Access policies registration
  • 9 minutes to read
  • Dark
    Light
  • PDF

Access policies registration

  • Dark
    Light
  • PDF

Article summary

This document provides information about the Access Policies form screen, where you can add new groups and their access policies and/or change groups already registered.

Path to access

  1. On senhasegura, in the navigation bar, hover over the Products menu and select PAM Core.
  2. In the side menu, select Access control > Access policies > Add.

General tab

This section provides general information about the access policy.

ItemTypeRequiredDescription
Access group name*Text fieldYesAccess group identifier name.
StatusToggle buttonNoEnables or disables the access group status.
DescriptionText fieldNoGeneral information about the access group.
Info

If AD group sync is enabled, permissions for members synced by that group will be overwritten on the next sync. Manual changes (add or remove users) will be undone.


Users tab

This section provides information about the list of users included in the access policy.

ItemTypeRequiredDescription
UsersText fieldNoSearch for the user's name in the list of users included in the group.
AddButtonNoOpens the senhasegura users' screen, so that they can be included in the group.
User tableTableNoData for each member of the access group containing checkbox fields, ID, Name, Username, E-mail, Creation type, Department, Added by and Added on.
Info

By default, users belonging to more than one access group will be assigned the most restrictive group settings.


In the Password and Session tabs, you can select the days and time range for which an approval workflow will be required. These functionalities are independent and can be enabled in Password, but disabled in Session, or vice versa.

Password tab

This section provides information about the password rules of the access policy.

Info

In this section, some fields will only be displayed after some specific fields are enabled.

ItemTypeRequiredDescription
Allow users to view passwordsToggle buttonNoEnables or disables permission whether the credential password can be seen by the user.
Part of the password to be viewed*Dropdown menuYesOptions for how to view the password. The options are: Full password, 1st part of the password and 2nd part of the password. Members of this group will only have access to the fraction defined in this field. However, the proxy functionality can use the password, as the user doesn’t have access to the plain text password when using any of our proxy solutions.
Request users a reason before viewing a passwordToggle buttonNoEnables or disables the need for the user to register a justification to see the password.
Require approval to view a passwordToggle buttonNoEnables or disables the need for approval, carried out by the registered approver, so that the user can view the password. Once enabled, you also need to define how many approvals will be required.
Approvals required for viewingQuantity inputNoSelect the number of approvals required to approve the operation for each level (doesn’t count the total number of approvals).
Disapprovals required to cancelQuantity inputNoSelect the number of disapprovals necessary to reject the operation for each level (doesn’t count the total number of disapprovals).
Approval in levelsToggle buttonEnables or disables the rule that approvers will be triggered in levels. When enabled, a hierarchy of approvers can be defined.

Advanced Options section

ItemTypeRequiredDescription
Allow emergency access without approvalToggle buttonNoEnables or disables whether the user can perform emergency access without the need for prior approval.
Users can change expiration dateToggle buttonNoEnables or disables whether the user can change the group's expiration date.*
Require approval daysToggle buttonNoEnables or disables the need to establish the days and times that approval will be required.
The date can be changed up to:Quantity inputNoSelect the number of minutes that the date changed by the user can occur. The options are from 0 to 100. This option is only available if the option Users can change the expiration date is enabled.
Info

*In the credentials display window, a button will appear for the user to increase their access period up to the time indicated in this field.

Require approval days section

This section will only be available if the Require approval days option is enabled.

ItemTypeRequiredDescription
All daysToggle button and checkboxNoIf enabled, the user must request approval every day. If disabled, select the days of the week on which group members must request approval.
All TimesToggle buttonNoEnables or disables the period of time in which the user will have to request approval.
Custom PeriodToggle button and time pickerNoEnables or disables a specific time range within which the user must request approval. When enabled, two-time pickers are enabled so that the beginning and end of the period can be stipulated.

Sessions tab

This section provides information about the session rules of the access policy.

Info

In this section, some fields will only be displayed after some specific fields are enabled.

ItemTypeRequiredDescription
Allow users to start sessionsToggle buttonNoEnables or disables permission for users in the group to start a session.
Enable session blocking during FreezingToggle buttonNoEnables or disables the permission for users in this group to have their session blocked during the session freeze period.
Request users a reason before starting sessionToggle buttonNoEnables or disables the need to record a justification to start the proxy session.
Require approval to start sessionToggle buttonNoEnables or disables the need for approval, carried out by the registered approver, so that the user can start a session. Once active, you also need to define how long this approval will be valid.
Approvals requiredQuantity inputNoSelect the number of approvals required to approve the operation for each level (does not count the total number of approvals).
Disapprovals required to cancelQuantity inputNoSelect the number of failures necessary to fail the operation for each level (does not count the total number of failures).
Approval in levelsToggle buttonNoEnables or disables the rule that approvers will be triggered in levels. Thus, a hierarchy of approvers can be defined.

