Announcing the Saviynt Knowledge Exchange unifying the Saviynt forums, documentation, training,
and more in a single search tool across platforms. Read the announcement here.

JIT access for shared accounts on assets

plakhangaonkar
New Contributor II
New Contributor II

Hello,

We have a use case that requires provisioning of JIT access for shared accounts. We will be implementing a privileged access workflow wherein the requestor will place a request for a particular account on an asset. Once the approver approves the request, the account will be automatically added to an AD group which has privileges/admin permissions. Once the request timeframe expires, the requestor will be automatically removed from the AD group. We are particularly focusing on how to update the AD membership with the user addition/deletion.

Thanks,

Priya

1 REPLY 1

NageshK
Saviynt Employee
Saviynt Employee

@plakhangaonkar Thanks for posting your question. JIT access and shared account access are two different ways of gaining access. Please see this article for more information:  https://docs.saviyntcloud.com/bundle/CPAM-Admin-Guide-v23x/page/Content/B-Key-Concepts/PAM-Methods.h...

Regarding your use case : You can achieve access elevation using "Emergency Access Roles" that you can define for your ActiveDirectory Endpoint. 

Emergency Access Roles can be created with Admin privileges by following the below article (Role Type would be Emergency Access and in the Entitlement tab you can add the AD Group that has elevated access):
https://docs.saviyntcloud.com/bundle/EIC-Admin-v23x/page/Content/Chapter02-Identity-Repository/Creat...

Once role is created, End users can start requesting it by following the Role-Based Access section of this article:
https://docs.saviyntcloud.com/bundle/CPAM-User-Guide-v23x/page/Content/A-PAM-Requests/Privileged-Acc...

Thanks,

Nagesh K