×

Privileged account manager, dynamic policy engine

  • US 9,667,661 B2
  • Filed: 06/10/2016
  • Issued: 05/30/2017
  • Est. Priority Date: 09/29/2011
  • Status: Active Grant
First Claim
Patent Images

1. A system, comprising:

  • a memory storing a plurality of instructions; and

    one or more processors configured to access the memory, wherein the one or more processors are further configured to execute the plurality of instructions to;

    receive a perspective selection for viewing multiple accounts based at least in part on user-defined tags assigned to registered accounts to display on a user device in a user-defined hierarchical view, the perspective providing an ability to create the user-defined tags to describe the accounts;

    receive account information that identifies a plurality of different types of accounts associated with different types of target systems external to the system that are managed by an account management service of the system, the plurality of accounts for accessing resources used by the associated target system;

    receive role information that identifies a role of at least one of the plurality of accounts;

    organize one or more of the plurality of accounts together in a group based at least in part on the role for each of the one or more of the plurality of accounts, the group being formed by the perspective selection and a policy manager;

    assign a grant to the group based at least in part on grant information for the group, the grant information identifying at least one of access rights or privileges; and

    update each account in an account group associated with a user role if a grant policy for the user role changes.

View all claims
  • 1 Assignment
Timeline View
Assignment View
    ×
    ×