Exercise Overview:

Exploring the Settings Application

Now that Tachyon has been installed and the 1E Client deployed, and we have explored the Tachyon Portal and the Applications, we are ready to configure Tachyon. Before we can use Tachyon, we need to create some users and assign them roles, so they can administer the system. The install account we used to install Tachyon has very limited rights to administer Tachyon, one of them being the ability to add new users and configure new roles. Thus, you want to install with an account which you will not be using for administration in Tachyon, beyond managing users/roles and adding Instruction Sets.

Configuring Tachyon Users and Roles

Configure Tachyon Users and Roles


  1. Log onto 1ETRNAP as 1ETRN\AppInstaller
  2. Launch the Tachyon Portal via https://tachyon.1etrn.local/tachyon using Google Chrome
  3. Create a Bookmark to the Portal – we will be using this often
  4. Launch the Settings Application
  5. Navigate to Permissions - Users, note that only one actual user exists: 1ETRN\AppInstaller
  6. This is the account we installed Tachyon with. It has limited rights in Tachyon, one of which is the ability to manage users and roles.
  7. Navigate to Roles - Review the default roles and their descriptions
  8. These are very granular roles, which might be used in some environments. However, usually you will want to have a combination of these roles applied to individual users or AD groups.
  9. On the Users tab, click the Add button to the far right to add a new user
  10. In the Add user box in the middle, start typing tachyon_admins and Select Tachyon_admins when it resolves from the suggestion list. Click Add
  11. Repeat the process to add 1ETRN\Tachyon_adminG as a user and then select the Tachyon_AdminG account by clicking in the Name column. Click Edit in the far right. Select Global Approvers and click Save
  12. Navigate to Users and Click on Tachyon_Admins
  13. Click Edit and add the following roles to the Tachyon_Admins group – Global Actioners, Global Approvers, Instruction Set Administrators. Click Save. Select the Group Members tab
  14. Why is this page empty? Hint – you will find out in the next task.
  15. Navigate back to Users and click on the AppInstaller user and note the roles that are assigned to this user
  16. Note all the Roles that are available in Tachyon. If you are familiar with the previous versions of Tachyon you will notice a significant increase.


  1. Log onto 1ETRNDC as 1ETRN\Administrator
  2. From the start menu, launch Active Directory Users and Computers
  3. Under the Users node, locate the Tachyon_admins group
  4. Double-click the group, and click on the Members tab. Note that there are no members in this group
  5. Click the Add button
  6. We installed Tachyon using the LDAP for Active Directory. We can use any Global or Universal Security Groups from Active Directory. If we had used GC(Global Catalog) variable for Active Directory, any groups we want to use in Tachyon must be configured to be universal for Tachyon to have visibility to them
  7. In the search box, type in Tachyon_admin and hit the Check Names button
  8. Multi select tachyon_admin1 and tachyon_admin2. Click OK. Click OK
  9. Ensure the correct users have been added. Click OK


  1. Return to the Tachyon Portal - Settings Application on 1ETRNAP
  2. Navigate to Permissions – Users Click on 1ETRN\Tachyon_admins user, and click the GroupMembers tab at the top
  3. Note it displays the members we just added to that group.
  4. Click the Roles tab at the top. Notice that we have the Global Actioners role, the Global Approvers role and Instruction Set Administrators role

Adding Additional Users and Roles

We need to add some additional users and roles in Tachyon for our upcoming exercises


  1. Return to the Settings Application from the Tachyon Portal
  2. Navigate to Permissions - Users and add the following users and their roles:
  3. UserRole(s) to assign


    Experience Viewers
    Guaranteed State Viewers
    Inventory Viewers
    Patch Success Viewers


    Guaranteed State Administrators
    Instruction Set Administrators


    Global Administrators


    Connector Administrators
    Global Questioners

    Instruction Set Administrators
    Inventory Administrators
    Management Group Sync Initiators
    Schedule Administrators

Exploring the Settings Application


  1. Still logged in as 1ETRN\AppInstaller
  2. Look at the other nodes of the Settings Application. Configuration, Monitoring and Instructions we will look at these in greater detail in later exercises
  3. Click Switch app Notice that we can only switch to Explorer
  4. This account does not have access to Experience, Guaranteed State, Inventory or Patch Success, so those options do not even appear in the navigation.

Exploring the Explorer Application

In this exercise, we will log on as different users and look at the Explorer Application based on what permissions each user has.

