AWS console access from PAM
search cancel

AWS console access from PAM

book

Article ID: 100928

calendar_today

Updated On:

Products

CA Privileged Access Manager - Cloakware Password Authority (PA) CA Privileged Access Manager (PAM)

Issue/Introduction



When configuring AWS console access through PAM via the following should there be a device called "capam.aws.amazon.com" for step 4?

https://docops.ca.com/ca-privileged-access-manager/3-2/EN/deploying/deploy-on-an-aws-amazon-machine-image-ami/configure-ca-privileged-access-manager-for-aws#ConfigureCAPrivilegedAccessManagerforAWS-CreateanAWSManagementConsoleAccessPolicy

1.  From the UI, select Policies, Manage Policies.
2. Click Add.
3. In the User or User Group field, enter super.
4. In the Device or Device Group field, enter capam.aws.amazon.com
5. On the Services tab, select AWS Management Console SSO [AWS Access Credential Accounts – cademo – PowerUserAccess]
6. On the Recording tab, select Web Portal and On Violation.
7. Click Save.

Environment

Release:
Component: CAPAMX

Resolution

This appears to be a typo in the documentation, the AWS device should be there by default. The device is 'xceedium.aws.amazon.com' under Devices > Manage Devices.