Be able to run predefined scripts, but not connect to a host
1 vote
We would like the feature to be able to run a set of scripts (via the gateway) without a temporary access request. They should be able to always run these scripts, but only be able to connect to them via a temp access request.
This ensures that pre-made scripts for common problems and diagnostics can be performed. Access needs to be requests for more advanced problems/
Hello,
Just to confirm with you, what type of entries are you using? I'm assuming it's a Powershell macro entry that you're running against something like an RDP, is this correct?
Does this setup work well for you, and the main issue here is that you'd like the script not to require the temporary access, but the remote connection (RDP for example), to require this access?
Regards,
Hubert Mireault
Hi! We are using RDP entries and powershell macro entities indeed. We have it set up the following way:
Admins have the right to grant temp access when a temp access request is made by a user. However most of the things users need to perform on the servers are a set of really simple tasks, like restarting a windows service. We want those users to always be able to use these ‘pre-defined’ set of scripts (made by admins) and let hem perform them whenever they want. Mostly for the calamities at night, when there isn’t always a admin awake. They need to be called and woken up to just give access to restart a simple service.
So in short: A couple of scripts that the admins create, need to be run by users without the rights to start a RDP session.
however (and I made a seperate request for this: https://forum.devolutions.net/topics/52212/run-powershell-scripts-through-the-gateway#224150) in our situation, the gateway should perform the script on the servers, not the users computer. But this would still be a amazing feature for tasks that needs to be performed more often.
Thank you for the details, this makes sense and helps clarify what your needs are. As I mentioned in the other thread, we have some ideas of ways we could allow this kind of workflow, to execute scripts without necessarily allowing RDP access, and all that through the Gateway.
I've added this information to our internal ticket.
Regards,
Hubert Mireault