Share credential with less priviliged user within RDM for a limited amount of time
0 vote
We've implemented a complete RBAC model in our RDM. Our users are authorised to access only the credentials that belong to their role of function.
However there are always exceptions. When a first line engineer needs access to a credential he normally should not be able to access. Of course we could make a change in the permissions but the people managing the permissions are not the same as the persons that have access to the required credentials.
What happens now is that 2nd line colleagues share these credentials outside of RDM, causing a risk of storing a credential in another system and not being able to audit the use of that specific credential from within RDM.
What I would like is the option to temporary share a credential entry with a less priviliged user for a certain periode of time. The audit logs should register the fact that the credential was shared.
This could perhaps be a permission you could assign to users to be able to share items.
Hello,
What type of data source are you currently using?
Best regards,
Jeff Dagenais
We're using DPS as the data source for our RDM environment (which is using Microsoft SQL)
Hello,
In a near future, it would be possible via DPS, using the PAM functionality, to generate a temporary password valid for a certain period of time.
However, I cannot provide you an exact date for it's delivery, but you can always follow our release notes
https://server.devolutions.net/release-notes
Best regards,
Jeff Dagenais
Hi Jeff.
thanks for your response
I hope the new PAM functionality you described meets our requirements! I will keep a close look on the release-notes.
I noticed there is already some recent documentation on the PAM functionality in the online help, is there some further clarification available what the PAM functionality offers exactly?
best regards
Hello,
I think this blog will answer your questions
https://blog.devolutions.net/2019/05/update-devolutions-pam-platform-for-smbs
Best regards,
Jeff Dagenais