- スタート アップ ガイド
- ベスト プラクティス
- テナント
- テナント コンテキストについて
- ロボットを管理する
- Robot を Orchestrator に接続する
- セットアップのサンプル
- CyberArk へ Robot 認証情報を保存する
- 監査
- アクション
- フォルダー コンテキスト
- 自動化
- プロセス
- ジョブ
- トリガー
- ログ
- 監視
- キュー
- アセット
- ストレージ バケット
- Orchestrator のテスト
- アクション カタログ
- プロファイル
- システム管理者
- Identity Server
- 認証
- その他の構成
- Integrations
- クラシック ロボット
- トラブルシューティング
このページでは、Orchestrator で設定されているロボット認証メカニズムに応じて、Robot を Orchestrator に接続する方法を選ぶ方法について概説します。UiPath では、期限が切れるトークン認証から無期限のトークンを使用する認証まで、多数のロボット認証方法が用意されています。
使用できる 3 つの認証メカニズムは、[設定] ページ > [セキュリティ] タブにある 2 つの Orchestrator テナント設定をどのように指定するかによって決定されます。
ロボット認証の種類
標準認証
[設定] ページ > [セキュリティ] タブで両方の認証オプションをクリアして、無期限の認証トークンを使用する接続のみを許可します。
- Allow both user authentication and robot key authentication - not selected
- Enforce user authentication, disable robot key authentication - not selected
| 入力 | 影響 |
|---|---|
| Attended | Assistant での Attended ロボットの認証を、マシン キーだけに制限します。Assistant に [サインイン] オプションは表示されないため、ユーザーは資格情報を使用して Studio と Assistant を Orchestrator に接続できません。 |
| Unattended | Unattended ロボットには常に、マシン キー接続が必要です。 |
ハイブリッド認証
[ユーザー認証とロボット キー認証の両方を許可] を有効化して、[ユーザー認証を強制し、ロボット キー認証を無効化] をクリアすることで、期限が切れないトークンを使用する標準接続と期限が切れるトークンを使用する接続の両方を許可します。
- Allow both user authentication and robot key authentication not selected
- Enforce user authentication, disable robot key authentication selected
| 入力 | 影響 |
|---|---|
| Attended | 対話型サインインを使用して、Attended ロボットを認証できます。Assistant に [サインイン] オプションが表示され、ユーザーは資格情報を使用して Studio と Assistant を Orchestrator に接続できます。 |
| Unattended | Unattended ロボットには常に、マシン キー接続が必要です。 |
セキュリティで保護された認証
[設定] ページ > [セキュリティ] タブで両方の認証オプションを有効化して、期限が切れるトークンを使用する接続のみを許可します。Orchestrator への HTTP 要求を作成したり、Attended ロボットを実行したり、Assistant でプロセスを表示したりするには、ユーザー ログインが必要です。
- Allow both user authentication and robot key authentication selected
- Enforce user authentication, disable robot key authentication selected
| 入力 | 影響 |
|---|---|
| Attended | Assistant での Attended ロボットの認証を、対話型サインインだけに制限します。 Attended ロボット認証にはサインインが必要です。サインインしないと、Assistant 内に関連するプロセスが表示されず、ロボットは「接続済み、ライセンスなし」として表示されます。 |
| Unattended | Unattended ロボットには常に、マシン キー接続が必要です。 |
| 有人モードでの Unattended | Unattended の場合、ホスト マシンは有人モードで接続され、ライセンスされるため、プロセス実行の規定の方法は Orchestrator になります。 マシンを有人モードで (Assistant を開いて) 使用する場合、ユーザー認証が強制されているとサインインが必要です。そうしないと、Assistant でプロセスが表示されず、ロボットは「接続済み、ライセンスなし」として表示されます。 |
この認証方法では、Orchestrator アクティビティを使用したり、Orchestrator API への直接 HTTP 呼び出しを行ったりするワークフローは、v2020.10 以降のアクティビティ パッケージを使用して再コンパイルする必要があります。
オートメーション プロジェクトで以下の依存関係の 1 つ以上が使用されている場合、ジョブの実行が失敗する可能性があります。
- UiPath.System.Activities < 20.10.0
- UiPath.Persistence.Activities < 1.1.7
- UiPath.DataService.Activities < 20.10.0
- UiPath.Testing.Activities < 1.2.0
