Sharing and Permission Levels in PAM3605 minutes to read
PAM360 offers a flexible and granular control mechanism for sharing accounts, resources, and resource groups with other users or user groups. When a resource or resource group is shared, all associated accounts within that resource or group are automatically included in the shared access. To maintain strict control over privileged accounts, administrators can define diverse granular permission levels over accounts, resources, and resource groups, ensuring that users only interact with shared passwords based on their assigned permission level. By leveraging PAM360’s sharing capabilities, organizations can:
1. Permission Level for Sharing Privileged ResourcesAdministrators can customize access permissions for individual users or user groups, aligning with operational requirements. PAM360 provides the following permission levels to manage privileged accounts securely:
Notes:
2. How Precedence Works for Permission Levels?PAM360 enforces a strict permission hierarchy to ensure that access to privileged accounts remains granular and secure. When multiple levels of permissions are assigned at the account, resource, or resource group level for a same account, certain rules determine which permission takes precedence. Below are the key principles governing PAM360’s permission hierarchy:
| ||||||||