Skip to main content
Question

Server grouping

  • October 10, 2024
  • 5 replies
  • 292 views

Is there a way to limit the servers a user sees when accessing their privileged account? We want to be able to only list servers a user has access to in AD so that they can RDP to them without being overwhelmed with a listing of all servers.

5 replies

  • Apprentice
  • October 10, 2024

if it’s just a few servers that the user needs access to, then I would just save those as favorites.


GloriaB
BeyondTrust Employee
  • BeyondTrust Employee
  • October 11, 2024

Yes, this can be done a few different ways as Password Safe is very configurable. It would depend on the setup in the environment. For example, are they local accounts, or directory accounts?  Are the accounts dedicated mapped? 

You can unlink the AD Managed Account from the Managed System.  If it is not linked it will not show for the webconsole log in user.


Can a Smart Rule be used to unlink Managed Accounts from Managed Systems? How to unlink Managed Accounts KB0019469

 

Below is another method:

How to allow access to a specific Managed System when linked to a Managed Account with multiple systems  KB0019870.

 

Hope this helps,

Gloria

 

 

 

 

 

 

 

 

 

  


Forum|alt.badge.img+1
  • Apprentice
  • October 16, 2024

Using Direct Connect is another approach to ease the pain of a cluttered Password Safe User Interface. Search the admin/user guide for these


Forum|alt.badge.img+3
  • Rising Star
  • December 3, 2024

@tcussat a users access to which domain joined servers their domain priv account is linked to, is managed via a ‘Linking Smart Rule’. You should create a suitable Smart Rule (based on selection criteria) and/or a Managed System Quick Group. This group is then assigned in the user group ‘Smart Groups’ with the Requestor role.


Jaconette de Kock
Forum|alt.badge.img+12

Based on ScottB’s response above, you can create specific asset/managed system groups according to user roles within the source environment (e.g., Active Directory).

These groups can then be imported into Password Safe using a Directory Query.

Once imported, you can link the asset group to the corresponding user group using a Linking Smart Group. The user will then just be presented with these systems in Password Safe for sessions requests.