Find PAM accounts by name

Find PAM accounts by name

1 vote

avatar

Hi, I have idea similar to this in request Find by name in the PAM vault. There is a credential type "Devolutions Server privileged account", if it could serach entries by name like credential type "Devolutions Server", it would improve linking PAM Accounts with sessions.
Also a credential "Devolutions Server" could find "Devolutions Server privileged account" credential entries but currently it filter them out.
Regards
Mateusz

All Comments (3)

avatar

Hello Mateusz,

Thank you for the request. We discussed this internally and I had a question for you to make sure we properly understand your request.
We see two different goals we could accomplish, and I would like to understand which of them you mean.

  1. Improve the flow so that users who have 'personal' privileged accounts can use them with a simplified configuration.
    1. Let's say I have a privileged account "hmireault-admin" and my colleague has one called "fdubois-admin". Currently, if you have an RDP in a shared vault where you want your users to use their specific privileged accounts, the setup can be complex. You would need to configure the RDP entry with either "My privileged account" or "Find by name (user vault)", and the latter would need the users to create a "Devolutions Server privileged account" entry in their user vault with the correct name.
  2. Improve the flow when you want to prompt a restricted list of privileged accounts based on a name.
    1. Let's say your PAM accounts have a naming scheme where their names are prefixed with a certain value according to the domain they should be used on. If you have PAM accounts with a prefix of "Contoso" and some with "Fabrikam" and an RDP that should use only the credentials from one of those domains, you could specify the string "Contoso" to only list these PAM accounts.


Both of these goals we are interested in achieving, but I want to know which of the two you're talking about so we can see about prioritizing that.

Let me know if I wasn't clear in my explanation or if I missed the mark with what I think you're trying to accomplish.

Regards,

Hubert Mireault

avatar

Hello,

At the beginning I was thinking about second case. Let's say there is vault with PAM Credentials with names in some convection. That naming convention could be used to finding them using variables, rather than manually linking. As I said it would be very similar to finding normal credential by "Devolution Server" credential entry:


But first case is also familiar for us. We currently using "Find by name (user vault)" but only for personal accounts, for shared accounts name convection and lookup is needed, but not possible for PAM Accounts yet.

Regards
Mateusz

a05c1ed6-3912-4ad8-9522-b412c65817ef.png

avatar

Thank you for the confirmation. We have noted this and we will discuss internally to see what we can do to improve these workflows.

Regards,

Hubert Mireault