

Troubleshooting Guide › Troubleshooting SAM › Break Glass Approval Workflow
Break Glass Approval Workflow
Symptom:
I want to configure a single-step break-glass workflow to verify that the SAM endpoint system administrator that the request applies to is notified and not the user manager.
Solution:
You can configure a single step, break glass workflow to specify that break glass requests are approved by the system administrator and not by the default approver.
Follow these steps:
- In CA ControlMinder Enterprise Management, select Users and Group, Tasks, Modify Admin Tasks.
The modify admin task: select task search window opens.
- Select Category from the pull-down menu and enter *home* in the text box area. Click Search.
CA ControlMinder Enterprise Management displays the tasks that correspond with the search criteria.
- Select the Break Glass WF task, then click Select.
The Break Glass WF properties window opens.
- Navigate to the Events tab and click the right pointing arrow.
The workflow mapping window opens.
- Select SingleStepApproval from the Workflow Process pull-down menu.
- Do the following in the Primary Approver section:
- Select Approve Break Glass Privileged Account from the Approval Task pull-down menu.
- Select Custom: PrivilegedAccountOwnerResolver from the Participant Resolver pull-down menu.
A message appears, informing you that participant resolver configuration parameters are not set.
- Specify SourceObject in the New Parameter Name text box.
- Specify TaskAdmin in the Value text box.
- Click Add Parameter.
CA ControlMinder Enterprise Management adds the approver task.
- Repeat steps c through e, using the following parameter name and values:
- SourceObjectAttribute—tblUser.manager
- TargetType—USER
- Click OK.
You have configures a single step break glass workflow and defined the system administrator as an approver.
Copyright © 2013 CA Technologies.
All rights reserved.
 
|
|