Since only a user can be selected in the Email Notification panel in a Password View Policy, a local user is being configured in PAM so a distribution list can receive emails when a password is viewed. How can the user be configured to be receive the PVP emails with the minimum amount of privileges?
Prior to configuring the user, first go to Credentials > Manage Credential Groups > Credential Roles create a custom role with the Get User and Update Password View Request Status privileges. Next, go to Credentials > Manage Credential Groups > Credential Groups and create a group with the role and leave the Group fields blank.
Once the CM role and user group have been created, the user can now be configured. Go to Users > Manage Users and click Add to create the user. Provide only the Password Manager role in the Roles tab, then go to the Credential Manager Groups tab and add the newly created CM group.
Now go to the PVP and the user will be available in the Email Notification tab.