プロセスの依存関係を上記で指定されたバージョン以上のバージョンに更新するには、Studio のプロジェクト依存関係一括更新ツールを使用します。本番環境にデプロイする前にテストします。
Attended ロボットを Orchestrator に接続する
対話型サインイン
対話型サインインを使用して、Attended ロボットを認証します。Assistant に [サインイン] オプションが表示され、ユーザーは資格情報を使用して Studio と Assistant を Orchestrator に接続できます。以下に対応しています。
- ハイブリッド認証
- セキュリティで保護された認証
-
Assistant を開きます。
-
[設定] メニューで、[サインイン] を選択します。Orchestrator インスタンスの [ログイン] ページに移動します。
-
通常どおりにログインします。
-
Once your identity is confirmed, the Assistant is populated with the processes in the folders your user has access to. Learn more about interactive authentication.
注:When using interactive sing-in, there is no need to create Machine objects in Orchestrator.
重要:対話型サインインは、クラシック フォルダーのコンテキストではサポートされません。
Assistant でマシン キーを使用する
Orchestrator で生成されたマシン キーを使用して、Attended ロボットを認証します。以下に対応しています。
-
標準認証
-
ハイブリッド認証
注:- 社内で Orchestrator の設定を担当する人は、Attended User と開発者に正しい Orchestrator URL とマシン キーを提供する必要があります。マシン オブジェクトを Orchestrator のフォルダーに割り当てる必要はありません。ユーザーのみに割り当てます。
- 複数のユーザーが同一マシン上で作業している場合、それぞれに Orchestrator で作成されたロボットが必要です。
-
Assistant を開きます。
-
[設定] メニューで、[設定] を選択します。[設定] ウィンドウが表示されます。
-
[Orchestrator の設定] に移動します。
-
[Orchestrator URL] フィールドに、Orchestrator の Web アドレスを入力します。例:
https://myOrchestrator.uipath.com/. -
[マシン キー] フィールドに、Orchestrator 内のマシン エンティティによって生成されたキーを入力します。
Learn about the various machine entities in Orchestrator and when to use each.
-
[接続] をクリックします。これで、Robot が Orchestrator に接続されます。
注:「高密度ロボット」機能は、ユーザーごとにロボットを登録する際に、同じマシン名とマシン キーが使用されている場合にのみ有効です。
コマンド ラインでマシンキーを使用する
- Orchestrator で生成されたマシン キーをクリップボードまたはファイルに保存します。
- コマンド プロンプトを開きます。
- UiPath Robot がインストールされているディレクトリに移動します (既定では
C:\Program Files\UiPath\Studio)。例:cd C:\Program Files\UiPath\Studio。 - コマンド ライン引数
--connect、-url、および-keyを Orchestrator URL およびマシン キーと組み合わせて使用します。例:UiRobot.exe --connect -url https://demo.uipath.com/ -key ba1e4809-2f64-4965-bae2-efda62d20164これで、UiPath Robot が Orchestrator に接続されます。高密度ロボット グループの場合は、各ユーザーに対応するロボットが Orchestrator に接続されます。
Unattended ロボットを Orchestrator に接続する
Assistant でマシン キーを使用する
Orchestrator で生成されたマシン キーを使用して、Unattended ロボットを認証します。無人実行には常に、マシン キー接続が必要です。以下に対応しています。
-
標準認証
-
ハイブリッド認証
-
セキュリティで保護された認証
注:この手順をサービス モードの Robot に実行するには管理者権限が必要です。
Orchestrator を使用して無人プロセスを実行できるように、ホスト マシンは無人モードで接続され、ライセンスされています。
マシンを有人モードで (Assistant を開いて) 使用する場合、ユーザー認証が強制されているとサインインが必要です。そうしないと、Assistant でプロセスが表示されず、ロボットは「接続済み、ライセンスなし」として表示されます。
-
Assistant を開きます。
-
[設定] メニューで、[設定] を選択します。[設定] ウィンドウが表示されます。
-
[Orchestrator の設定] に移動します。
-
[Orchestrator URL] フィールドに、Orchestrator の Web アドレスを入力します。例:
https://myOrchestrator.domain.local/. -
In the Machine Key field, enter the key generated by the machine entity in Orchestrator. Learn about the various machine entities in Orchestrator and when to use each.
