HP BladeSystem bc2800 Administrator's Guide HP Session Allocation Manager (HP - Page 14

How HP SAM Works, HP SAM uses HP Remote Graphics Software RGS or Microsoft® Remote Desktop

Page 14 highlights

How HP SAM Works 1. When a user on an access device (desktop, notebook, thin client) requests a desktop session, the HP SAM client sends a request to the HP SAM Web server. a. If configured, HP SAM supports server failover. If the HP SAM Web server does not respond, the HP SAM client goes down the list to the next HP SAM Web server. b. The HP SAM client sends the user name and domain information to the HP SAM server. 2. The HP SAM Web server receives the user name and domain name from the HP SAM client. The Web server validates this information with the Microsoft Active Directory server. The account must be valid and enabled in Active Directory to continue. Normally, the password is not authenticated at this point, but is authenticated when logging into the operating system on the resource. With HP SAM 3.0, the Authenticate Before Allocation feature can be enabled which will cause the password authentication to occur during this step instead. 3. The HP SAM Web server returns the appropriate desktop session information to the HP SAM client. a. The HP SAM Web server determines whether or not the user still has a desktop session running and, if so, reconnects the user to that same session (i.e., follow-me roaming). If the user has no existing desktop session, the HP SAM Web server checks its internal database to see what resources are available and connects the user to an appropriate resource. b. If the user has more than one role or resource assignment, they will be prompted to choose. c. The data returned to the HP SAM client contains the IP address(es) (or Host name(s), depending on how it is configured on the HP SAM Web server) of the appropriate resources. d. If no computing resource is available, the HP SAM client informs the user. 4. The HP SAM client connects to the appropriate desktop session. NOTE: HP SAM uses HP Remote Graphics Software (RGS) or Microsoft® Remote Desktop Protocol (RDP) to connect between access devices, computing resources, and OUs. 5. The user is then prompted at the login screen for the password. The user name and domain is prepopulated by the HP SAM client. This step is omitted if the user has already entered the password on the HP SAM client and either RDP is used or RGS in Single Sign-on mode is enabled. NOTE: With RDP, RGS 5.1 or later, or Authenticate Before Allocation (seeAuthenticate Before Allocationon page 3), HP SAM allows users with expired passwords to log on. They are then required to update their passwords immediately. 6. Once the user logs in, the HP SAM registration service on the computing resource reports back to the HP SAM Web server. 7. Once the user disconnects or logs out, the HP SAM registration service updates the HP SAM Web server with the new information. 6 Chapter 1 Introduction ENWW

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104

How HP SAM Works
1.
When a user on an access device (desktop, notebook, thin client) requests a desktop session, the
HP SAM client sends a request to the HP SAM Web server.
a.
If configured, HP SAM supports server failover. If the HP SAM Web server does not respond,
the HP SAM client goes down the list to the next HP SAM Web server.
b.
The HP SAM client sends the user name and domain information to the HP SAM server.
2.
The HP SAM Web server receives the user name and domain name from the HP SAM client. The
Web server validates this information with the Microsoft Active Directory server. The account must
be valid and enabled in Active Directory to continue. Normally, the password is not authenticated
at this point, but is authenticated when logging into the operating system on the resource. With HP
SAM 3.0, the
Authenticate Before Allocation
feature can be enabled which will cause the
password authentication to occur during this step instead.
3.
The HP SAM Web server returns the appropriate desktop session information to the HP SAM client.
a.
The HP SAM Web server determines whether or not the user still has a desktop session
running and, if so, reconnects the user to that same session (i.e., follow-me roaming). If the
user has no existing desktop session, the HP SAM Web server checks its internal database
to see what resources are available and connects the user to an appropriate resource.
b.
If the user has more than one role or resource assignment, they will be prompted to choose.
c.
The data returned to the HP SAM client contains the IP address(es) (or Host name(s),
depending on how it is configured on the HP SAM Web server) of the appropriate resources.
d.
If no computing resource is available, the HP SAM client informs the user.
4.
The HP SAM client connects to the appropriate desktop session.
NOTE:
HP SAM uses HP Remote Graphics Software (RGS) or Microsoft® Remote Desktop
Protocol (RDP) to connect between access devices, computing resources, and OUs.
5.
The user is then prompted at the login screen for the password. The user name and domain is
prepopulated by the HP SAM client. This step is omitted if the user has already entered the
password on the HP SAM client and either RDP is used or RGS in Single Sign-on mode is enabled.
NOTE:
With RDP, RGS 5.1 or later, or Authenticate Before Allocation (see
Authenticate Before
Allocation
on page
3
), HP SAM allows users with expired passwords to log on. They are then
required to update their passwords immediately.
6.
Once the user logs in, the HP SAM registration service on the computing resource reports back to
the HP SAM Web server.
7.
Once the user disconnects or logs out, the HP SAM registration service updates the HP SAM Web
server with the new information.
6
Chapter 1
Introduction
ENWW