Shared accounts in Evo are known as Elevated Access accounts.
An elevated, or privileged access account is an account that has more privileges than ordinary users. The elevated account, might be able to install/remove software, upgrade operating systems, or modify system/application configuration. They might also have access to files that are not accessible to a regular user.
How to add a shared directory account
Shared elevated access accounts created from a directory, will only be possible for an Active Directory (On-Premise or Azure) that has been connected to sync with Evo.
Didn’t enable the new account(s) for password rotation? Not to worry, you can do that at any time, see How do I enable, or disable password rotation?
- From the top navigation, click Professional Services.
- Click Privileged Access Management.
- Click Elevated Access.
- With the Shared Accounts tab selected. In the displayed list of tenants, find the one the new shared account should be added. Click the tenant’s name.
- Click Add Shared Accounts.
- Click Select from Synced Directory.
- In the displayed list of directories, find the one you want to associate. Select the radio button for the directory.
- Click Next Step.
- Enter in the email address of the user. Once located click Add.
- Skip if the correct user has been applied. If you’ve selected the wrong user, hover over the email address and click the trash can to delete. Repeat step 10 to add the correct user(s).
- Click Next Step.
- Optionally, switch the toggle to enable password rotation for the new account.
- If you have toggled password rotation on.
- Select the rotation frequency:
- Hours: Use the slider to select the rotation frequency. Anywhere between 1-hour to 24-hours.
- Days: Use the slider to select the rotation frequency. Anywhere between 1-day to 30-days.
- Select the rotation frequency:
- Click Add Shared Accounts.
Repeat steps 5 to 14 for each tenant where a shared account is to be added.
Now that the new shared account has been created, you’ll need to assign it to a group for use. Refer to How do I add, edit, or delete an access group?
The first password rotation can take up to 10-minutes to complete. Until that happens the existing password you have set on the shared account remains in effect. Once the password rotation is completed. You’ll be able to view the new password from the table, refer to Can I see the shared account passwords?
How to manually add a shared account
Tip: To confirm the entered password is correct, click the eye () in the password field to see what you’re typing in plain text. To hide the password, click the eye (
) again.
- From the top navigation, click Professional Services.
- Click Privileged Access Management.
- Click Elevated Access.
- With the Shared Accounts tab selected. In the displayed list of tenants, find the one the new shared account should be added. Click the tenant’s name.
- Click Add Shared Account.
- Click Add Manually.
- Fill in the appropriate detail
- Enter the email address or username for the shared account.
- Enter a password for the shared account.
- Optionally, enter a domain.
- Click Add Shared Accounts.
Repeat steps 5 to 8 for each tenant where a shared account is to be added.
Now that the new shared account has been created, you’ll need to assign it to a group for use. Refer to How do I add, edit, or delete an access group?
How to edit a shared account
Editing shared account is limited to the type of account that was added.
- A shared account created from a synced directory you can update the password rotation frequency or enable/disable password rotation.
- A manually created shared account, you can update the shared account, password, and domain.
- From the top navigation, click Professional Services.
- Click Privileged Access Management.
- Click Elevated Access.
- With the Shared Accounts tab selected. In the displayed list of tenants, find the one the new shared account should be added. Click the tenant’s name.
- Click the edit pencil at the end of the row for the shared account to be edited.
- Make the edits you want.
- Click Edit Shared Account.
Comments
0 comments
Please sign in to leave a comment.