The section is intended to work with user directory of Active Directory.
Search is located in the Users section
Enter your First Name, Last Name, Phone Number or Email in whole or in part in the search bar.
Click Extended Search and enter one or more criteria: First Name, Last Name, Phone Number or Email in whole or in part.
The profile displays the data of an Active Directory user:
Username — the name used to login to the system.
Path — LDAP.
Email — email address.
Phone — user phone number.
Photo — user photo from Active Directory (thumbnailPhoto attribute).
|
The user permissions are displayed in the Permissions tab.
The following data is displayed for every permission:
All groups in which user is a member will be listed here.
All active and finished sessions of the user are available in the Sessions tab.
The following data is displayed for every session:
To view detailed information about the session, you must click on it. To show all sessions for this user, click Show all.
The user authenticators and corresponding settings are displayed in the Authenticators tab. You can change the 2fa requirement setting here to enable, disable or use defaults. To change requirement setting:
The user events are displayed in the Events tab.
The following data is displayed for every event:
Creation time — date and time when the event was created.
Code — is the event code.
Event — is the event description.
Component — is the Axidian Privilege component that generated the event.
Initiator — is the account that initiated the event generation.
To view detailed information about the event, you must click on it. To show all events for this user, click Show all.
This feature helps PAM administrator to quickly close user’s access to the resources. At the same time, there is no need to change resources and accounts.
A blocked user is unable to:
At the moment a user is blocked, all active sessions are closed.
Block a user if you notice suspicious actions from them. This allows you to quickly close user’s access to the resources until the circumstances are clarified. You can unblock a user as quickly as block them. |
To block a user:
Do not use this feature to close access to former employees. They will still be able to authenticate to the user console and the administrator console (if access was available). When employees leave, remove users from Active Directory. |
To unblock a user: