Adding Function Groups
Menu permissions and privilege definitions in Kron PAM are configured based on user groups.
Kron PAM provides default portal function groups. Users can be granted rights through the default groups. New function groups can be created using the desired portal functions for various authorization purposes.
To create a new function group:
- Navigate to Policy > Portal Functions.
- Open the Function Group Definition tab.
- Click on the +Add button.
- Fill in the Function Group Name and Description fields.
- Select the functions and module views to be assigned to the users.
- Click Save.

To edit an existing function group:
- Navigate to Policy > Portal Functions.
- Open the Realm Definition.
- Click the action button and Edit Realm.
- Select the functions and module views to be assigned to the users.
- Click Save.
Function | Description |
|---|---|
aioc.command.player.moduleVisibility | Grants the right to view the Quick Commands screen in the Utility menu. The Quick Commands section is used to run pre/post-check commands. |
aioc.cp.script.builder.ui.moduleVisibility | Grants the right to view the Script Builder screen in the Script Designer menu. The Script Builder is used to design new scripts and manage existing scripts. |
aioc.cp.script.player.ui.moduleVisibility | Grants the right to view the Script Player screen in the Script Designer menu. Users can run pre-defined scripts from the Script Player. |
aioc.cp.workflow.history.moduleVisibility | Grants the right to view the Workflow History screen in the Workflow Designer menu. When a defined workflow is run, its records are available in the Workflow History screen. |
aioc.cp.workflow.manager.moduleVisibility | Grants the right to view the Workflow Designer screen in the Workflow Designer menu. Workflows are created here. User groups require permission to use a workflow. |
aioc.device.group.moduleVisibility | Grants the right to view the Device Groups screen in the Inventory menu. Device groups are created in this menu and device realms are created to determine the authorizations of user groups in the device groups. |
aioc.device.group.show.secrets | Grants the right to view device group secrets such as passwords. |
aioc.discovery.discover.device | Grants the right to access the tabs “New Device Discovery”, “Auto Device Discovery”, “Auto Discovery Log”, and “Auto Discovery Dashboard” under the Inventory section. |
aioc.discovery.add.device | Grants access rights to the Inventory, Discovery, Auto Discovery Log and Auto Discovery Dashboard tabs under the Devices section, and grants the right to add devices. |
aioc.discovery.delete.device | Grants access rights to the Inventory under the Devices section, and the right to delete devices. |
aioc.discovery.manage.operationMode | Grants the right to schedule maintenance times for devices in the Devices tab under the Inventory section. |
aioc.discovery.manage.unassigned | Grants the right to manage devices in unassigned device groups under the Inventory section. |
aioc.element.type.moduleVisibility | Grants the right to view the Element Type screen under the Inventory menu. This menu is used to create, delete, or edit element types (and their properties) manually. |
aioc.help.manager.moduleVisibility | Grants the right to view the Help Manager screen in the Device Administration menu. This is used to create, edit, or delete the help menu content. |
aioc.platform.activity.logs.moduleVisibility | Grants the right to view the Activity Logs screen in the Logging menu. System events and all transactions made in the web interface are logged and can be viewed from here, and the user can only view their own logs. |
aioc.platform.activity.groupLogs.moduleVisibility | Grants the right to view the Activity Logs screen in the Logging menu. System events and all transactions made in the web interface are logged and can be viewed from here, and the user can view the logs of all users within their own user group. |
aioc.platform.sysconfig.integration.approvalMailbox.moduleVisibility | Grants the right to view and manage the Approval Mailbox Configuration screen. This section is used to configure mailbox settings for approval workflows. |
aioc.platform.sysconfig.integration.emailConfig.moduleVisibility | Grants the right to view and manage the Email Configuration screen under System Configuration Manager. This section is used to configure and maintain email integration settings. |
aioc.platform.sysconfig.integration.LdapUserIntegration.moduleVisibility | Grants the right to view and manage the LDAP User Integration screen. This section is used to configure LDAP-based user synchronization and authentication. |
aioc.platform.sysconfig.integration.LDAPDeviceIntegration.moduleVisibility | Grants the right to view and manage the LDAP Device Integration screen. This section is used to configure LDAP-based device discovery and synchronization. |
