We are trying to restrict PAM user to access only Device/Group Manager role. However, creating a device using that Device/Group Manager role user causes the following error
PAM-CMN-1599: User Device tried to add target server test1010 without authorization
Here is how the Role has been configured and All Devices scope is also specified.
Privilege Access Management 4.2.x
"Password Management" device type is selected when creating the device.
When creating a device, please ensure that the "Password Management" device type is not selected on the "Basic Info" page. This is because users with the "Device/Group Manager" role do not have the necessary privileges to perform password management tasks.