Skip to main content

Example: Onboard accounts for a personal admin

Instead of requesters on a team being granted access to an onboarded account, account trustees can give a specific user exclusive access to the account, regardless of team. The user, referred to as the personal admin, would be able to check out an account without needing authorization. The access will also be automatically checked out (for 12 hours by default) at login.

Install the Scenario.pam_personal_admin component for this example.

Any managed systems onboarded before the scenario is installed will need to be manually binded to the PERSONAL_ADMIN_ACCOUNTS managed system policy. This example will onboard accounts from the Corporate AD target system.

  1. Log into Front-end as a superuser.

  2. From the main menu click Manage components > RefBuild.

  3. Select the checkbox for Scenario.pam_personal_admin_management.

  4. Click Install component(s).

    The panel on the right will indicate when the installation is complete.

  5. Configure the Corporate AD target system with the additional step of selecting Automatically create a Privileged Access Manager managed system.

  6. Click Privileged access > Managed system policies.

  7. Select the PERSONAL_ADMIN_ACCOUNTS managed system policy.

  8. Click the Member systems tab.

  9. Click Add new… .

  10. Select the Corporate AD managed system and click Select.

  11. Log into Front-end (PSF) as the account trustee for the corporate AD team.

  12. Click Manage Resources.

  13. Click Account: Onboard.

  14. Select an account to be managed by the corporate AD team.

    Click Next .

  15. Select the Personal administrator access policy as the Managed SystemPolicy ID.

  16. Select disclosure options, as needed.

    Click Next .

  17. Select a user to be the privileged access owner (the personal admin)

  18. Click Next .

  19. Select session monitoring options, if desired.

  20. Click Next .

  21. Enable Allow override and randomization of password , if desired.

  22. Click Submit.

    Once the request has been approved, the personal admin will have instant access to the onboarded account the next time they log in.