Skip to main content

Hello Beekeepers

 

We have a scenario where we want split out managed system from one platform to another with removing the systems from password safe as manage system.

Example we have Redhat Linux servers using a custom Linux platform and also have centos on the same platform and now we want to separate it so we can apply separate functional account and rules .

Is this possible somehow without impacting the managed systems

 

I don’t know if this is what you are looking for but you can place systems into different workgroups.

We have two functional accounts.

  1. svc_beyondtrust_users - manage passwords for all users who do not have an adminCount of 1.
  2. svc_beyondtrust_DA - Manage passwords for all users where admincount=1 (domain admins, etc.)

We place each account in its required workgroup based on which account will rotate the password.

Now, I see this

All DA accounts or any other account that has admin count of 1 are tied to the domain in the DA Workgroup while all other accounts are tied to the BeyondTrust Workgroup. The functional account for each workgroup is different. DA gets the DA functional account, BeyondTrust Workgroup uses the standard user functional account

In this screenshot, it is the same domain for all 4 rows, just a different workgroup.

I also have two separate workgroups for the lab, DMZ, and lab DMZ as well.

Workgroups are defined under Configuration → General → Organizations

Workgroups can also have specific discovery scanners assigned to them so you can have a single appliance with access to the DMZ instead of your whole BeyondTrust deployment.

You can most definitely move assets to another platform as well. Simply edit your asset, Edit the asset and in workgroup, click the pulldown and select your new workgroup.

 


Hello Rhager

 

Thank you for the response  however what we looking for is updating the Platform , we have all Linux servers on a Custom Linux platform and we want to split out RHEL from Centos servers. We want to move Centos to it own Platform with its own functional account . I believe this can be done with SMART RULES but not entirely sure .


Reply