aioc.platform.sysconfig.integration.SAMLConfig.moduleVisibility | Grants the right to view and manage the SAML Configuration screen under System Configuration Manager. This section is used to configure SAML-based authentication settings. |
aioc.platform.sysconfig.integration.smsConfig.moduleVisibility | Grants the right to view and manage the SMS Configuration screen. This section is used to configure SMS notification and integration settings. |
aioc.platform.sysconfig.integration.vmwareIntegration.moduleVisibility | Grants the right to view and manage the VMware Integration screen. This section is used to configure VMware environment integration settings. |
aioc.platform.sysconfig.moduleVisibility | Grants the right to view the System Configuration Manager screen in the Administration menu. From here, authorized users can add, edit, or delete system configuration parameters. |
aioc.pki.auth.integration.moduleVisibility | Grants the right to view and manage the PKI Authentication screen. This section is used to configure certificate-based authentication settings. |
aioc.risk.score.integration.moduleVisibility | Grants the right to view and manage the Application Inspection Integration screen. This section is used to configure risk scoring and application inspection settings. |
aioc.system.backup.moduleVisibility | Grants the right to view the Backup Management page under the Administration menu. This page allows users to get backups after setting relevant parameters in the system configuration. |
aioc.users.approve.all_user | Grants the right to approve new user requests, even if the grantee is not an admin. |
aioc.users.approve.finalApproval | Grants the right to approve pre-approved user requests. |
aioc.users.manage.user | Grants the right to manage users. |
aioc.users.manage.user_group | Grants the right to manage user groups. |
desktop.device.group.moduleVisibility | Grants the right to view only the permissioned device list on Kron PAM Desktop Client and Kron PAM Web GUI. Note that aioc.device.group.moduleVisibility is used to view/edit the permissioned device list on Kron PAM Web GUI, whereas desktop.device.group.moduleVisibility is a limited version of aioc.device.group.moduleVisibility, which only grants view permission to the permissioned device list. |
kronpam.assigned.credential.user.self.manage | Grants users limited access to the Assigned Credentials menu and allows them to manage assigned credentials only within their own user groups. Users with this function can perform actions only within their own groups and do not have visibility or permissions across other groups. (can only view, add, or delete Assigned Credentials related to users and devices within their own group and cannot view or modify credentials belonging to other groups.) |
kronpam.auditLog.groupLogs.moduleVisibility | Grants the right to access the Audit Logs tab in the Session Log section, under the Logging menu. In this tab, Audit users can sign sessions as “passed audit”, “failed”, or “n/a”. The user can see the log records of all users within their own user group. |
kronpam.commandLog.userLogs.moduleVisibility | Grants permission to view the Command Log screen under Logging > Session Log. The user can see only the command logs of the commands they executed in their own sessions. |
kronpam.commandLog.groupLogs.moduleVisibility | Grants permission to view the Command Log screen under Logging > Session Log. The user can see the command logs of all users in their own user group. |
kronpam.freeradius.acc.groupLogs.moduleVisibility | Grants the right to view the RADIUS Account Logs screen in the Logging menu. This section displays RADIUS account logs, and the user can view the logs of all users within their own user group. |
kronpam.user.auth.groupLogs.moduleVisibility | Grants permission to view the User Authentication Logs screen in the Logging menu. From this screen, the user can access the login and logout log records of all users within their own user group. The Authentication Logs page shows when and where users logged in and which authentication method was used. |
kronpam.httpProxy.groupLogs.moduleVisibility | Grants the right to view the HTTP Proxy Logs screen in the Logging menu. In this section, the user can view the HTTP Proxy session transactions of all users within their own user group. |
kronpam.tacacs.acc.groupLogs.moduleVisibility | Grants the right to view the TACACS Account Logs screen in the Logging menu. All commands executed during the TACACS+ session can be viewed in the TACACS Account Logs menu, and the user can view the logs of all users within their own user group. |
statistics.dashboard.visibility | Grants the right to view statistics regarding connections, devices, users, and vault. |
netright.admin.datasource.manager.moduleVisibility | Grants the right to view the Datasource Manager screen in the Administration menu. This section allows the definition of a datasource for Kron PAM. |
