Announcing the Saviynt Knowledge Exchange unifying the Saviynt forums, documentation, training,
and more in a single search tool across platforms. Read the announcement here.

How to revoke approved/authorized access?

BrandonLucas_BF
Regular Contributor III
Regular Contributor III

How to handle the scenario where authorization/approval has been granted to a privileged session, but the user has now switched roles? They still have access to request the account until their approval has expired.

Another scenario: potential breach has occurred and we want to revoke all existing privileged account approvals? Or for just one account?

How to accomplish as I don't see you can revoke or discontinue approval after it has been completed? I do see you can end session, but in credential rotation that doesn't apply, and monitoring sessions constantly to make sure they are not started is not feasible.

Removing CPAM access is one option, but may not be desirable in certain scenarios.

2 REPLIES 2

NageshK
Saviynt Employee
Saviynt Employee

@BrandonLucas_BF Thanks for posting the question. We can use "Manage Service Accounts" feature to edit the privileged account where it shows the list of current authorized users and you can remove the user that shouldn't have the authorization anymore. 

Thanks,

Nagesh K

BrandonLucas_BF
Regular Contributor III
Regular Contributor III

Thanks!