When configuring CA PAM to connect to target devices, it is not unusual to have a pool of Windows Domain target accounts available to connect to Windows target devices. In some cases, you may have more users than target accounts available - what would lead your team to run out of accounts to use, specially if connecting to the same Windows Server.
To avoid one user to take over the RDP Session from another user, you can check what target accounts are in use with what target devices. This is something CA PAM administrators have available by default, but it is possible to make it available for regular users.
CA PAM 3.2 and later.
You will create a new Role in CA PAM (or edit the Roles you already created for your teams, if any) adding the privilege named "All Logging". For more info, please check our documentation:
To create a new Role:
Now you will add the new Role to your Users. To do this:
Now your users have access to the Sessions menu, with the Logs option. The image below is an example of what they will see: