Log in to the Remote Application with a Vault User
when configuring the login to a remote application with a password vault docid\ irgu3amm8wp0 nkc vlcb account, the definition of an ip address is mandatory and can be selected from a combo box, meaning it has to be selected from among the devices already added to kron pam the ip address is the target device’s ip address and should match the device ip configured in the auto login screen for the vault account to be seen on the auto login screen to the target application to use this account for remote app auto login, assign this credential to the session account for more information, see assigned credentials docid\ gk qxovrnos5wfox qyp7 sometimes more than one device per user is kept in the vault in such cases, the user to be used while logging in to the remote application should be identified the following figure shows the vault account configuration for remote application login as mentioned, vault accounts can also be assigned to session users to automatically log into remote apps vault account strategies are important for user listing when using the allow assigned credentials option the diagram below shows how remote app user listing is affected when a vault account is assigned to a session user the always show\ accounts in auto login parameter shown in the diagram above is a vault configuration parameter for more information, see adding vault configurations docid\ xujmkhum25ee8dt0vuic2 the remote app %s ip independent account show\ in auto login parameter is a configuration parameter on the remote app auto login page this parameter can be selected when an assigned credential is used according to the flow in the diagram above, if the always show\ accounts in auto login parameter is set as true and we check this parameter, the account is shown on the remote app auto login user list without checking the ip match assigned credentials and time restrictions in remote applications when a user is assigned an account via assigned credentials and attempts to log into a remote application, the availability of the account depends on the time parameters set in the assigned credentials here's how the behavior is determined account listing based on assigned credential time if the login attempt to the remote application occurs within the time frame specified in the assigned credentials, the account will be listed among the available accounts for login if the login attempt occurs outside of the assigned time frame , the account will not appear in the list of available accounts for the remote application session behavior when assigned credential time expires active session management timeout warning notification by configuring these parameters, administrators can control both the visibility of accounts based on assigned credential time and the session behavior when the assigned time expires parameters are defined in system config manager