Symantec Privileged Access Management

  • 1.  How to Set CA PAM RDP session logout time for active user?

    Posted Aug 08, 2018 02:10 AM

    Hi Team,

     

    I want to close the user session for the RDP or SSH. I have the solution for inactive session time in global setting as applet timeout, but i didn't find any solution for active user session in PAM console. So please suggest any option for this.



  • 2.  Re: How to Set CA PAM RDP session logout time for active user?

    Broadcom Employee
    Posted Aug 08, 2018 09:50 PM

    Hi Bhumesh, If I understand right, you want to kick users out of sessions after a configured time, even if they are actively working in it. PAM currently does not have such a feature. This carries the risk of interrupting important work. But interest in such a feature has been expressed in the past here, see e.g. https://communities.ca.com/ideas/235735668-disconnect-session-when-credentials-checked-in .



  • 3.  Re: How to Set CA PAM RDP session logout time for active user?
    Best Answer

    Broadcom Employee
    Posted Aug 30, 2018 03:36 PM

    only option would be to force the Checkout-Checkin PVP and set a time length and force check-in

    dont like to use Checkout-Checkin if not necessary, but... it satisfies what you need