netright.bulkimport.moduleVisibility | Grants the right to view the Bulk Import screen in the Inventory menu. Devices can be added in bulk from this section. |
netright.commands.moduleVisibility | Grants the right to view the Command Template screen in the Utility menu. Defined commands that are used in scripts or pre/post-checks are managed from here. |
netright.components.moduleVisibility | Grants the right to view the Components screen in the Administration menu. |
netright.discovery.moduleVisibility | Grants the right to view the Inventory screen in the Devices menu. This section enables adding, deleting or editing devices. |
netright.jobs.moduleVisibility | Grants the right to view the Job Scheduler screen in the Administration menu. This section allows managing automated and/or manually triggered jobs. |
netright.log.moduleVisibility | Grants the right to view the System Log Viewer screen in the Administration menu. System logs can be monitored from this section. |
netright.mailSender.moduleVisibility | Grants the right to view the Mail Management screen in the Administration menu. You can send emails through Kron PAM GUI from this section. |
netright.memory.moduleVisibility | Grants the right to view the Memory Manager screen in the Administration menu. You can check the memory status from this section. |
netright.realms.moduleVisibility | Grants the right to view the Portal Functions screen in the Policy menu. The screens available to user groups is determined in this section. |
netright.siem.configuration.moduleVisibility | Grants the right to view the SIEM Configuration screen in the System Configuration Manager menu. Kron PAM can send logs to SIEM systems. |
netright.user.approval.moduleVisibility | Grants the right to view the User Approval in the User Management menu. The User Approval section displays all users who have sent the “New User” request from the main page and is used to confirm their requests. |
netright.user.auth.log.moduleVisibility | Grants permission to view the User Authentication Logs screen in the Logging menu. From this screen, the user can access only their own login and logout log records. The Authentication Logs page shows when and where the user logged in and which authentication method was used. |
netright.users.moduleVisibility | Grants the right to view the User Accounts screen in the User Management menu. You can define users and user groups in this section. |
sc.aaa.remote.db.moduleVisibility | Grants the right to view the AAA Remote Database screen in the RADIUS menu. In this section, you can define and edit databases. |
sc.cloud.integration.moduleVisibility | Grants the right to view the Cloud Integration screen in the Administration menu. In this section, the required configurations to add or discover devices from Amazon Web Services, Google Cloud Platform, and Microsoft Azure can be set. |
sc.devops.moduleVisibility | Grants the right to view the DevOps Management screen in the DevOps menu. You can define new DevOps teams or edit existing ones in this section. |
sc.log.duplicator | This function provides the “duplicate log” option for logs in the Command Log tab in the Session Log section under the Logging menu. |
sc.log.search.network.admin | Grants the right to access the logs of device groups which the user shares a realm with. The user can view the logs of these device groups from the Command Log tab in the Session Log section, under the Logging menu. |
sc.log.search.skip.realm | Grants the right to view all logs of all devices in the Command Log tab in the Session Log section, under the Logging menu. Regardless of the device realm the user is part of, the user with this function can still view logs for all devices. |
sc.log.session.auditor | Grants the right to access the Audit Logs tab in the Session Log section, under the Logging menu. In this tab, Audit users can sign sessions as “passed audit”, “failed”, or “n/a”. Each user can see only their own log records. |
sc.reservation.manager.request.on.behalf.of.group.users | Grants the right to the group manager to enter a connection reservation request on behalf of any group members. When granted, the “For User” selection field appears in the Connection Reservation screen for the group manager. |
sc.script.builder.super.user | Grants the right to access the Script Realm tab in the Script Builder section under the Script Designer menu. In this tab, you can authenticate user groups to play scripts. |
sc.sensitive.data.discovery.moduleVisibility | Grants the right to view the Sensitive Data Discovery screen in the Sensitive Data Discovery menu. This section is used to discover sensitive data in databases. |
sc.ssh.keys.provisioning.viewer | This function is defined for admins to allow them access to the User Key Management tab, on the SSH Key Manager page under the Users menu. |
