docs: update outdated Access Management webui references (#57248)

* update outdated Access Management webui references

* update outdated Access Management webui references

 addressed feedback from Zac and Paul
This commit is contained in:
marie
2025-07-31 20:21:49 +00:00
committed by GitHub
parent be4c871ddf
commit f9527cc6f2
18 changed files with 23 additions and 43 deletions
Binary file not shown.

Before

Width:  |  Height:  |  Size: 138 KiB

After

Width:  |  Height:  |  Size: 40 KiB

Binary file not shown.

Before

Width:  |  Height:  |  Size: 168 KiB

Binary file not shown.

Before

Width:  |  Height:  |  Size: 190 KiB

After

Width:  |  Height:  |  Size: 40 KiB

Binary file not shown.

After

Width:  |  Height:  |  Size: 48 KiB

Binary file not shown.

After

Width:  |  Height:  |  Size: 66 KiB

Binary file not shown.

After

Width:  |  Height:  |  Size: 27 KiB

Binary file not shown.

Before

Width:  |  Height:  |  Size: 226 KiB

After

Width:  |  Height:  |  Size: 99 KiB

Binary file not shown.

Before

Width:  |  Height:  |  Size: 166 KiB

After

Width:  |  Height:  |  Size: 58 KiB

Binary file not shown.

