Privileged account

Privileged account Privileged account

All threads (1)
avatar

jm2

Backlog Privileged account

WebUI unable to launch sessions using 'find by name (uservault)' that resolves to a PAM credential

Hello, In environments where an administrator has multiple privileged accounts, it is often necessary to set the credential attribute of an entry in a shared vault to 'find by name (uservault)'. For example, to search for 'My Domain1 Admin' or 'My Domain2 admin'. When these user vault entries are of type 'Devolutions Server Privileged Account' which link to a PAM credential, attempting to launch connections using WebUI that utilize these credentials fail with an error suggesting its unsupported. However, when a session is explicitly configured to use a specific PAM account it works, as does when the credential discovered by 'find by name' is not a PAM credential. It seems that WebUI does indeed support using both PAM credentials and 'find by name (uservault)' when used independently, but not when chained together. Tested with DVLS 2025.2.10. Behavior is similar with Hub Business, although error message is different. Additionally, chained PAM type credential entries cannot be created or edited in WebUI, even though 'Privileged Account' is a supported credential type for other session type entries (i.e. RDP). Please let me know if you would like any additional info. Thanks Joe [image] [image]

1

118

5

avatar

Marc-Antoine Dubois

1 - 1 of 1 items