sc.tacacs.management.moduleVisibility | Grants the right to view the TACACS Management screen under the Administration menu. Kron PAM uses its own TACACS+ server to authenticate users. TACACS+ configuration can be done from the TACACS+ Management section. |
single.connect.aapm.moduleVisibility | Grants the rights to view the screens related to Application Token management under Vault. |
single.connect.assigned.credential.moduleVisibility | Grants users the ability to view the Assigned Credentials menu and manage assigned credentials within the Users menu. Users with this function have full access across the system regarding credential management. They can manage Assigned Credentials across all user groups. |
single.connect.cli.moduleVisibility | Grants the right to establish an SSH/Telnet connection by clicking the “Open Terminal” option for devices. The “Open Terminal” option is presented in the Device Inventory section under the Device Management menu, or on the Dashboard. |
single.connect.dashboard.moduleVisibility | Grants the right to view the Statistic screen in the Dashboard menu. The activities and commands ran by users are viewed in this section. |
single.connect.diagnostic.moduleVisibility | Grants the right to view the Policy Tracking screen in the Policy Control menu. You can search any user’s authentication/authorization details, and Vault account permissions in this section. |
single.connect.freeradius.802dot1x.moduleVisibility | Grants the right to view the RADIUS Account Logs screen in the Logging menu. This section displays RADIUS account logs, and the user can only view their own logs. |
single.connect.freeradius.acc.moduleVisibility | Grants the right to view the RADIUS Account Logs screen in the Logging menu. |
single.connect.httpProxy.ui.moduleVisibility | Grants the right to view the HTTP Proxy Logs screen in the Logging menu. In this section, the user can view only their own HTTP Proxy session transactions. |
single.connect.instanceController.moduleVisibility | Grants the right to access the Kron PAM Controller Configuration section. You can configure all instances by using this section. |
single.connect.linux.audit.report.moduleVisibility | Grants the right to view the Linux Audit Report screen in the Audit Report menu. This section is used to report the current security status of local Linux accounts. |
single.connect.macfiltering.moduleVisibility | Grants the right to view the MAC Filtering screen in the Administration menu. This section is used to manage the users' MAC addresses. Allowed MAC addresses can be defined, edited or deleted. |
single.connect.policy.enforcement.moduleVisibility | Grants the right to view the Policy screen. |
single.connect.rdp.client.moduleVisibility | Grants the right to establish a Remote Desktop session by clicking the “Open Remote Desktop” option for devices. The “Open Remote Desktop” option is presented in the Inventory section, under the Device Management menu, or on the Dashboard. |
single.connect.rdp.disallow.hiding.keys | This function is used to disable the key log hiding feature for certain user groups. |
single.connect.remote.desktop.app.moduleVisibility | Grants the right to view the Remote Desktop App screen in the Administration menu. Kron PAM allows you to limit the applications to be accessed on windows servers from this section. After the application name and path are defined in this section, permissions are set from the Device Management menu. |
single.connect.remote.desktop.moduleVisibility | This function grants the right to play sessions in the Command Logs tab of the Session Log section, under the Logging menu. |
single.connect.reports.ui.moduleVisibility | Grants the right to view the Reports screen. |
single.connect.reservation.management.moduleVisibility | Grants the right to view the Reservation Management screen in the Policy Control menu. Users can make connection reservations for devices that require managerial approval for connection from this section. After the approval from a manager, users can connect to the system within the time frame specified during reservation. |
single.connect.sapm.admin | This function makes the user a Vault admin. Vault admins have rights to manage all Vault accounts and view all logs. |
single.connect.sapm.approval.requirement | This function restricts users from viewing passwords without approval. When a user wants to retrieve a Vault password, an approval email is sent to the Vault admin. After approval by the Vault admin, the user can view the password. |
single.connect.sapm.auditor | Grants the right to list all Vault accounts, without seeing details. |
single.connect.sapm.configuration.admin | Grant the right to access the Configuration section in the Vault menu. Vault configurations can be edited in this section. |
single.connect.sapm.historical.password.viewer | Grants the right to view the old passwords of Vault accounts. |