Advanced Options

ItemTypeRequiredDescription
Allow emergency accessToggle buttonNoEnables or disables whether the user can perform emergency access without the need for prior approval.
[Change Audit] Require Change ID to start sessionToggle buttonNoEnables or disables whether the requester must register an ITMS code at the time of justification.
Require approval daysToggle buttonNoEnables or disables the need to establish the days and times that approval will be required.

Require approval days

ItemTypeRequiredDescription
All daysToggle buttonNoIf enabled, the user must request approval every day. If disabled, select the days of the week on which group members must request approval.
All TimesToggle buttonNoEnables or disables the period of time in which the user will have to request approval.
Custom PeriodToggle buttonNoEnables or disables a specific time range within which the user must request approval. When enabled, two-time pickers are enabled so that the beginning and end of the period can be stipulated.
Attention

When the Approval in levels field is enabled, there are rules that must be followed for approval and disapproval to work correctly. More information in About Approval and disapproval rule.


Approvers tab

This section provides information about the list of approvers added to the access policy.

ItemTypeRequiredDescription
ApproversText fieldNoSearch for the user's name in the list of users included in the group.
AddButtonNoOpens the senhasegura approving users screen, so that they can be included in the group.
Approvers tableTableNoData for each member of the access group containing checkbox fields, ID, Name, Username, E-mail, Creation type, Department, Added by, Added on and Level.
LevelDropdown menuNoOptions to choose possible approver levels. The options are Level 1, Level 2 and Level 3. See the explanation of approver levels above.
Governance ID required when justifying?*Toggle buttonYesEnables or disables whether the applicant must enter the ITMS code at the time of justification.
Always add user manager to approvers?*Toggle buttonYesEnables or disables whether the user responsible for the registered user's department should be automatically consulted as an additional approver for this group. This way, this user will be alerted with the other approvers in the Approvers tab.
Attention

For each approver added, a level must be assigned to them. More information in About Approvers level.


Criteria tab

This section provides information about the criteria of the access policy.

ItemTypeRequiredDescription
Site*Dropdown menuYesOptions with the types of sites that will be visible to the group. The available options will be as registered in senhasegura.
Device type*Dropdown menuYesOptions with the types of devices that will be visible to the group. The options are defined according to the types of registered devices.
Credential type*Dropdown menuYesOptions with the types of credentials that will be visible to the group. The options are: All, SSH Key, Domain User, Local User and Local administrator.
DeviceToggle buttonNoEnables or disables the text field for including devices.
Device (comma separated)Text fieldNoDevice registration name. In the Device Field document there are possible ways to fill in this field.
ProductToggle buttonNoEnables or disables the text field for including device models.
Product (comma separated)Text fieldNoDevice models name.
UsernameToggle buttonNoEnables or disables the text field for including user names.
Username (separated by comma)Text fieldNoCredential username. In the
Username field document there are possible ways to fill in this field.
Additional informationToggle buttonNoEnables or disables the text field for including additional information.
Additional information (separated by comma)Text fieldNoText with additional information about the registration.
Device TagsToggle buttonNoEnables or disables the text field for including tags for devices.
Device Tags (comma separated)Text fieldNoTags registered for devices.
Credential TagsToggle buttonNoEnables or disables the text field for including tags for credentials.
Credential Tags (separated by commas)Text fieldNoTags registered for credentials.
Attention

For filling out the Device (comma separated) and Username (separated by comma) fields, there are rules that need to be followed. More information in About Filling Out the Device and Username Fields.


Access limitation tab

This section provides information about the restriction rules for the access policy.

Access permission days

ItemTypeRequiredDescription
All daysToggle buttonNoEnables or disables the permission option for all days. By default the option Every day are enabled, to select specific days, disable this option and select the days.
Days of the weekCheckboxNoWhen the field above is disabled, select the days of the week.

Access permission times section

ItemTypeRequiredDescription
All timesToggle buttonNoEnables or disables the permission option for all time slots. By default the option All times are enabled, to select specific days, disable this option and select the days.
Time rangeCheckboxNoWhen the field above is disabled, select time ranges.
CustomToggle button and time pickerNoEnables or disables the option to customize the access permission time.

Access permission period section

ItemTypeRequiredDescription
StartDate and time pickerNoSelect the start date and time of the permission period.
EndDate and time pickerNoSelect the end date and time of the permission period.

Review tab

This section provides information added in the previous steps so that it can be analyzed and, if necessary, changed before finalizing the registration. The information is grouped by each tab.


Was this article helpful?