-
[接続] をクリックします。これで、UiPath Robot が Orchestrator に接続されます。
注:- マシン オブジェクトを Orchestrator のフォルダーに割り当てる必要があります。
- 「高密度ロボット」機能は、ユーザーごとにロボットを登録する際に、同じマシン名とマシン キーが使用されている場合にのみ有効です。
コマンド ラインでマシンキーを使用する
- Orchestrator で生成されたマシン キーをクリップボードまたはファイルに保存します。
- コマンド プロンプトを開きます。
- UiPath Robot がインストールされているディレクトリに移動します (既定では
C:\Program Files\UiPath\Studio)。例:cd C:\Program Files\UiPath\Studio。 - コマンド ライン引数
--connect、-url、および-keyを Orchestrator URL およびマシン キーと組み合わせて使用します。例:UiRobot.exe --connect -url https://demo.uipath.com/ -key ba1e4809-2f64-4965-bae2-efda62d20164これで、UiPath Robot が Orchestrator に接続されます。高密度ロボット グループの場合は、各ユーザーに対応するロボットが Orchestrator に接続されます。
自動登録
接続文字列を指定して、サービス ロボットを Orchestrator に自動的に登録します。
接続文字列は、次の情報を含む URL です。
-
Orchestrator URL - ロボットの接続先である Orchestrator インスタンスを特定します。
-
テナント ID - ロボットの接続先であるテナントを特定します。
-
domain name - identifies the domain of the machine; this is only necessary if the machine is in a different domain than that specified for the WindowsAuth.Domain parameter (this is valid for subdomain machines as well). The domain needs to be in a two-way trust relationship with the one set for the
WindowsAuth.Domainparameter.Click here for details about authorization parameters in UiPath.Orchestrator.dll.config.
マシンのドメインに応じて 2 つの接続文字列を例として示します。
-
UiPath.Orchestrator.dll.configで指定されたものと同じドメイン -https://demo.uipath.com/api/robotsservice/GetConnectionData?tenantId=1 -
UiPath.Orchestrator.dll.configで指定されたものとは異なるドメイン -https://demo.uipath.com/api/robotsservice/GetConnectionData?tenantId=1&domainName=domain_name注:接続文字列を使用してロボットを Orchestrator に接続するには、次の条件が必要です。
- the WindowsAuth.Enabled parameter has to be set to
true - the WindowsAuth.Domain parameter has to be set to a valid domain
- the Service Mode Robot has to be installed.
- the WindowsAuth.Enabled parameter has to be set to
-
In Orchestrator, navigate to Settings,General tab. (Tenant > Settings > General). Look for the Connection String field on the Application Settings section, and click Copy. The connection string is copied to the clipboard.
-
接続文字列を Orchestrator に接続するロボット端末に送信します (メールや USB スティックなどを使用)。
-
Use an automatic deployment tool to install the Robots and provide the connection string copied above in the CONNECTIONSTRING parameter used with the
UiPathStudio.msiinstaller. UiPath Robot is connected to Orchestrator and is displayed as Available in the Robots page.注:Connecting Robots to Orchestrator using the
--connectionstringparameter is only possible when Standard Machines are used. Environments with Machine Templates do not support this.