You have a group of users who should be able to update/reset the password of a set of target accounts, which you can define in a static or dynamic target group. You need to know the minimum set of Credential Management privileges required to allow this activity.
The following set of seven privileges is the minimum required for a PAM user to edit a target account from the Credentials > Manage Targets > Accounts page, enter a new password and save it:
The user needs to be assigned the Password Manager role with a CM group that is assigned the target group containing the list of target accounts the user is meant to be able to update, and a role that includes the above privileges.
Depending on your use case you may need to include the following additional privileges:
With the additional privileges the Credential Manager role would look as follows:
In a multi-site cluster users need to log on to a primary site node to perform password update activities. On secondary site nodes the Credentials > Manage Targets > Accounts page will show the list of target accounts, but the accounts cannot be updated.