Unable to add Hub Privileged account entry using RDM

Unable to add Hub Privileged account entry using RDM

avatar

Hello,

When attempting to add an entry of type 'Devolutions Hub Privileged account', RDM responds with an access denied message when attempting to select the Vault. It also prompts for reauthentication beforehand, even though this already occurred when opening the data source. The respective user has necessary permissions to PAM vaults, and they can be accessed directly using RDM or WebUI.

This is a blocker for environments where multiple administrator have multiple privileged accounts, and the credential attribute of entries in shared vaults is set to 'find by name (uservault)'. For example, to search for 'My Domain1 Admin' or 'My Domain2 admin' which link to personal PAM accounts in Hub.

Please let me know if you would like any additional info.

Thanks
Joe



1043ceba-17e5-45d4-bc3f-f441d7b4d37f.png

All Comments (2)

avatar

Hi Joe,

Thank you for reaching to our forum.I tested this on my side using RDM 2026.1.22 with Devolutions Hub Business. I created a Hub Privileged Account entry from my Personal Vault, following the same workflow you described, and it worked as expected.
I tested both scenarios:

  • with Use my account settings enabled;
  • with Use my account settings disabled and the account selected manually.

In both cases, I was able to find the PAM vaults and select the privileged account.

That said, I did run into a similar behavior once, but after re-authenticating, I was not able to reproduce it again. This may indicate a local cache/session/authentication state issue rather than a permanent permission issue.

Could you please try the following?

1- Update RDM to the latest version
Please confirm which RDM version you are currently using and update to the latest available build if you are not already on it.

2- Reset the RDM cache
In RDM, try resetting the local cache, Ctrl + F5 then restart RDM and authenticate again to your Hub Business datasource.

3- Re-authenticate to Hub Business
Sign out/sign back in to the Hub datasource, then try creating the Hub Privileged Account entry again.

4- Test with temporary administrator permissions
As a validation test, temporarily grant administrator rights to the affected user/test account, then retry the same operation.
If it works as administrator, we can narrow it down to permissions.
If it still fails as administrator, it is more likely related to cache, authentication, datasource context, or the RDM version/build.

5- Validate the Hub host when not using “Use my account settings”
If you disable Use my account settings and manually enter/select the user, make sure the correct Host is selected, especially if you have access to multiple Hub Business instances. Selecting the wrong Hub host can prevent RDM from finding the expected PAM vaults/accounts.

6- Try configuring it through My Account Settings
Please also try this path:
File > My Account Settings > My Privileged Account
Select the privileged account there, then retry the entry configuration. This should achieve a similar result to using Find by name, but through the account settings flow.

Please let us know:

  • your exact RDM version;
  • whether resetting the cache and re-authenticating changes the behavior;
  • whether the issue still happens after updating RDM;
  • whether the test works when the user is temporarily granted administrator rights;
  • whether you have multiple Hub Business accounts/hosts available in RDM.

This will help us determine if the issue is permission-related, caused by the selected Hub host/context, or due to a stale local cache/session state.

Best regards,

Michel Audi

avatar

Hi Michel,

Thanks for looking into this. Re the info requested:

  • Using RDM 2026.1.22.
  • Resetting cache didn't alter behavior
  • Elevating user to administrator didn't alter behavior
  • Using or not using 'my account settings' didn't alter behavior
  • Yes RDM has multiple Hubs configured


The issue may be limited to when authenticating via SSO (EntraID), as I was able to get it to work when using a 'Devolutions' credential, however there was still a secondary authentication prompt when clicking the 'vault' button, which shouldn't be necessary since authentication had already occurred previously when opening the data source.

Please let me know if you would like any additional info.

Joe