View as Global Actioners, Global Approvers, and Instruction Set Admins


  1. Log into 1ETRNW71 as 1ETRN\Tachyon_admin1
  2. Launch the Tachyon Portal by opening a browser and navigate to https://tachyon.1etrn.local/tachyon in Google Chrome
  3. If the machine is already logged in, log out and log in with the account listed above.
  4. Add the Tachyon Portal as a bookmark on each of the devices
  5. Open the Settings Application at the bottom of the page. Note only the Instructions Node is available
  6. Click on Switch app at the bottom and Navigate to Explorer
  7. If you are familiar with the prior versions of Tachyon – this is our Explorer Application
  8. Navigate around and notice which nodes are available. Click Switch app to try to navigate to the other applications
  9. We configured the Tachyon_admins AD group with granular security roles (Instruction Set Administrators, Global Actioners, and Global Approvers), thus only nodes and Applications applicable to those roles will be visible.
  10. Stay logged in and leave the console running, we will revisit this machine with this logged in user later in the labs

View of Guaranteed State Administrators


  1. Log onto 1ETRNW72 as 1ETRN\Manager1
  2. Launch Google Chrome and navigate to https://tachyon.1etrn.local/tachyon
  3. Launch the Guaranteed State Application create a bookmark
  4. Manager1 is our Guaranteed State Administrator and could also access Guaranteed State without going through the Tachyon Portal via https://tachyon.1etrn.local/tachyon/app/#/guaranteedstate
  5. Launch each of the nodes to see what they contain. There will not be much data yet as we have not created any policies. We will revisit this in later exercises
  6. Notice that 1ETRN\Manager1 has no access to any of the other applications in the Tachyon Portal. It can see the Explorer Application in Switch App but cannot navigate there as all of the responses will be passed into the Guaranteed State Application

View as a Global Approver


  1. Log onto 1ETRNW73 as 1ETRN\Tachyon_adminG
  2. Navigate to https://tachyon.1etrn.local/tachyon in Google Chrome
  3. Launch the Explorer application. Note the nodes available for this account
  4. 1ETRN\Tachyon_adminG is our Global Approver role, so it only has access to the Explorer Application to approve instructions. You can see that it does not have access to any of the other applications in the Tachyon Portal.
  5. Expand the Devices node, and click on Table
  6. Note that 7 clients are shown in the top pane, each with an Online status. If any machines show as being offline, check to ensure they are powered on
  7. There might be machines that haven't yet run the installation package via SCCM. Carry on with the labs, they'll show up in due time.
  8. Navigate to Devices – Dashboard. Have a look at the items that are available to this user
  9. Navigate to Notifications. Notice that it is empty as we do not have any instructions yet
  10. Leave the browser open we will be back to this one in a bit
  11. Click on the Start button in Windows, and in the search box type Calc. Click on the Calculator application and launch it. Minimize it and leave it running
  12. We will be using Tachyon to kill the Calculator application in a later exercise, so we're prepping the environment for Tachyon usage labs.

View as Experience, Guaranteed State, Inventory and Patch Success Viewer


  1. Log onto 1ETRNW101 as 1ETRN\user
  2. Navigate to https://tachyon.1etrn.local/tachyon in Google Chrome
  3. Launch the Explorer application from the Tachyon Portal
  4. 1ETRN\User is our Experience Viewer, Guaranteed State Viewer, Inventory Viewer and Patch Success Viewer. This user can only view these applications.
  5. Launch the Experience Application
  6. Launch the Guaranteed State Application
  7. Launch the Inventory Application
  8. Launch the Patch Success Application
  9. At this point you may see an error fetching data or no data for any of these applications, we will revisit later, but this is to give a feel for each application
  10. Explore the nodes to get a feel for the applications

View as Global Administrator


  1. Log onto 1ETRNW102 as 1ETRN\Tachyon_AdminPP
  2. Launch Google Chrome and navigate to https://tachyon.1etrn.local/tachyon
  3. Launch the Settings Application
  4. Notice the increased number of nodes. 1ETRN\Tachyon_AdminPP is our Global Administrator and has access to all of Tachyon
  5. Navigate to Configuration – License Information
  6. Review the License properties for our lab
  7. Later in the labs when we create our own instructions, we will review the properties of our license and how that applies to creating Instructions
  8. Navigate to the other nodes and Applications to review the options
  9. Stay logged into 1ETRNW102. We will be revisiting the machine once we start using Tachyon

Lab Summary

In this lab, we explored the Tachyon Portal and the different applications under different user contexts. We validated the role-based security we applied on different users and groups. Finally, we navigated into the different nodes within the applications to get a feel for the product.

Next Page
Ex 4 - TCN Opr v5.0 - Instruction Sets and Management Groups