Time restrictions control when the entitlement is in effect relative to the user's time zone. For more information, see About time restrictions.
On the Time Restrictions tab, specify the time restriction properties for the entitlement.
Navigation: Administrative Tools | Entitlements| (add or edit entitlement)
Property | Description |
---|---|
Use Time Restrictions |
Select this option to enforce time restrictions. |
Daily calendar |
Select and drag the hours you want to allow. |
Have the Entitlement Expire on Date and Time |
Select this option to enforce an expiration date, then enter the date and time. When an entitlement expires, all the access request policies associated with the entitlement also expire. To set an expiration date on a policy, see Creating an access request policy. |
An entitlement's time restrictions enforce when Safeguard for Privileged Passwords uses a policy; a policy's time restrictions enforce when a user can access the account passwords. If the entitlement and the policy both have time restrictions, the user can only check out the password for the overlapping time frame.
Time restrictions control when the entitlement or policy is in effect relative to a user's time zone. Although Safeguard for Privileged Passwords Appliances run on Coordinated Universal Time (UTC), the user's time zone enforces the time restrictions set in the entitlement or policy. This means that if the appliance and the user are in different time zones, Safeguard for Privileged Passwords enforces the policy in the user's time zone set in his account profile.
It is the responsibility of the Security Policy Administrator to define access request policies in Safeguard for Privileged Passwords.
To add an access request policy to an entitlement
Where you add general information about the access request policy as well as specify the type of access being requested. | |
Where you assign assets, asset groups, accounts, or account groups to an access request policy. | |
Where you configure the access request policy requester settings. | |
Where you configure the access request policy approver settings. | |
Where you configure the access request policy reviewer settings. | |
Where you define the access settings for the selected type of request including allowing users to request passwords from their respective linked accounts. | |
Where you configure the recording settings for session access requests. | |
Where you indicate policy time restrictions. | |
Where you enable emergency access for the accounts governed by the access request policy. |
Deleting an access request policy
Modifying an access request policy
Copying an access request policy
On the General tab, enter the following information for the access request policy.
Navigate to Administrative Tools | Entitlements | Access Request Policies | (create or edit a policy).
Property | Description | ||
---|---|---|---|
Name |
Enter a unique name for the access request policy. Limit: 50 characters Required | ||
Description |
Enter descriptive text that explains the access request policy. Limit: 255 characters | ||
Priority |
The priority of this policy compared to other policies in this entitlement. If a user desires to access an account in the scope of two different request polices within an entitlement, then the policy with the highest priority (that is, the lowest number) takes precedence. For more information, see About priority precedence. | ||
Access Type |
Specify the type of access being requested:
| ||
Have the Policy Expire on Date and Time | If applicable, select this check box to enforce an expiration date for the policy. Enter the expiration date and time. |
© 2021 One Identity LLC. ALL RIGHTS RESERVED. Feedback Terms of Use Privacy