Symantec Privileged Access Management

 View Only
  • 1.  Kick/ Alert Mechanism for Access Request Duration

    Posted Nov 13, 2019 03:09 AM
    CA PAM v3.2.6

    I need some confirmation of whether or not PAM able to either kick user access or give them alert when their access request duration about to come to an end. Currently, user still able to access target device even after their requested duration is over as long as they do not close their access session.

    ------------------------------
    Regards,
    Jorghy M.
    ------------------------------


  • 2.  RE: Kick/ Alert Mechanism for Access Request Duration

    Broadcom Employee
    Posted Nov 13, 2019 09:21 AM
    Hi Jorghy, PAM doesn't have "access request duration". PAM has a password view duration, i.e. a time window during which you are allowed to view or use the password of a target account. This is required only at the time you log on to a target server. Once logged on, the password is not needed anymore (unless you have a transparent login configuration). The only timeout that impacts an established access session is the idle timeout that you configure in Global Settings.


  • 3.  RE: Kick/ Alert Mechanism for Access Request Duration

    Posted Nov 14, 2019 03:29 AM
    Yes, i meant Password View under Workflow Approval duration, but i only use it for Auto Connect and not View. When a user requesting access to target device that needs approval, they have to put Request Start - End Date with maximum length of duration which limited by our configuration of Maximum Request Interval under Dual Authorization. There's a need for both alert notification and force termination after the requested duration is over, is it possible?


  • 4.  RE: Kick/ Alert Mechanism for Access Request Duration
    Best Answer

    Broadcom Employee
    Posted Nov 14, 2019 09:47 AM
    No, PAM doesn't kill active connections to target devices. Again, the request interval is for the password, not for the access session itself.


  • 5.  RE: Kick/ Alert Mechanism for Access Request Duration

    Posted Nov 14, 2019 10:28 PM
    I see. That means PAM cannot do any termination or alerting againts active access session even when their duration is up. Thanks for your reply Ralf.