Symantec Privileged Access Management

 View Only
  • 1.  How can we have the visibility of a common account of DB via PAM?

    Posted Dec 04, 2019 05:54 AM

    How can we have the visibility of a common account of DB via PAM?

    ex.

    If more than 5 users access the same account of same DB. How can we segregate which user has carried out which activity?


    Please suggest?


    Also, what is the best practice for onboarding and managing DB users from PAM?



    ------------------------------
    Network and security Engineer technical associative
    Cas Trading House
    Putalisadak, KTM
    ------------------------------


  • 2.  RE: How can we have the visibility of a common account of DB via PAM?
    Best Answer

    Broadcom Employee
    Posted Dec 05, 2019 12:33 AM

    Hello Sudip,

    This is currently not possible to track, but you ca post this as a feature requirement in the communities under the "ideation" section.

    The other option would be to deploy CA PIM on the RDP Terminal host, and then define an audit policy for the DB to track the events of each login.

    But, in CA PAM this is currently not possible.

    Thanks,

    Reatesh.



    ------------------------------
    Principal Support Engineer
    Broadcom
    ------------------------------



  • 3.  RE: How can we have the visibility of a common account of DB via PAM?

    Posted Dec 17, 2019 03:26 AM
    Hello Reatesh,

    Can you elaborate on this thing:

    The other option would be to deploy CA PIM on the RDP Terminal host, and then define an audit policy for the DB to track the events of each login.
    Does PIM mean privilege identity manager?
    Please share a detail document on this thing?

    Thank you,


    ------------------------------
    Network and security Engineer technical associative
    Cas Trading House
    Putalisadak, KTM
    ------------------------------



  • 4.  RE: How can we have the visibility of a common account of DB via PAM?

    Broadcom Employee
    Posted Dec 05, 2019 12:33 AM
    Hi Sudip, You could use Check-Out/Check-In to serialize use of the DB account. If parallel use is required, you would need to record the sessions.