Password Access Control Workflow |
Term | Description |
---|---|
Request |
The user has to make a request to view the password. |
Waiting for Approval |
User's password release request is pending with administrator(s) for approval. |
Check Out |
Administrator has approved the request and the user can view the password. |
Approve/Reject |
Administrator can either approve or reject the password request. |
Yet to Use |
Indicates that the user is yet to view the password released by the administrator. |
In Use |
Password is being used exclusively by a user. |
Check In |
Giving up/revoking password access. |
Password Manager Pro provides a password access control mechanism that allows administrators to grant password access to users for a specific period. Admins can start granting exclusive privileges once a password is ready to share, and only one user is allowed to use a particular password at a single point of time.
You will learn the following topics concerning Password Access Control workflow in this document:
3.1 Implementing Access Control at Resource level
3.2 Implementing Access Control at Account level
3.3 Viewing Access Control Details
Once the password access control is enforced for a resource or an account, the following workflow is invoked for password access attempt by the users:
Note: The access control workflow does not override the password ownership and sharing mechanism of Password Manager Pro. Rather it is only an enhanced access control mechanism. Normally, when a password is shared with a user, the user will be able to view the password directly. Now, with the password access control mechanism, the user will have to request access to a password, even if they have access to it.
Account level access control configuration takes higher precedence over Resource level access control configuration as explained below in detail:
Follow the below steps to implement password access control for a resource or an account:
3.1 Implementing Access Control at Resource Level
3.2 Implementing Access Control at Account Level
3.3 Viewing Access Control Details
With Access Control at account level, it is possible to set password access control independently for each account under a resource, without affecting the access control configurations of other accounts in the resource. This ability to set unique configurations for each account helps users maintain unparalleled security levels for each account, based on requirements.
Follow the below steps to implement access control for accounts:
Designate the administrator(s) as the approvers of password release requests. The list of all administrators, password administrators, and privileged administrators in the system are listed in the left pane. You can designate as many administrators as you wish for a particular resource or an account. Anyone from the list of Authorized Administrators could approve the requests raised by users.
Exclude a set of users from the access control workflow using this option. The excluded users will be able to access passwords directly without raising requests.
Note: You can also designate user group(s) as approvers for password release requests. When a user group is designated as an approver, all the users with admin rights within that group (the administrators, password administrators, privileged administrators and admin users with the custom role) are given access rights. If you have enforced approval by a particular number of administrators, say 5, then the authorized user group must have at least 5 valid administrators.
Once Access Control is activated for an account or a resource, the Access Control Details option consolidates all the settings applied and provides it in a single window for easy perusal. Please note that the Access Control Details window can be accessed from the Account Actions menu only. Follow the below steps to view the access control details:
Note: Users can choose the required resources in the domain account and request permission to access them. Users will be able to access only the approved resources using that domain account.
The following are some of the use case scenarios in which access control workflow will be useful in an organization.
To access a password protected by the access control workflow, a user will have to request the administrator to grant permission to view the password.
If you're an administrator and a user has requested your approval to view a password, you will receive an email notification about the request. You can view all the requests pending your approval from the Admin tab.
Steps to Approve a Request:Note: If a password access request is rejected by an admin in the above scenario, the request will be removed from the queue.
Steps to request a password:
Note: Users can choose the required resources in the domain account and request permission to access them. Users will be able to access only the approved resources using that domain account.
To Approve a Request:
The crux of the access control mechanism is that the user will be allowed only temporary access to passwords. So, once the user finishes their work, they can give up the password.
To Give Up Access to the Password:Access control mechanism allows exclusive access privilege to a user for a specified time period. During this period, no one else will be allowed to view the password, including the owner. In case an emergency arises to revoke the exclusive permission to the user, administrator can forcefully check in the password at any point of time.
Once a password is checked out by a user, it will be checked in due to any of the following three reasons:
When password is checked in, if the admin settings require automatic password reset, Password Manager Pro will try to reset the password. In case Password Manager Pro is not able to reset the password in the actual resource, Password Manager Pro will immediately trigger email notifications to the administrators who approved the password access request of the use so that they can troubleshoot and set things right. The password reset failure will also reflect on the audit trails.
Password Manager Pro provides an option to create scheduled tasks for automatic and periodic password resets. It is possible that a scheduled task starts executing the reset of a password that is currently checked out by a user. If that reset task is allowed to execute successfully, the user will be working with an outdated password. To avoid such password mismatch issues, Password Manager Pro will prevent the reset of that password alone while all other passwords of other resources that are part of the scheduled task will be reset. The failure to reset the exempted password during the password reset schedule will reflect on the audit trails.
As an administrator, if you want to disable access control for any resource or an account, you may do so at any time as explained below.
Note: Deactivating the Resource level access control will not affect any Account level access control configuration enforced on the accounts belonging to that resource.
Now, the Access Control for the selected resources or accounts is deactivated. So, any user who has permission to view a password (owned/shared) can directly view the password without going through the access control process.
Note: If Account level access control is deactivated and there is a Resource level access control already in place for the resource, then the Resource level access control will be automatically applied to the account as well. Click here to read more about how precedence works for access control settings.
When an administrator leaves the organization or moves to a different department, resources/ accounts owned by that administrator are transferred to some other administrator. If the departing administrator had acted as the approver for password release requests, the approval privileges should also be transferred. All the resources and accounts that were earlier controlled by one admin can be easily transferred in bulk to another admin. Follow the below steps to learn how to transfer approver privileges from one administrator to another.
By default, Password Manager Pro has predefined templates for access control dialog boxes such as Password Request, Password Check In, Password Check Out. Using message templates, the administrators will be able to alter the messages in access control workflow dialog. To customize the messages in access control dialog:
The password access control workflow in Password Manager Pro currently presents a compatibility issue when it comes to High Availability secondary servers. If the primary server becomes unavailable, Password Manager Pro users won't be able to utilize the password access control workflow.
To solve this, administrators can use a workaround solution, though it needs careful tracking of approved requests in that timeframe. Here's how to use the password access control workflow when the primary server is down:
Upon the primary server's restoration, the automated check-in will not work efficiently for the resources checked out from the secondary server during the interim time. So, it becomes the administrator's responsibility to review manually and check-in the resources that were checked out during the interim period.
©2025, ZOHO Corp. All Rights Reserved.