Password Vault Group
To view the Vault accounts in a tree structure and to set group-based permissions, Password Vault accounts can be grouped.
Adding accounts to groups can be made mandatory by adding the following parameter in the System Configuration Manager:
Parameter Name | Parameter Value |
|---|---|
sapm.group.required | true |
Password Vault Groups are created in a tree structure. Users with portal rights can view the created groups or create Password Vault Groups themselves. The ability to create a Password Vault Group is specific to the user. If other user groups are given permission, users belonging to these can also see it.
The unique format for Vault accounts is provided as AccountName@/GroupFullPath. Since the @ character is used as a separator in this structure, its use is prohibited when creating Vault groups.
In addition, users can be permitted to create a Parent Group or only a Sub-group. The reason for this distinction is that Password Vault management can be done entirely by admins, or end users can manage their groups. Therefore, the following parameter is defined in the System Configuration Manager.
Parameter Name | Parameter Value |
|---|---|
sapm.create.parent.group.right | true |
Password Vault Groups with the same name can be created at different levels in the tree structure. For each Password Vault Group to be unique, case sensitivity can be ensured with the following parameter in the System Configuration Manager:
Parameter Name | Parameter Value |
|---|---|
sapm.allow.case.insensitive.group.name | false |
The following portal functions are used for Password Vault Group rights:
- Password Vault Groups Module Visibility: User group members have the right to see the Vault tab. Account and group-related rights should be given individually.
- SAPM Group Manager: User group members have the right to see the Vault tab as well as the right to add new groups. Account and group-related rights should be given individually.
- SAPM Group System Manager: User group members have the right to see the Vault tab as well as the right to add new accounts, groups, or sub-groups. Account and group-related rights should be given individually.