to display the forced authenticator verification setting.

When settings are migrated from policies, the authenticator settings of the policy with the highest priority are transferred.

You can transfer the settings of the following providers:

The following settings are transferred:

  • The authenticator actions available to the user that require registration.
  • The maximum number of authenticators that require registration, as defined in the policy with the highest priority.
  • The settings of the Forbid to use option for all the installed authenticators, as defined in the policy with the highest priority.

Preparation​

Before you migrate the settings:

  1. Decrypt the Core Server configuration file C:\inetpub\wwwroot\am\core\Web.config in one of the following ways:
    • With the configuration wizard. Open the C:\inetpub\wwwroot\am\core\Web.config file, go through all the steps again, and at the File encryption step, clear the Encrypt the configuration file (recommended) option.
    • With the decryptConfigs.bat script. For more information, see Core Server.
  2. Create a backup copy of the database.
  3. Create backup copies of the configuration files and of the registry of the server components, either manually or with the UpdateHelper utility.
  4. If you migrate the settings from the registry, make sure that a group policy with the registry settings is applied on the server with Core Server installed.
  5. If you migrate the settings from a policy, create a backup copy of the C:/inetpub/wwwroot/am/core folder for Axidian Access 8.1.x before you update the server to 8.2.x. This folder is used as the data source.

Migration​

To transfer the settings with the utility:

  1. Run the axidian 8.2.x\Axidian Access Manager Server\8.2.x\Misc\EA.Settings.Migration.Tool\EA.Settings.Migration.Tool.exe file.

  2. Confirm that you have created a backup copy of the database.

  3. Enter the Core Server address in the http(s)://full_dns_server_name/am/core/ format.

  4. If required, enter the credentials for access to Core Server.

  5. Specify the path to the Core Server configuration file.

  6. Use the arrow keys to select one of the options and perform the actions required for it:

    • Auth method settings — migration of the settings from the registry. After you select this option, select the providers whose settings you want to transfer, using the spacebar or the Ctrl+A key combination (to select all the providers).

    • Policy settings — migration of the settings from a policy. After you select this option, enter the path to the backup copy of the Core Server Web.config configuration file. Then select the policy whose settings you want to transfer.

    • Forced Authenticator Verification policy — to display the forced authenticator verification setting in the Management Console.

    Note

    The forced authenticator verification setting is displayed only for the one-time password authentication providers that have already been installed. After you install new providers, run the migration again.

  7. Press Enter.

  8. In the log that is displayed, make sure that the settings have been migrated successfully.

Important

After you transfer the settings, check the number of authenticators in the Maximum number setting for each provider in the Management Console.