Error PAM-CM-0553 Authorization Failed when using PAM API for Target Accounts
search cancel

Error PAM-CM-0553 Authorization Failed when using PAM API for Target Accounts

book

Article ID: 445367

calendar_today

Updated On:

Products

CA Privileged Access Manager (PAM)

Issue/Introduction

When attempting to use the PAM REST API endpoint: api.php/v1/devices.json/{deviceid}/targetApplications/{appid}/targetAccounts

The request fails with a 400 Bad Request or 403 Forbidden, and the following error is returned in the API response or found in the Tomcat (catalina.out) logs:

"message": "Bad Request: PAM-CMN-0467: A Password Authority problem prevented completing the request. Message: PAM-CM-0553: Authorization failed. User {0} does not have permission for this action. Not authorized on all objects."

Cause

Target Group Scope: The user’s Credential Management Group is not scoped to a Target Group that includes the specific application or target account being requested.

Resolution

Verify Credential Management Group Membership

  1. Navigate to Credentials > Manage Groups.
  2. Edit the CM User Group that the API user belongs to.
  3. Check the Target Groups tab.
  4. Ensure that the group includes the targets you are trying to query