Skip to main content
Veteran
August 11, 2026
Question

Managing and linking groups to users and managed systems

  • August 11, 2026
  • 1 reply
  • 37 views

I’m not sure how other admins managed their Password Safe but would love to know how others did theirs.

My main question is that I have thousands of servers with hundreds of different AD groups (privileged Admin accounts) having local admins to several mixed servers. These AD groups were either assigned via GPO or were manually added as local admins to some servers. How do you manage and link these privileged accounts to the managed systems without creating hundreds of different smart rules? Or is there a simpler way to do this?

    1 reply

    Guru
    August 12, 2026

    Hi ​@Jasper 

    This really depends of the granularity of the customers I deal with, but a full blown RBAC will rely on many of Smart Rules and Groups, AD Security Groups etc.

    Consider also using Attributes, Business Units etc. to help you group things up.

    I suggest using a mind-map to map everything out.

    If a subset of users need access to the local Admin on a subset of computers, Group up the systems and those local accounts from those system, which is the local Account Smart Group to grant them access. Allows you to give a different access policy etc.

    Alternatively create shared accounts for your departments etc. that can only be used with forced Proxy session, set concurrent sessions to 1 in your Smart Rule.

    KR Jens