You can use the Privileged access requests service category to request privileged access to high-security systems (Privileged Account Management systems).
TIP: For more information on the topic of Privileged Account Management, see the One Identity Manager Administration Guide for Privileged Account Governance.
To request privileged access
-
In the menu bar, click Requests > New request.
-
On the New Request page, in the Service Categories pane, click the Privileged Access Requests service category.
-
Select how you want to access the system by selecting the check box next to the relevant option:
-
API key request: Request a temporarily valid API key.
-
File request: Request files for accounts.
-
Password release request: Request a temporary password.
-
Remote desktop application request: Request temporary access to a remote desktop application.
-
Remote desktop session request: Request temporary access through a remote desktop connection.
-
SSH key request: Request temporarily valid SSH key.
-
SSH session request: Request temporary access through an SSH session.
-
Telnet session requests: Request temporary access using a Telnet session.
-
-
Click Add to cart.
-
In the Request Details side panel, expand the selected product.
-
In the PAM user account drop-down, select the PAM user account that you want to use for PAM access.
-
Depending on the type of access you have selected, perform one of the following actions:
-
-
In the System to access field, click Select.
-
In the Edit Property side panel, select whether you want to request access for a PAM asset or a PAM directory.
-
Next to the corresponding PAM directory or PAM asset, click Select.
-
-
-
In the System to access drop-down, select the relevant PAM access.
-
-
-
Perform the following actions:
-
In the Account to access field, click Select.
-
In the Edit Property side panel, select whether you want to request access for a PAM asset account or a PAM directory account.
-
Next to the corresponding PAM asset account or PAM directory account, click Select.
-
-
(Optional) In the Comment field, enter a comment, for example, to justify why you are requesting this access.
-
In the Valid from field, specify the time from which you want the access to be valid or clear the check box so that access is valid from the time of this request.
-
In Checkout duration, enter the number of minutes for which the access is valid.
NOTE: This duration refers to your entry in the Valid from field. For example, if you have specified that the access is valid from 12 noon tomorrow and should be valid for 60 minutes, then the validity period will expire at 1 pm tomorrow.
-
Click Apply.
-
(Optional) Repeat the steps for all other users and access types.
-
Click Add to cart.
-
Click Go to cart.
TIP: You can also add more products to your shopping cart and configure various settings. For more information, see Managing products in the shopping cart.
-
On the Shopping Cart page, click Submit.
Once the request has been approved, a button will appear in the request details pane of the request history (see Displaying request history) that you can use to log in to the Privileged Account Management system to obtain the login credentials.