By requesting these standard products, access requests to privileged objects of a PAM system can be created. The products are multi-request resources
Products |
API key request: For requesting API keys for accounts in a PAM system. File request: For requesting files for accounts in a PAM system. Password release request: For requesting passwords for accounts in a PAM system. Remote desktop application request: For requesting remote desktop applications for assets in a PAM system. Remote Desktop session request: For requesting remote desktop sessions for assets in a PAM system. SSH key request: For requesting SSH keys for accounts in a PAM system. SSH session request: For requesting SSH sessions for assets in a PAM system. Telnet session request: For requesting Telnet sessions for assets in a PAM system. |
Service category: |
Privileged access requests |
Shelf | Identity & Access Lifecycle | Privileged access |
Approval procedures: |
PG - owners of the requested privileged access request |
Approval policies/approval workflows | Approval of privileged access requests |
The requester provides information about the required access request, such as the product and asset or account to be accessed, together with the time period for the access. The owner of the privileged object for which you are requesting access approves the order. In the PAM system, a corresponding access request is made.
In the request, it is noted whether it was possible to create the access request in the PAM system and whether the access request was approved in the PAM system. The status of an access request is checked at regular intervals in the PAM system by means of the Read status of privileged access requests schedule.
If the access request has been approved, the user can log on to the PAM system and retrieve the required password, or start the required session.
Prerequisites
-
The requester's PAM user account has the entitlement for requesting the access request.
-
In the access request policy, the One Identity Manager enabled option is activated. This allows you to request access requests for assets, asset accounts, directory accounts, asset groups, and account groups that are within the request access policy's scope.
-
An application role under Privileged Account Governance | Assets and account owners is assigned to the requestable assets, asset accounts, directory accounts, asset groups, and account groups as the owner.
-
Identities are assigned to the application roles.
-
The Read status of privileged access requests schedule is enabled. Adjust the schedule in the Designer if necessary.
- The URL of the PAM web application is entered on the appliance. In this way, the users can log in to the PAM System from the Web Portal and retrieve the password or start a session.
For more information about configuring the One Identity Manager IT Shop Administration Guide, see the IT Shop. For more information about requesting access requests in the Web Portal, see the One Identity Manager Web Portal User Guide.