■ | Log on to a remote machine through a PSM connection from the Account Details page or from the Versions tab by clicking the Connect button. |
| To log onto remote machines through a non-PSM connection, users require the ‘Retrieve accounts authorization as well. |
Retrieve accounts
Retrieve and view accounts in the Safe. Users who have this authorization can do the following:
■ | View the account in the Account Details page and the Versions tab by clicking the Show button in the account content panel. If the platform attached to the account doesn’t permit users to view the account, the user requires the ‘Manage Safe’ authorization. |
■ | Copy the account in the Account Details page by clicking the Copy button. If the platform attached to the account doesn’t permit users to view the account, the user requires the ‘Manage Safe’ authorization. |
■ | Display the account in the Accounts list by clicking the Show/Copy password icons. If the platform attached to the account doesn’t permit users to view the account, the user requires the ‘Manage Safe’ authorization. |
■ | Log on to a remote machine through the PVWA. Platforms can be configured not to display the account value to end users, but only allow the connection. |
■ | Save files by clicking the Save As button in the Files List, File Details and File Versions pages. |
■ | Open files that are stored in the Vault through the Files List, File Details and File Versions pages. |
List accounts
View Account lists. Users who have this authorization can do the following:
■ | View the Accounts or Files list. |
These permissions enable users to perform account management tasks, including the following tasks:
Permission | Enables Safe Members to … | ||||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|---|
Add accounts | Add accounts in the Safe. Users who are given this authorization in PVWA automatically receive Update account properties as well.
| ||||||||||||
Update account content | Change account values as well as the contents of files. Users who have this authorization can do the following:
| ||||||||||||
Update account properties | Update existing account properties. This does not include adding new accounts or updating account values. Users who have this authorization can do the following:
| ||||||||||||
Initiate CPM account management operations | Initiate account management operations through the CPM, such as changing, verifying, and reconciling account values. Users who have this authorization can initiate CPM account management operations in the Accounts List and the Search results page, as well as the Account Details page by clicking Change, Verify, or Reconcile on the toolbar. In the Change Password window, the ‘Manually selected password’ option will be enabled if the user has the ‘Specify next account content’ authorization. | ||||||||||||
Specify next account content | Specify the content that will be used when the CPM changes the account value. Users who have this authorization can do the following:
If the user does not have this authorization, the ‘Manually selected password’ option will be disabled and the CPM will set a new randomly generated account value.
| ||||||||||||
Rename accounts | Rename existing accounts in the Safe in the Advanced section of the Edit Account page. | ||||||||||||
Delete accounts | Delete existing accounts in the Safe. Users who have this authorization can do the following:
| ||||||||||||
Unlock accounts | Unlock accounts that are locked by other users. Users who have this authorization can do the following:
|
These permissions enable users to control account workflows in the Safe.
Permission | Enables Safe Members to … |
---|---|
Authorize account request | Give “confirmation” to a Safe members requesting permission to enter a Safe. Users also require the ‘List accounts’ authorization to see the Request details of the account requests waiting for their confirmation. |
Access Safe without confirmation | Access the Safe without confirmation from authorized users. This overrides the Safe properties that specify that Safe members require confirmation to access the Safe. |
These permissions enable users to perform folder related activities in the Safe, including the following tasks:
Permission | Enables Safe Members to … |
---|---|
Create folders | Create folders in the Safe. |
Delete folders | Delete folders from the Safe. |
Move accounts/ | Move accounts and folders in the Safe to different folders and subfolders. |
Users who are authorized to Manage Safe Members in a Safe can add existing Vault users and groups, as well as users in external LDAP directories, as Safe members in the PVWA and specify Safe authorizations.
In the Policies page, select the Safe where you will add a Safe member, then click Members; the Safe Details page appears.
In the Members tab, click Add Member; the Add Safe Member window appears.
The default authorizations that will be given to the new Safe Member are selected. These authorizations can be configured in the Default Safe Authorizations in the Web Access Options in the System Configuration page. For more information, refer to Configure the system through PVWA.
In the Search edit box, enter either part of the name of the user or group to add as a Safe member or the whole name. You can also leave the Search edit box empty to search for all users.
In the Search In drop-down box, select Vault, then click Search; a list of users and groups in the Vault whose names match the specified keyword is displayed.
Select the user or group to add as a Safe member, then select the authorizations that they will have in the Safe. Select the checkbox next to the title of the authorizations group to select all the authorizations in that group.
Click Add; the selected user or group is added and confirmation appears at the bottom of the screen.
Click Close; the Safe Details page appears and displays the new Safe member in the Members list.
If the Vault is configured to support transparent user management, users that are configured in an LDAP directory can be added through the PVWA.
In the Policies page, select the Safe where you will add a Safe member, then click Members; the Safe Details page appears.
In the Members tab, click Add Member; the Add Safe Member window appears.
In the Search In drop-down box, select the External Directory where the user that you will add as a Safe member is defined.
In the Search edit box, enter either part of the name of the user or group to add as a Safe member or the whole name. You can also leave the Search edit box empty to search for all users.
Click Search; a list of users in the specified external directory whose names, user ID or email match the keyword and the relevant Vault LDAP mapping rules is displayed.
Select the user to add as a Safe member, then select the authorizations that they will have in the Safe. Select the checkbox next to the title of the authorizations group to select all the authorizations in that group.
Click Add; the selected user is added and confirmation appears at the bottom of the screen.
Click Close; the Safe Details page appears and displays the new Safe member in the Members list.
For more information about managing users in external directories, refer to External user accounts.
Users who are authorized to Manage Safe Members can update existing Safe Member authorizations.
In the Safe Details page, in the Members tab, click the name of the Safe member to update; the Update Safe Member window appears.
Update the Safe authorizations for this Safe member. Select the checkbox next to the title of the authorizations group to select all the authorizations in that group.
Click Save; the user’s authorizations in the Safe are updated and the Safe Details page is displayed again.
In the Safe Details page, in the Members tab, use the horizontal scroll bar to scroll to the end of the Safe Member authorizations; you can see the Remove Member icon.
Click the Remove Member icon in the row of the user to remove; a message appears prompting you for confirmation.
Click OK to remove the user from the list of members for this Safe,
or,
Click Cancel to return to the Safe Members list without removing the user from it.