GITEX Global on October 13 — 17 in Dubai

More results

Generic selectors
Exact matches only
Search in title
Search in content
Post Type Selectors
Filter by Categories
Events
Knowledge Base
News
Press Releases
Reviews
Success Stories
Update
Webinars
Back

How to securely connect external users to chats on TrueConf Server?

6 min.

Сorporate messengers are widely used in various companies, and in some cases, it is critical to connect external users, e.g., contractors and partners, to the corporate chat. To minimize the risk of information leakage, let us discuss secure ways of connecting external users to the chats.

TrueConf Server is well-equipped to handle this task since it offers all the necessary tools and features:

  • User account management and configuration;
  • User administration and permissions management for user groups;
  • Authentication settings in the video conferencing system;
  • And more, refer to the documentation for more details.

In the context of this article, guests or external users are chat participants authenticated on an external server. Do not confuse them with guests in a webinar (public conference).

This will enable your users to:

  • Invite external participants to internal (corporate) chats;
  • Safely receive and send files in chats with external users;
  • Call external users and invite them to conferences.

Use of federation

Federation mode enables you to configure the connection of external users from other TrueConf Servers. To use this method, you will need to deploy an additional TrueConf Server and set up federation on both servers. To achieve maximum security, we recommended running the second TrueConf Server in the DMZ (demilitarized zone of your network). The picture below shows how this method will work:

How to securely connect external users to chats on TrueConf Server? 1

An alternative solution is to deploy the second “guest” TrueConf Server in a cloud (VPS) on rented machines from any suitable provider. Federation will need to be configured between your server and the guest server. This method will work in the following way:

How to securely connect external users to chats on TrueConf Server? 2

Whichever option is chosen, the corporate server will work in the usual manner. Access permissions for external users are controlled on the “guest” server by creating full accounts. On the guest server, you will need to configure the federation mode, user accounts, and the address book of guest users.

To configure the corporate server, just set up the federation mode and address book for corporate users.

Step 1. Configuration of federation on the corporate server

To set up federation on the corporate server, take the following steps:

  • Select the federation mode Allowed for whitelisted servers in the drop-down list.
  • Click the Add button to include the domain name of the external server in the white list.
  • Click the Apply button to restart the corporate server and save changes.

The full guide on federation is provided in this documentation section.

Step 2. Configuration of federation on the guest server

Federation for the guest server can be configured in the same way as for the corporate server (refer to the description above).

Step 3. Creating accounts for external users

Finally, you need to create accounts for guest server users. Switch to Registry data storage mode. In this mode. data is stored locally on the server. This approach will allow you to conveniently edit accounts and permissions for user groups.

Next, create accounts for guest users, and ,if needed, create separate groups for them and configure permissions.

When accounts are created, users will be able to log in to the guest server with the login and password. You can share the login information with the users in any convenient way.

Step 4. Configuration of users’ address book on the corporate server

To make sure that users on your server and external users can see each other in the contact list, you will need to configure their address book.

TrueConf Server does not allow administrators to add the entire group of federated users to the address book. The thing is that there can be many federated servers, and it is necessary to flexibly configure the visibility of users in the address book independently of each other. So, we will show how to link users from two servers.

Let us suppose that the main server is hosted at corp_server.com. As shown above, deploy the second server for guest users, for example guest_server.com. Create user accounts in Registry mode on the second server, and then configure the address book on both servers.

Suppose that certain groups on the corporate server corp_server.com will interact with guest users of the server guest_server.com, e.g., Sales, Operators, and Technical Support. It is necessary to add the guest server users to the address book of these groups.

To do it, on the server corp_server.com, click on Groups in the sidebar, click Customize in the Address Book column of the Operators group, and add a user in the Group address book section.

Enter the full TrueConf ID of the guest user, for example, moore@guest_server.com, and this person’s display name. For the sake of convenience, we recommend adding a note which would indicate that this user is from a different server, for example, Albert Moore (Guest) or Albert Moore (guest_server.com). Continue adding other users in this manner, and repeat the process for the Sales and Technical Support groups.

How to securely connect external users to chats on TrueConf Server? 3

Step 5. Configuration of address book for guest server users

To make sure that guest server users can contact corporate server users on their own, you should set up their address book in the same way as for corporate users.

For example, on the external server guest_server.com, click on Groups in the side menu. Next click Customize in the Address Book column of Users without a group (by default, all created users can be found here), and add a user in the Group address book section.

Enter the full TrueConf ID of the corporate user, for example, wolf@corp_server.com, and his/her display name. For the sake of convenience, we recommend adding a note indicating affiliation with another server, such as James Wolf (Corp.) or James Wolf (corp_server.com). Add other users in the same way.

How to authenticate as a guest user

To connect to the server, external users have to take these steps:

  • When the application is launched for the first time, click the Sign In button in the pop-up window.
  • In the opened window, select the Corporate user account. option in order to authenticate on the guest server with the account created previously.
  • Next, click the button Enter server address manually.
  • Enter the server address which can be obtained from the administrator.
  • Specify your TrueConf ID (login) and click Next.
  • On the next window, enter the account password (we recommend checking the box Remember Password) and click Next.

For more details on authentication, guest server users should refer to the application documentation.

What features can be enabled for external users?

The administrator of the corporate server can configure the permissions of external users by editing the rights for the Federated Users group. It is possible to configure the rights for the following actions:

  • Edit the address book;
  • Create group conferences;
  • Share content;
  • Show slides;
  • Send files to chats;
  • Download files in chats;
  • Record conferences in a client application;
  • Send a request for the remote control of a meeting participant’s desktop;
  • Allow control of one’s own desktop;
  • Operator rights.

Here, you can flexibly configure permissions for external users; for example, you may disable the right to send files to the chat due to security reasons; however, you can allow them to download files sent by the users of the corporate server.

To edit permissions, go to the control panel of the main (corporate) server, and click on Groups in the side menu. Find the Federated Users group in the table and use the toggles to enable or disable features for this user group.

Additionally, you can select what kind of data about the users of your server should be visible to federated users. To do it, go to the Users → Settings in the side menu. In the Display Fields area, you can use toggle switches to specify which data is displayed for federated (external) users.

How to protect the corporate server from external users?

When federation is set up, the administrator should use the following settings to configure the server according to corporate security policy:

Previous article Next article

Try out the secure video conferencing platform TrueConf!

Video conferencing solution TrueConf Server works inside of your closed network without an internet connection
and allows you to gather up to 1,500 people in one conference!

Content