Skip to main content
Version: Axidian Privilege 3.5

User Groups

The section presents working with permissions of user groups.

Add Axidian user group

  1. Navigate to the User Groups section and click Add.
  2. Fill in the Name and Description fields.
  3. Click Save.

Add from catalog

  1. Navigate to the User Groups section and click Add from directory.
  2. Enter the directory name and click search-icon.svg.
  3. Select the group and click Save.

Group profile

For each user group, the following are displayed:

  • Users — a list of users who are members of the group.
  • Permissions — a list of granted permissions for the group to connect to resources.
  • Sessions — a list of active, ended, and aborted sessions.
  • Events — records of operations related to the group.

Add users to the group

info

Only for groups created via Axidian Privilege.

To add users to a group:

  1. Open the user group profile.
  2. Go to the Users tab and click Add users.
  3. Select one or multiple users and click OK.
  4. Confirm the selection and click Add.

Create permission

Permissions allow users to connect to resources.

To create a permission:

  1. Open the group profile and click Create permission.

  2. (Optional) Select an organizational unit and click Select.

  3. Define the permission composition. If necessary, modify the preset parameters.

    More about permission scope
    1. Select who gets access:

      • Users — the permission is granted to one or several selected users.
      • User group — the permission is granted to one selected user group.
    2. Select what to get access to:

      • Resources — the permission is granted to one or several selected resources.

      • Resource groups — the permission is granted to one selected resource group.

      • Ad hoc connections — the permission is granted to Ad hoc resources with the selected connection type, including resources not registered in PAM. One shared account is used for all connection types.

        License required

        A special license is required to work with Ad hoc resources.

        A special license is required to create a permission for PostgreSQL or MSSQL. Before creating the permission, add an account from the DBMS to PAM. You need to specify it in the permission.

    3. Click Next.

    4. Select the account under which the user will open a session on the resource:

      • Select account in PAM — the permission is granted to an account added to Axidian Privilege.
      • Use user account — the permission is granted to an arbitrary account.
        The user needs to enter the login and password of the account on the resource. In RDP and SSH sessions, it is possible to log in using the current Axidian Privilege user credentials.
  4. (Optional) Configure access to credentials.

    More about access settings

    You can grant access to credentials only at the permission creation step.

    The following settings are available:

    • Credentials — the option defines actions with credentials:
      • Allow view account credentials — users can view passwords of the accounts from this permission.
      • Allow change account credentials — users can change passwords of the accounts from this permission.
    • Allow running pamsu in SSH sessions — the setting defines access to PamSU when connecting via SSH Proxy:
      • Managed by policies — access to PamSU is determined by the policy of the resource for which the permission is granted.
      • Allowed — the user can use PamSU regardless of policy settings.
      • Denied — the user is not allowed to use PamSU regardless of policy settings.
  5. (Optional) Fill in the Description field.

  6. (Optional) Configure time restrictions.

    More about time restrictions

    You can set a schedule according to which users are allowed to open sessions or change credentials. For example, you can grant permission to work only on weekdays from 8:00 to 17:00.

    The following settings are available:

    • Validity period — the time period during which the permission is valid. For example, you can grant permission for one day or month.

      • Begin — set the date and time when the permission becomes active.
        If only Begin is set, the permission will become active on the selected date, and its validity period will be unlimited.

      • End — set the date and time when the permission becomes inactive.
        If only End is set, the permission will become active at the moment of creation, but will be suspended on the specified date.

        info

        If the Begin and End parameters are not set, the permission will be valid indefinitely.

    • Access schedule — restrictions by days of the week taking into account the specified schedule.

      • Allow access only on selected days — select the days of the week when the permission will be active.

      • Allow access only during selected hours — select the time when the permission will be active.

        info

        Access by days of week is granted according to the management server time zone.

    After the validity period expires, the permission will transition to the Restricted/Inactive state, and the user session will be terminated.

  7. In the Connection source setting, select the network address from which sessions to the resource are allowed to be opened. If no network locations are added to PAM, the value is set to No restrictions — the permission can be used from any device on the network.

  8. Check the data and click Create permission.

Synchronize user groups with directory

info

Only for groups from directory service.

  1. Open the user group profile.
  2. Click Sync and confirm the action.

Select policy

  1. Open the user group profile.
  2. Click pencil_icon.svg next to the Policy parameter.
  3. Select a policy from the list and click Select.

Remove

  1. Open the user group profile.
  2. Click Remove.
  3. Confirm the action by clicking Remove.

To remove multiple groups, in the User Groups section, select the required groups and click Remove.