It's been too long since I've done this to remember the specific steps, but here is the one step that most people forget but is the most critical:
Set a Master Password for each CF application. You'll find all this in the security section of the documentation. This way, if it stops working, you can still get into applications to correct any issues.
Also, little known hint: if you only use CF thick clients (not CF web/network stuff), you can use an Access Manager LAE file as the security provider inside Access Manager. I've had a client or two run that way for years. It was never officially supported by Cognos et al, but it worked fine (you just need to be good about taking backups). If I remember correctly, it even worked with OS authentication instead of basic.