A user was created in Privileged Access Manager (PAM) and given the Password Manager role with a custom Credential Manager Group that uses the FirecallApprovers role. When trying to add the user to a Password View Policy, the following error occurs.
PAM-CM-1056: Password view policy approvers are not able to access the target accounts that use this policy.
The Target Group field within the Credential Manager User Group was blank, which resulted in users within that CM Group having no access to any target group.
PAM verifies that the approver is allowed to use its privileges against target accounts that use the password view policy being updated. Adding the target group scope to the user group definition resolves the problem. If approvers are meant to be able to approve any target account password requests, use target group "Targets".
Important Note: The built-in FirecallApprover role includes privilege "View Account Password". If you assign the above group to a user, the user will be able to view all target account passwords. If this is not desired, make a copy of the default FirecallApprover role on page Credentials > Manage Credential Groups > Credential Roles and remove privileges such as "View Account Password" until the role fits your use case. If you want the user to manage password views for a subset of target accounts only, define a target group on page Credentials > Manage Targets > Target Groups and configure a new target group to include the desired set of accounts only. The password view policy would have to be limited to use within this target group.
To speak with a customer representative or a Support Engineer, see . Scroll to the bottom of the page and click on your respective region.