Password Retrieval Second-Level Approval Notifications
A two-level approval mechanism can be set up for the desired user groups with a Device Group Realm that contains the device where the Vault account originates from. These user groups should have the SAPM Second Level Approval Requirement function group defined in their Portal Functions Realm. To do so, follow these steps:
- Navigate to Policy > Portal Functions.
- Set the realm between the SAPM Second Level Approval Requirement function group and the user group of the user that will need the second-level approval.
When a user who requires two-level approval attempts to retrieve an account password, a Vault Password Approval Request email is sent to the users listed below:
- User groups with the FULL_CONTROL permission over the Vault Account that requested the approval.
- User groups with the single.connect.sapm.admin and the single.connect.sapm.network.admin portal functions
single.connect.sapm.admin | Grants the right to manage all Vault accounts and view all logs. |
|---|---|
single.connect.sapm.network.admin | Grants the right to manage and view all Vault accounts of devices the user has access to via device realm settings. |
To set up managerial approval for account password retrieval:
- Navigate to Policy > Portal Functions.
- Set the function realm containing the SAPM Admin function group and the user group of the user that should be able to provide first approval for all password retrieval requests AND/OR Set the function realm containing the SAPM Network Admin function group and the user group of the user that will be able to provide first approval for all password retrieval requests related to the devices in their Device Group Realms only.
If a user fitting any of the above criteria approves the initial request, a Password Vault Approval Request email is sent to the second-level approvers, who are:
- Members of user groups with the single.connect.sapm.secondlevel.admin and single.connect.sapm.secondlevel.network.admin portal functions.
single.connect.sapm.secondlevel.admin | Grants the right to give second-level approval for all password vault accounts and view all logs. |
|---|---|
single.connect.sapm.secondlevel.network.admin | Grants the right to give second-level approval for all Vault accounts of devices the user has access to via device realm settings. |
To set up two-level managerial approval for Account password retrieval:
- Navigate to Policy > Portal Functions.
- Set the function realm containing the SAPM Second Level Admin function group and the user group of the user that should be able to provide second approval for all password retrieval requests AND/OR Set the function realm containing the SAPM Network Admin function group and the user group of the user will be able to provide second-level approval for all password retrieval requests related to the devices in their Device Group Realms only.
If a user from these lists approves the second-level request, the requester receives an email and can proceed to password checkout.
If any of the authorizers deny the request, informational emails are sent to all participants, and the request is terminated.