single.connect.sapm.log.viewer | Grants the right to see the “Password Change”, “New Users”, and “Password Check” logs in the Vault page. |
single.connect.sapm.moduleVisibility | Grants the right to view the Vault menu. |
single.connect.sapm.network.admin | Grants the right to manage and view all accounts that are on any device the user shares a realm with. |
single.connect.sapm.network.auditor | Grants the right to list all device accounts defined in the user's policy realms, without seeing the details. |
single.connect.sapm.secondlevel.admin | Grants the right to give second level approval for all Vault accounts and view all logs. |
single.connect.secondlevel.approval.requirement | This function restricts viewing the password without a two-level approval. |
single.connect.sapm.secondlevel.network.admin | Grants the right to give second level approval for all device accounts defined in the user's policy realms. |
single.connect.session.active.logs.moduleVisibility | Grants the right to view the Active Sessions screen in the Policy menu. Administrators can manage active proxy sessions, such as wiring to the session or killing the session. |
single.connect.sessionmanager.ui.moduleVisibility | Grants the right to view the Session Manager screen in the Administration menu. User activities can be viewed in this section. |
single.connect.setup.wizard.moduleVisibility | Grants the right to view the Kron PAM Setup Wizard screen in the Setup Wizard menu. |
single.connect.sql.proxy.moduleVisibility | Grants the right to view the SQL Proxy Policy screen in the Policy Control menu. The dynamic masking policy and masking methods are defined and managed in this section. |
single.connect.sshkeys.moduleVisibility | Grants the right to view the SSH Keys Manager screen in the User Management menu. SSH keys can be generated and managed in this section and used for logging in to the Kron PAM proxy instead of the user’s password. |
single.connect.tacacs.acc.moduleVisibility | Grants the right to view the TACACS Account Logs screen in the Logging menu. All commands executed during the TACACS+ session can be viewed in the TACACS Account Logs menu, and the user can only view their own logs. |
single.connect.tenant.admin | Kron PAM’s multitenancy function can provide multiple and independent applications and functions. It enables an architecture in which a single instance serves multiple customers. Each customer is called a tenant. Tenants may be given the ability to customize some parts of the application. This function works if the licensing requirements are met. Tenant admins can only manage devices and users that they are allowed to access and can only see the logs related to the devices and users they have access to. |
single.connect.twofactor.hardwareToken.management | Grants the right to access Hardware Token Management, and the Hardware Token Bulk Import tabs under the Multi-factor Authentication section. |
single.connect.twofactor.acc.moduleVisibility | Grants the right to view the Multi-factor Authentication section in the Administration menu. Kron PAM provides a Multi-factor Authentication by mobile application or SMS verification. |
single.connect.twofactor.assign.hardware.token | This function provides the right to assign hardware tokens in the Multi-factor Authentication section. |
single.connect.twofactor.barcode.viewer | Grants the right to see the MFA token’s QR Code or written code in the User Information section, in the right-hand upper corner of Kron PAM interface. |
single.connect.user.logs.moduleVisibility | Grants the right to view the Session Log screen in the Logging section. The user can only view their own session log records. |
single.connect.warp.configuration.viewer | Grants the right to access the Report Configuration tab in the Windows Audit Report section. In this tab, you can create a report configuration to check the security of Windows accounts. |
single.connect.warp.dashboard.viewer | Grants the right to access the Dashboard tab in the Windows Audit Report section. In this tab, you can view the reports as graphs. |
single.connect.warp.report.viewer | Grants the right to access the Report tab in the Windows Audit Report section. In this tab, you can search for reports and view them with their details. |
single.connect.windows.audit.report.moduleVisibility | Grants the right to view the Windows Audit Report screen in the Audit Report section. The Windows Audit Report is used to report the current security status of local Windows accounts. |
tfaProvisioningViewer | Grants the right to see the “User Token Management”, and the “User Group Management” tabs in the Multi-factor Authentication section under the Administration menu. You can manage user and user group tokens and OTPs (One-Time Password) for user groups. |
threat.analytics.dashboard.visibility | Grants the right to view statistics regarding threat analytics. |