Before

Width:  |  Height:  |  Size: 329 KiB

After

Width:  |  Height:  |  Size: 102 KiB

@@ -20,7 +20,6 @@ process.
This guide details how to integrate GCP workforce Identity Federation service with Teleport
SAML IdP, so users can sign in into GCP web console by authenticating with Teleport.
## Prerequisites
(!docs/pages/includes/edition-prereqs-tabs.mdx edition="Teleport Enterprise"!)
@@ -42,7 +41,7 @@ pool provider to help you quickly get started with the integration.
## Guided configuration flow
Create a workforce pool and pool provider with the script generated by Teleport.
In the Web UI, under **Access Management**, click **Enroll New Resource** menu.
In the Web UI, under **Add New** in the left pane, click **Resource** menu.
In the search box, enter “workforce”, which will show the Workforce Identity Federation
integration tile. Click the tile.
![Test the IdP](../../../../img/access-controls/saml-idp/gcp-workforce/gcp-workforce-tile.png)
@@ -34,15 +34,10 @@ of the service provider.
Below we'll show both of the configuration options.
First, in the Web UI, under **Access Management**, click **Enroll New Resource** menu.
In the search box, enter "saml", which will show the SAML application
integration tile. Click the tile.
First, in the Web UI, under **Zero Trust Access**, click **Auth Connectors** in the menu.
Choose the appropriate SAML application integration tile. Click the tile and follow the resulting steps.
![Enroll SAML app](../../../../img/access-controls/saml-idp/enroll-saml-app.png)
The first configuration step, **Configure Service Provider with Teleport's Identity Provider Metadata**
shows Teleport SAML IdP metadata values. For this guide, you can move to next step by clicking **Next** button
which takes to **Add Service Provider To Teleport** step.
![Enroll SAML app](../../../../img/access-controls/saml-idp/saml-idp.png)
### Option 1: Configure with Entity ID and ACS URL
@@ -177,7 +172,7 @@ already available to access under resources page.
## Step 3/3. Verify access to iamshowcase protected page
To verify everything works, navigate to **Resources** page in Teleport Web UI.
To verify everything works, navigate to **Resources** page in Teleport Web UI and look for the app.
![Access app](../../../../img/access-controls/saml-idp/access-app.png)
@@ -17,7 +17,7 @@ The following features use an AWS OIDC integration to interact with AWS:
It targets users who would prefer a more manual approach or to manage the integration with Infrastructure as Code tools.
As an alternative to this guide, you can use the Teleport Web UI (Access Management / Enroll New Integration).
As an alternative to this guide, you can use the Teleport Web UI. In the left-hand pane, click **Add New** -> **Integration**.
## How it works
Teleport is added as an [OpenID Connect identity provider](https://docs.aws.amazon.com/IAM/latest/UserGuide/id_roles_providers_create_oidc.html) to establish trust with your AWS account and assume a configured IAM role in order to access AWS resources.
+1 -3
View File
@@ -885,9 +885,7 @@ You can use `tsh` to examine sessions that users have completed in resources
protected by Teleport. This section explains how to list and play Teleport
session recordings with `tsh`.
Note that you can also play session recordings in the Teleport Web UI. To do so,
navigate to the **Access Management** tab on the top sidebar and view the
**Session Recordings** tab on the left sidebar.
To view the recording, select **Audit** in the Teleport Web UI, then click **Session Recordings** in the menu.
### Listing recordings
@@ -63,7 +63,7 @@ For the purpose of this guide, we will define an `editor-requester` role, which
can request the built-in `editor` role, and an `editor-reviewer` role that can
review requests for the `editor` role.
In the Teleport WebUI navigate to **Access -> Roles**. Then select **Create New
In the Teleport Web UI navigate to **Zero Trust Access -> Roles**. Then select **Create New
Role** and create the desired roles.
@@ -94,12 +94,12 @@ spec:
First, assign yourself the `editor-reviewer` role. This will allow your user to
review Access Requests for the `editor` role. To edit your user roles navigate to
**Management -> Access -> Users**, then for your user select **Options -> Edit**
**Zero Trust Access -> Users**, then for your user select **Options -> Edit**
and add the `editor-reviewer` role.
Next, create a user called `myuser@example.com` who has the `editor-requester` role.
Later in this guide, you will create an Access Request as this user to test the
Datadog plugin. To this user, navigate to **Management -> Access -> Users**. Then
Datadog plugin. To this user, navigate to **Zero Trust Access -> Users**. Then
select **Enroll Users** and create a user with the `editor-requester` role.
You should end up with two users that look like this:
@@ -141,9 +141,8 @@ to create a new Application key. Copy the Application key to paste in a later st
## Step 4/6. Enroll the Datadog Incident Management plugin
At this point, you're now ready to enroll the Datadog Incident Management plugin.
Navigate to **Access Management -> Enroll New Integration -> Datadog**.
![Select enrollment](../../../img/enterprise/plugins/datadog/select-enrollment.png)
(!docs/pages/includes/plugins/enroll.mdx name="the Datadog Incident Management"!)
Provide the API and Application keys generated above. Select the desired API endpoint.
Then provide the Datadog team handle, that you created earlier, as the fallback recipient.
@@ -154,8 +153,6 @@ can be a Datadog user email, or a Datadog team handle. You can configure more cu
notification routing rules afterwards using
[Access Monitoring Rules](./notification-routing-rules.mdx).
![Datadog enrollment](../../../img/enterprise/plugins/datadog/datadog-enrollment.png)
If the recipient is a Datadog team, the team name will be added to the Datadog incident
teams attribute.
@@ -77,13 +77,7 @@ Create a user called `myuser` who has the `requester` role. Later in this
guide, you will create an Access Request as this user to test the Opsgenie
plugin:
To create a user first navigate to Management -> Access -> Users
![Add user one](../../../img/enterprise/plugins/opsgenie/add-user-one.png)
Then select 'Create New User' and create a user with the requester role.
![Add user two](../../../img/enterprise/plugins/opsgenie/add-user-two.png)
To create a user, first navigate to Zero Trust Access -> Users.
## Step 3/5. Set up an Opsgenie API key
@@ -97,10 +91,9 @@ See https://support.atlassian.com/opsgenie/docs/create-a-default-api-integration
## Step 4/5. Configure the Opsgenie plugin
At this point, you have generated credentials that the Opsgenie plugin will use
to connect to the Opsgenie API. To configure the plugin to use this API key navigate
to Management -> Integrations -> Enroll New Integration.
![Integrations page](../../../img/enterprise/plugins/opsgenie/opsgenie-integration-page.png)
to connect to the Opsgenie API. To configure the plugin to use this API key,
navigate to **Add New** in the Web UI; in the left pane, click **Integration**.
Click the Opsgenie tile.
## Step 5/5. Test the Opsgenie plugin
@@ -208,10 +208,10 @@ $ kubectl -n <Var name="teleport-cluster-namespace" /> rollout restart deploymen
$ kubectl -n <Var name="teleport-cluster-namespace" /> rollout status deployment/teleport-proxy # Wait for the deployment to succeed
```
## Step 4/4. View the Access Graph in the Web UI
## Step 4/4. View Access Graph data in the Graph Explorer
You can find the Access Graph in the "Access Management" tab in the Web UI.
![Access Management menu item](../../../img/access-graph/menu-item.png)
In order to visualize the data from the Access Graph service, use the Graph Explorer in the Web UI.
Click **Identity Security** --> **Graph Explorer** and then select a resource to view in the Graph Explorer.
To access the interface, your user must have a role that allows `list` and `read` verbs on the `access_graph` resource, e.g.:
@@ -124,10 +124,10 @@ access_graph:
Then, restart Auth Service instances, followed by Proxy Service instances.
## Step 3/3. View the Access Graph in the Web UI
## Step 3/3. View Access Graph data in the Graph Explorer
You can find Access Graph in the "Access Management" tab in the Web UI.
![Access Management menu item](../../../img/access-graph/menu-item.png)
In order to visualize the data from the Access Graph service, use the Graph Explorer in the Web UI.
Click **Identity Security** --> **Graph Explorer** and then select a resource to view in the Graph Explorer.
To access the interface, your user must have a role that allows `list` and `read` verbs on the `access_graph` resource, e.g.:
+2 -4
View File
@@ -2,13 +2,11 @@
In Teleport Enterprise Cloud, Teleport manages {{ name }} for you, and you can
enroll {{ name }} from the Teleport Web UI.
Visit the Teleport Web UI and on the left sidebar, click **Access** followed
by **Integrations**. Then click **Enroll New Integration** to visit the
"Enroll New Integration" page:
Visit the Teleport Web UI and on the left sidebar, click **Add New** followed
by **Integration**:
![Enroll an Access Request plugin](../../../img/enterprise/plugins/enroll.png)
On the "Select Integration Type" menu, click the tile for your integration. You
will see a page with instructions to set up the integration, as well as a form
that you can use to configure the integration.