Hi Devolutions,
is it possible to create an administrator account for configuration of the whole DPS, but without the possibility to view any passwords?
We have many departments with vaults in DPS and for sure they dont want that an administrator can view all finance passwords for example.
We already created a role which has the right to manage users and roles and so on, which can be set under system permissions.
But this account cant manage two factor authentication or the rest of the DPS.
So, is there a way to implement such an account?
Thanks and regards,
Ingo
This is not possible for now but it's an interesting features. Could you give me more details about manage 2FA?
Regards
David Hervieux
Hi,
its not only manager 2FA, its the whole DPS configuration.
For example, we can enable some users or roles withinh the system permission to change system settings.
But we cant access the passwordserver settings. So we would need an account with full permission to change settings and configuration, but not able to see any passwords.
Greetings,
Ingo
Ok, Maybe we should just be able to restrict the View password for some Administrator. What do you think?
David Hervieux
Hi,
this would be fine. But the Admin should not be able to change this setting.
Is this possible with the actual DPS Version?
Greetings,
Ingo
Of course He should not be able to change it. Unfortunately it's not possible but I was asking the question simply because I think it would be easier to implement. I will add this to our todo list.
Regards
David Hervieux
Sound great, that solution would be fine.
How long is your todo list and is there a way to speed up this topic?
Regards,
Ingo
I can tell you exactly when this will be implemented for now. We have just released our 2020.1 version and we expect the next major update just before the summer.
Regards
David Hervieux
Hi,
something new on this topic?
Thanks and regards,
Ingo
Hi,
would like to reactivate this feature request.
Could you please add an administrator role, who can configure the whole DVLS instance, but without password view permissions?
Regards,
Ingo
Hello Ingo,
Thank you for your interest. The way our security is structured currently does not allow us to easily create a read-only administrator user. However, I would like to improve or change our security system to be based on roles. This is a significant project that could take a long time. We will keep you updated here once we have something, but unfortunately, we cannot expect a short-term solution.
Do not hesitate if you have any questions.
Best regards,
François Dubois