0 vote
Consider expanding the PAM features to allow the management of groups and group membership. Since most of the connections are already in the PAM features, this would be a great consolidation of managing user access to accounts and via group membership. This would enable a group admin to add groups and group owners,enable workflow to approve group membership changes, and allow any SSO authenticated user to request group membership.
Hello,
Thank you for your suggestion. It is always welcome to receive feature request about our PAM. I have a few questions to help us understanding your request.
First, we already have an Active Directory Dashboard in RDM allowing users to manage their Active Directory. We are working to integrate that tool to our web interface. Would it help to see that tool available directly on the Active Directory Provider ? Is it what you would like ? And I understand that it could be useful for you to have a similar dashboard for Azure, am I right ?
We also support Just In Time (JIT) elevation for AD and AzureAD (new in 2023.3). It allows your user to request group membership at the checkout phase. Once it is approved, the user will be added to the group and will get permission from that group. Does it fill your need to allow a user to request group membership ?
You also talked about workflow to approve group membership changes. What do you mean by that ? Would it be useful to request permanent group membership throught DVLS instead of adding group membership for a user in Active Directory/AzureAD ? Am I understanding correctly ?
Don't hesitate to explain us what you are trying to achieve, it always help us to understand differents flows used by customers.
Best regards,
François Dubois