×

Privileged account manager, dynamic policy engine

  • US 9,390,255 B2
  • Filed: 05/31/2012
  • Issued: 07/12/2016
  • Est. Priority Date: 09/29/2011
  • Status: Active Grant
First Claim
Patent Images

1. A system, comprising:

  • a memory storing a plurality of instructions; and

    one or more processors configured to access the memory, wherein the one or more processors are further configured to execute the plurality of instructions to;

    receive a perspective selection for viewing multiple accounts based at least in part on tags assigned to registered accounts to display on a user device in a user-defined hierarchical view;

    receive information that identifies a plurality of different types of accounts associated with a different type of target system external to the system that is managed by an account management service of the system, the plurality of accounts for accessing resources used by the associated target system;

    receive a role of at least one of the plurality of accounts;

    organize one or more of the plurality of accounts together in a group based at least in part on the role for each of the one or more of the plurality of accounts, the group being formed by the perspective selection and a policy manager;

    assign a first grant to the group based at least in part on received grant information for the group, the grant information identifying access rights and privileges of users, accounts, groups of the users, or groups of the accounts;

    identify a new account of the plurality of accounts that corresponds to the role, the new account being associated with at least a second grant that is different from the first grant;

    add the new account to the group based at least in part on a request from an administrative account of the account management service; and

    update privileges of the group to include the second grant based at least in part on adding the new account to the group.

View all claims
  • 1 Assignment
Timeline View
Assignment View
    ×
    ×