23.1 Privileged Sessions

In Privileged Sessions, you can view all the privileged sessions that you are entitled to access either through policies or emergency access approval. You can click on the required privileged session and start the session based on the type of the session. There are different tabs for each type of session. The following lists the details of each tab:

23.1.1 Windows

The Windows tab lists all the privileged sessions that are created for access to a Windows server or desktop. This includes policy created for a remote desktop session with specific privileges and request of type RDP. If you have requested for an RDP session through emergency access, then you also get emergency access to credential provider.

To start a session from the Windows tab, perform the following:

  1. In Privileged Sessions, click the Windows tab.

  2. Click on the required policy depending on which server you want to connect to.

  3. On the Remote desktop client dialog box, click Connect.

    NOTE: RDP Relay is supported only on Internet Explorer 9.0 or later.

Starting Remote Desktop Connection with Credential Provider

To start a remote desktop connection by using credential provider, you must save the properties for remote session to that machine.

Perform the following to save the properties of a particular remote desktop connection:

  1. Click on Remote Desktop Connection client.

  2. Type the IP address of the target machine.

  3. Click Options then click Save to save the Remote Desktop connection to the RDP file.

    Specify the location and filename for the RDP file to display the Remote Desktop Connection icon on that location.

  4. Add the following value to the saved Remote Desktop Connection properties by using any xml editor and save the file:

    enablecredsspsupport:i:0

  5. Start the saved Remote Desktop Connection client.

    For subsequent sessions you can just click on the saved Remote Desktop Connection icon.

    NOTE:Ensure that you provide the user name in capital letters.

23.1.2 SSH

The SSH tab lists all the privileged sessions that are created, and also lists the approved requests for an SSH relay session. When you click on any of these privileged sessions, a JAVA Webstart program will then launch the downloaded JNLP file, which will then launch the JAVA UI.

23.1.3 Database

The Database tab lists all the privileged sessions that are created, and also lists the approved requests for a database session. When you click on any of these listed privileged sessions, you need to fill the password checkout page. The Privileged Account Manager provides database credentials, which you can use to connect to the database server.

23.1.4 Applications

The Applications tab lists all the privileged sessions that are created, and also lists the approved requests for an application session. When you click on any of these listed privileged sessions, you need to fill the details in the password checkout page to checkout the credentials for the application server. The Privileged Account Manager provides the application credentials, which you can use to connect to the application server.

23.1.5 Keys

The Keys tab lists all the privileged sessions that are created for a key check out. When you click on any of these listed privileged sessions, you need to fill the details in the password checkout page to checkout the credentials of a key. The Privileged Account Manager provides the shared key credential, which you can use wherever required.

23.1.6 Cloud Services

The Cloud Services tab lists all the privileged sessions that are created for the cloud service key check out. When you click on any of these listed privileged sessions, you need to fill the details in the password checkout page to checkout the credentials of the cloud services Openstack or Amazon Web Services (AWS). The Privileged Account Manager provides the cloud service credential, which you can use to access the service.