Privileged account manager, dynamic policy engine
First Claim
1. A system, comprising:
- a memory storing a plurality of instructions; and
one or more processors configured to access the memory, wherein the one or more processors are further configured to execute the plurality of instructions to;
receive a perspective selection for viewing multiple accounts based at least in part on user-defined tags assigned to registered accounts to display on a user device in a user-defined hierarchical view, the perspective providing an ability to create the user-defined tags to describe the accounts;
receive account information that identifies a plurality of different types of accounts associated with different types of target systems external to the system that are managed by an account management service of the system, the plurality of accounts for accessing resources used by the associated target system;
receive role information that identifies a role of at least one of the plurality of accounts;
organize one or more of the plurality of accounts together in a group based at least in part on the role for each of the one or more of the plurality of accounts, the group being formed by the perspective selection and a policy manager;
assign a grant to the group based at least in part on grant information for the group, the grant information identifying at least one of access rights or privileges; and
update each account in an account group associated with a user role if a grant policy for the user role changes.
1 Assignment
0 Petitions
Accused Products
Abstract
Techniques for managing accounts are provided. An access management system may check out credentials for accessing target systems. For example a user may receive a password for a period of time or until checked back in. Access to the target system may be logged during this time. Upon the password being checked in, a security account may modify the password so that the user may not log back in without checking out a new password. Additionally, in some examples, password policies for the security account may be managed. As such, when a password policy changes, the security account password may be dynamically updated. Additionally, in some examples, hierarchical viewing perspectives may be determined and/or selected for visualizing one or more managed accounts. Further, accounts may be organized into groups based on roles, and grants for the accounts may be dynamically updated as changes occur or new accounts are managed.
94 Citations
20 Claims
-
1. A system, comprising:
-
a memory storing a plurality of instructions; and one or more processors configured to access the memory, wherein the one or more processors are further configured to execute the plurality of instructions to; receive a perspective selection for viewing multiple accounts based at least in part on user-defined tags assigned to registered accounts to display on a user device in a user-defined hierarchical view, the perspective providing an ability to create the user-defined tags to describe the accounts; receive account information that identifies a plurality of different types of accounts associated with different types of target systems external to the system that are managed by an account management service of the system, the plurality of accounts for accessing resources used by the associated target system; receive role information that identifies a role of at least one of the plurality of accounts; organize one or more of the plurality of accounts together in a group based at least in part on the role for each of the one or more of the plurality of accounts, the group being formed by the perspective selection and a policy manager; assign a grant to the group based at least in part on grant information for the group, the grant information identifying at least one of access rights or privileges; and update each account in an account group associated with a user role if a grant policy for the user role changes. - View Dependent Claims (2, 3, 4, 5, 6, 7, 8, 9)
-
-
10. A computer-implemented method, comprising:
-
receiving, by a computer system, a perspective selection for viewing multiple accounts based at least in part on user-defined tags assigned to registered accounts to display on a user device in a user-defined hierarchical view, the perspective providing the ability to create the user-defined tags to describe the accounts; receiving, by the computer system, account information that identifies a plurality of different types of accounts associated with a plurality of different types of target systems external to the system that are managed by an account management service of the system, the plurality of accounts for accessing resources used by the associated target system; receiving, by the computer system, role information that identifies a role for at least one of the plurality of accounts; forming, by the computer system, a group of the plurality of accounts based at least in part on the role information, the group being formed by the perspective selection and a policy manager; assigning, by the computer system, a grant policy to the group of the plurality of accounts based at least in part on grant information for the group, the grant information identifying at least one of access rights or privileges; and updating each account in an account group associated with a user role if the grant policy for the user role changes. - View Dependent Claims (11, 12, 13, 14, 15, 16)
-
-
17. A computer-readable memory storing a plurality of instructions executable by one or more processors, the plurality of instructions comprising:
-
instructions that cause the one or more processors to receive a perspective selection for viewing multiple accounts based at least in part on user-defined tags assigned to registered accounts to display on a user device in a user-defined hierarchical view, the perspective providing an ability to create the user-defined tags to describe the accounts; instructions that cause the one or more processors to receive account information that identifies a plurality of different types of accounts associated with a plurality of different types of target systems external to a system that is managed by an account management service of the system; instructions that cause the one or more processors to receive, from an administrative account of the account management service configured to manage the plurality of accounts associated with the plurality of target systems, role information that identifies a role for at least one of the plurality of accounts; instructions that cause the one or more processors to form a group of the plurality of accounts based at least in part on the role information, the group being formed by the perspective selection and a policy manager; instructions that cause the one or more processors to assign a grant policy to the group of the plurality of accounts based at least in part on grant information for the group, the grant information identifying at least one of access rights or privileges; and instructions that cause the one or more processors to update each account in an account group associated with a user role if the grant policy for the user role changes. - View Dependent Claims (18, 19, 20)
-
Specification