Open multiple Sessions with Same PAM Account

Open multiple Sessions with Same PAM Account

0 vote

avatar

We leverage "My Account Settings --> My Privileged Account" feature with "Always Prompt" enabled since we use daily different Tier'd accounts for access to Servers vs Desktops. Is there and if not add a way to open many sessions with the same PAM credential and not be prompted repeatedly for a credential. I tried using "Playlists" but it prompts for each entry. It could be something as simple as a checkbox "Use this account for multiple connections" We have Admins that open many sessions to do complete tasks like manual patching

79e4336d-28fc-4d04-b08a-5840f560de25

79e4336d-28fc-4d04-b08a-5840f560de25.png

All Comments (7)

avatar

Hello,

Thank you for your request. I'm not sure to understand completely your request. My question would be the following: If you use it with "Always prompt", how would you expect the system to know if it is time to prompt again or reuse an account ? I understand your suggestion to have a check box "Use this account for multiple connections", but after a few connections, I guess you expect to be prompted to use another one ? I'm not sure how the flow would work in a such situation. Could you explain a bit more ? Thanks in advance

Best regards,

François Dubois

avatar

We have many different accounts for many different zones that we are prompting, hence our need for the pictured accounts above. However, we also open many sessions with teh same account. If I try to open 5 sessions I am prompted for the the account to use each time.

avatar

Hello,

Thank you for your answer. If I understand correctly, in your example where you open 5 sessions, you would like to reuse the same account for the 5 sessions since you open them in a short period of time. If you want to open another session a few minutes later, you would expect to get prompted again, am I right ?

Best regards,

François Dubois

avatar

Yes, in my case, much like my compatriots, open many servers for daily work, maintenance etc. We we do so we would like to have the ability to use the same account during that operation once. Hence my screen shot as an example to open all with that one credential.

79e4336d-28fc-4d04-b08a-5840f560de25

avatar

Hello,

My colleague François moved your thread to the RDM feature request forum as this is more of a feature for RDM itself rather than Devolutions Server.

For your request itself, adding a checkbox there might be complicated due to the way RDM is designed. It's not impossible, but I would like to suggest a different solution and see if it would work for you, as it would be simpler for us to implement and give you a way to improve your workflow more quickly.

What we could do is add a new button here, called something like "Open (select privileged account)":


So the workflow would be:

  • Select your entries in the navigation pane
  • Right click > Open with parameters > Open (select privileged account)
  • From there, choose your privileged account, and RDM would open the selection by using this specific privileged account and would not prompt multiple times


Do you think this would work for you, or would it not cover your main scenarios?

Regards,

Hubert Mireault

da1758b2-90f5-4f35-a09e-bb58b563fcfc.png

avatar

Tried it and it does not use the same account in succession, it still prompts each time. As stated originally in my request:

"We leverage "My Account Settings --> My Privileged Account" feature with "Always Prompt" enabled since we use daily different Tier'd accounts for access to Servers vs Desktop"

avatar

Hello,

Sorry, maybe my explanation was confusing. The feature I'm speaking of doesn't exist yet. I did not mean the existing "Open using my privileged account", but a new button that would force using the "privileged account" feature to prompt you. Similar to when you configure an entry this way:


The feature I'm imagining would for the selection of entries to be opened using a PAM account, whether the entry was configured this way or not.

One thing to confirm though, are you connected to the same Devolutions Server datasource as the one you are fetching the PAM accounts from? If you are on a different datasource, then the solution I'm suggesting wouldn't work.

Let me know if there's something I misunderstand in your scenario.

Regards,

Hubert Mireault

88ba86e8-7ce2-4073-901c-da5ada9c865d.png