/
Granting Access to PAM with Management Roles

Granting Access to PAM with Management Roles

EmpowerID restricts access to PAM and PSM through the use of Management Roles. To work with PAM and PSM, users must be assigned to the appropriate roles. Management Roles are prefixed by their function in EmpowerID and include the following:

  • UI – Management Roles prefixed with UI grant users access to specific UI elements in the EmpowerID Web interface. An example of this type of role for PAM is UI-Computer-PAM-User-Full-Access. This role grants access to the user interfaces and workflows for requesting PSM access to computers.

  • VIS – Management Roles prefixed with VIS grant users the ability to see specific objects in EmpowerID. An example of this type of role for PAM is VIS-Computer-MyLocations. This role grants access to see computers that belong to the same location as the person with the role.

  • ACT – Management Roles prefixed with ACT grant users the ability to manage specific objects in EmpowerID. An example of this type of role for PAM is ACT-Computer-Shared-Credential-Assigner-MyLocations. This role grants users with the role the ability to assign and unassign shared credentials to computers in the person's locations.

Roles needed to use credentials and access computers

To use vaulted credentials and access computers, users need to be a member of one of the below Management Roles (based on the needed scope):

Management Role

Access Granted

Management Role

Access Granted

PAM User for All Creds and Computers (Role Bundle)

This Management is a role bundle that grants people with the role membership in the below Management Roles:

  • UI-Shared-Credential-PAM-User-Self-Service

    • Grants access to the user interfaces and workflows to request and use vaulted credentials

  • UI-IT-Shop-MS-Computer

    • Grants access to shop for access to servers in the IAM Shop microservice app

  • UI-Computer-PSM-User-Self-Service

    • Grants access to the user interfaces and workflows to request PSM access to computers

  • UI-IT-Shop-MS-Shared-Credential

    • Grants access to shop for Shared Credentials in the IAM Shop microservice app

  • ACT-Shared-Credential-Use-All

    • Grants access to check-out all shared credentials

  • ACT-Computer-Shared-Credential-Login-All

    • Grants access to use a shared credential to initiate a Privileged Session to any computer

  • VIS-Computer-All

    • Grants access to see all computers

  • VIS-Shared-Credential-All

    • Grants access to see all vaulted credentials

  • IAM Shop, My Tasks, and My Identity Self-Service Basic UI Access Only - no resource types

    • Grants access for the UI to use the IAM Shop, My Tasks, My Identity microservices but does not grant visibility to objects or the UI- roles for each resource type.

PAM User for Creds and Computers in My Locations (Role Bundle)

This Management is a role bundle that grants people with the role membership in the below Management Roles:

  • UI-Shared-Credential-PAM-User-Self-Service

    • Grants access to the user interfaces and workflows to request and use vaulted credentials

  • UI-IT-Shop-MS-Computer

    • Grants access to shop for access to servers in the IAM Shop microservice app

  • UI-Computer-PSM-User-Self-Service

    • Grants access to the user interfaces and workflows to request PSM access to computers

  • UI-IT-Shop-MS-Shared-Credential

    • Grants access to shop for Shared Credentials in the IAM Shop microservice app

  • ACT-Shared-Credential-Use-MyLocations

    • Grants access to check-out shared credentials in the person’s locations

  • ACT-Computer-Shared-Credential-Login-MyLocations

    • Grants access to use a shared credential to initiate a Privileged Session to computers in the person’s locations

  • VIS-Computer-MyLocations

    • Grants access to see computers in the person’s locations

  • VIS-Shared-Credential-MyLocations

    • Grants access to see vaulted credentials in the person’s locations

  • IAM Shop, My Tasks, and My Identity Self-Service Basic UI Access Only - no resource types

    • Grants access for the UI to use the IAM Shop, My Tasks, My Identity microservices but does not grant visibility to objects or the UI- roles for each resource type.

PAM User for Creds and Computers in My Org (Role Bundle)

This Management is a role bundle that grants people with the role membership in the below Management Roles: