Certain commands in Unix are extremely powerful in terms of their magnitude of effect. Misuse of such commands may hamper development, maintenance, production or else create a security threat for confidential information. Sectona PAM provides a solution with its Server Access Policy wherein you can restrict or allow the usage of certain commands for specific User Groups. You can choose these commands from the existing library or add to the Command Repository

Procedure:

  1. Navigate to Policies on the top navigation bar. 
  2. Select Server Access Policy from the sidebar. 
  3. Click on the Unix section. 
  4. Click on +Add Server Access Policy. Fill in the essentials (Policy details, User Groups and Parameters) in the form that appears.
  5. Under Policy Type: (a) choose Allow if you want to allow the user group access only for particular commands.  
                                  (b) choose Deny if you want the user group to abstain from accessing certain commands.
  6. Click on Next.
  7. Select the User Group(s) to whom the policy should apply. If you want to except some users belonging to the selected groups, you can mention them in the Exception User(s) field.
  8. Click on Next.
  9. Under Parameters, choose the commands you want to allow/deny access to. 
  10. Click on Next. Verify the policy details and click on Finish.

                              

Refer here if you want to set an expiry date for a Server Access Policy.

There is no content with the specified labels