Reference Guide
...
Password Vault
Split Password Feature
3 min
to secure the two part approval process, account passwords can be split in two and each part retrieved by different users after placing the users in different user groups, follow these steps navigate to policy > realms click on to add button create the device group realm between the user groups (who?) and the device group (what?) containing the target device and save navigate to secrets> vault search for the account click the account options button select permissions to open the permissions pop up window define the read only first part permission type for the user group that will receive the first part of the password define the read only second part permission type for the user group that will receive the second part of the password close the permissions pop up window navigate to policy > portal functions create a portal realm with the sapm management, and sapm account module visibility function groups for both user groups after completing these steps, the users log in and retrieve their parts of the password from the vault section, just like with normal password retrieval they can log in to the target system using the account username and the password combined in the correct order if one or two level approval applies to the user, the user will receive the password part via email, once the approval process is completed