DPS | PAM - Delegating approvers for non admin's

DPS | PAM - Delegating approvers for non admin's

avatar
pandagong
Disabled

Hello,

I'm new to devolutions products and have labbed up DPS to test as a potential PAM solution which seems to be going quite well.
But I seem to be struggling a bit regarding delgation of who can approve check out requests.

I've gone through the console options and your online articles but cannot find anything that goes into detail on this topic.
It is very possible that may have missed something and if there are articles that would help clarify my query I will be very happy to read through if you point me in the right direction.

But going back to my reason for wanting to delegate out who can approve check outs.
My team is ultimatly responsible idenity management but as this solution would used cross teams i.e network, desktop, apps, ect I woud prefer it that these tasks are delegated to specific trained individuals in the respective teams.

I guess my question is if approvers have to be administrators in DPS?

Kind regards
Panda

All Comments (5)

avatar

Hello,

Indeed approvers need to be administrators in Devolutions Password Server. We will update our online documentation to add that information.
https://helpserver.devolutions.net/pam_checkoutprocess.html

Best regards,

Érica Poirier

avatar

but... we are reworking the whole permission system to introduce built-in roles (kind of like in azure...)

Definitely you will be able to choose any user for approver at a "team folder" level. We also have unique permissions for "log reviewers" (our own infosec team needs this...) and many more.

We are releasing version 2020.1.10 this tuesday, which should be our final build. We have already started work on version 2020.2 which should have all that you need.

I would be happy to jump on a call with you to discuss what we are working on, I would love your input.

Best regards,

Maurice

avatar

Thank you both,

Thank you for the offer of the call Maurice that maybe quite helpful, and from your message above, just to clarify when you say:

Definitely you will be able to choose any user for approver at a "team folder" level. We also have unique permissions for "log reviewers" (our own infosec team needs this...) and many more.


So the new version coming tomorrow should allow me to deletgate out permisions at the folder level?
If so that is pretty much the level of functionality we need for me to drive this forward.

I'll be working most of the day tomorrow but will look forward to upgrading the software in the lab to test functionality.

Kind regards
Panda

avatar

Hi,

The version that comes out today allows still only admins.

The new role system is for 2020.2, planned for June. I would hope we could have a beta cycle starting in May for you to test it out.

Thanks

Maurice

avatar
Hi,

The version that comes out today allows still only admins.

The new role system is for 2020.2, planned for June. I would hope we could have a beta cycle starting in May for you to test it out.

Thanks


thank you,will look forward to it