The actions a user authorized to request access to a privileged session can take depends on the state of the request and the client interface you are using.
(web client) To take action on a session request
- From the web client, click My Requests.
- Search to find what you need. For more information, see Search box.
- Click Filters to filter by the status.
- All: Requests in all states.
- Available: Approved requests that are ready (that is, a session that can be launched).
- Pending Approval: Requests that are waiting for approval.
- Approved: Requests that have been approved, but the check out time has not arrived.
- Revoked: Approved requests retracted by the approver.
- The approver can revoke a request after it is available.
-
When a user with Security Policy Administrator permissions revokes a live session, the active session is terminated.
- Expired: Requests for which the Checkout Duration has elapsed.
- Denied: Requests denied by the approver.
- Click or to see more or less information on the request.
- You can take the following actions on session requests, depending on the state.
- Available: If the password changes while you have it checked out, and your current request is still valid, select either Copy or Show again to obtain the new password, if enabled by your Administrator. Seconds Remaining shows you how long you have to copy information to use to log in.
- For SSH and RDP accounts:
- Click Launch to launch the SSH client or RDP connection. For more information, see Launching the SSH client or Launching an RDP session.
- Click Check-In to complete the check out process once you have ended your session.
-
In addition, you can use the following buttons to view or copy information into the dialog that contains the credentials needed to launch the session.
- Click Copy to check out and copy the credential.
- Click Show to check out the credential and view the credential.
- For telnet or TN3270/TN5250 over telnet accounts, the fields needed are based on the terminal service application in use:
- For a terminal service application that uses an inband connection string (like telnet), click Copy to copy the Hostname Connection string and check out the password. Then, paste the information in the log in screen.
- If the terminal service application requires more information for log in (for example, TN3270/TN5250 over telnet):
- Click Show to display values that may include Vault Address (the SPP address), a one-time Token, Username, Asset, and Sessions Module (the SPS address).
- Click Copy by any of the values to copy a single value. Or, you can click Copy at the right of all values to copy the entire the connection string, if that is required by your terminal service application.
- Paste the necessary information into your terminal service application.
- Click Check-In to complete the password check out process. This makes the session request available to reviewers.
- Click Hide to conceal the information from view.
- For SSH and RDP accounts:
- Approved: Select Cancel to remove the request. A session request changes from Approved to Available when the requested time is reached. It stays available until you either cancel the request or it reaches the end of the duration period.
- Pending: Click Cancel to remove the request.
-
Revoked:
- Expired: Click Remove to delete the request from the list.
-
Denied:
- Available: If the password changes while you have it checked out, and your current request is still valid, select either Copy or Show again to obtain the new password, if enabled by your Administrator. Seconds Remaining shows you how long you have to copy information to use to log in.
(desktop client) To take action on a session request
- From your Home page, use any of these controls on the Requests widget, as needed. You can enable or disable the Home page widgets in the Settings (desktop client) menu.
- Select (expand down) to open the list of active requests.
- Select Popout. You can then select and drag the pane to any location on the console and re-size the window to float the Requests pane.
-
Open the list of requests and select one of these view filters. The number indicates how many requests are in that state.
- All: Requests in all states
- Available: Approved requests that are ready (that is, a session that can be launched)
- Approved: Requests that have been approved, but the check out time has not arrived
- Pending Approval: Requests that are waiting for approval
- Revoked: Approved requests retracted by the approver
-
The approver can revoke a request between the time the requester launches the session and checks it back in.
-
When a user with Security Policy Administrator permissions revokes a live session, the active session is terminated.
-
- Expired: Requests for which the Checkout Duration has elapsed.
- Denied: Requests denied by the approver.
- Select an account to see the details of the session request.
-
You can take the following actions on session requests, depending on the state.
- Available: If the password changes while you have it checked out, and your current request is still valid, select either Copy or Show again to obtain the new password, if enabled by your Administrator. Seconds Remaining shows you how long you have to copy information to use to log in.
- For SSH and RDP accounts:
- Click Launch to launch the SSH client or RDP connection. For more information, see Launching the SSH client or Launching an RDP session.
- Click Check-In to complete the check outprocess once you have ended your session.
-
In addition, you can use the following buttons to view or copy information into the dialog that contains the credentials needed to launch the session.
- Click Copy to check out and copy the credential.
- Click Show to check out the credential and view the credential.
- Click Help to copy the value into the appropriate field of the configuration dialog.
- For telnet or TN3270/TN5250 over telnet accounts, the fields needed are based on the terminal service application in use:
- For a terminal service application that uses an inband connection string (like telnet), click Copy to copy the Hostname Connection string and check out the password. Then, paste the information in the log in screen.
- If the terminal service application requires more information for log in (for example, TN3270/TN5250 over telnet):
- Click Show to display values that may include Vault Address (the SPP address), a one-time Token, Username, Asset, and Sessions Module (the SPS address).
- Click Copy by any of the values to copy a single value. Or, you can click Copy at the right of all values to copy the entire the connection string, if that is required by your terminal service application.
- Paste the necessary information into your terminal service application.
- Click Check-In to complete the password check out process. This makes the session request available to reviewers.
- Click Hide to conceal the information from view.
- For SSH and RDP accounts:
-
Approved: Select Cancel to remove the request. A session request changes from Approved to Available when the requested time is reached. It stays available until you either cancel the request or it reaches the end of the duration period.
- Pending Approval: Click Cancel to remove the request.
-
Revoked:
- Expired: Click Remove to delete the request from the list.
-
Denied:
- Available: If the password changes while you have it checked out, and your current request is still valid, select either Copy or Show again to obtain the new password, if enabled by your Administrator. Seconds Remaining shows you how long you have to copy information to use to log in.