For the complete documentation index, see llms.txt. This page is also available as Markdown.

Configure and Elevate Access for a PAM Machine

Configure JIT elevation and workflow settings for a PAM Machine record.

Overview

This guide shows how to use a PAM Machine record to grant just-in-time elevated access to a machine through the configured identity provider.

After the record is shared and the JIT and Workflow settings are configured, users can request access, receive temporary group-based elevation for the approved time window, and launch the machine without permanent standing privilege.

Use this setup when access to a server or VM must be approved, time-bound, and fully auditable.

Configure and Share the PAM Machine Resource

In the example below, a PAM Machine record is configured to grant elevated access through the identity provider. Select Edit in PAM Settings to configure Workflow and JIT.

See SSH Connections for more detailed configuration information

JIT Settings

JIT settings define how access is granted after approval. In this example, the record uses group-based privilege elevation. If the machine authenticates through an identity provider, enable authentication through the identity provider. The group name must match the corresponding group in the identity provider. After approval, the user receives temporary elevation for the configured duration. Role-based elevation is not supported through identity-provider elevation at this time.

Workflow Settings

Workflow settings define the approval controls for the record. In this example, the record requires approval and limits access to 1 hour. When the access window ends, any active session closes and the temporary elevation is removed. You can also require a reason and ticket number with each request.

See Workflow for more information.

Requesting Access

Once the PAM Machine record is shared and JIT and Workflow settings are configured, the user can submit an access request from the Keeper Vault or from Commander.

See Access Workflow for a full workflow.

Last updated