Per-device idle timeout configuration in Privileged Access Manager (PAM)
search cancel

Per-device idle timeout configuration in Privileged Access Manager (PAM)

book

Article ID: 449205

calendar_today

Updated On:

Products

CA Privileged Access Manager (PAM)

Issue/Introduction

This article clarifies the configuration capabilities for session and idle timeouts within CA Privileged Access Manager (PAM), specifically addressing whether these timers can be applied to individual target devices or specific servers.

  • Settings: Global Settings > Basic Settings

Environment

  • Product: CA Privileged Access Manager (PAM)
  • Versions: All Supported Versions

Cause

This is a product inquiry regarding the granularity of timeout configurations for specific migration activities or device-specific requirements.

Resolution

Privileged Access Manager currently does not support the configuration of timeout values for specific target devices.
All timeout settings are global and apply to every session managed by the appliance.

Current Global Settings

The following timers are configured globally and cannot be overridden at the device or policy level:

  1. Login Timeout: Defines the maximum duration of a PAM user session.
  2. Connection Idle Timeout: Defines the maximum allowed inactivity before a target connection is terminated.

Modifying Global Timeouts

To adjust these values for all devices:

  1. Navigate to Settings > Global Settings.
  2. Select the Basic Settings tab.
  3. Update the Login Timeout or Connection Idle Timeout fields.
  4. Click Save.

Product Enhancements

If your business requirements necessitate per-device timeout controls, please submit an enhancement request (Idea) through the Broadcom Community. Product Management reviews these submissions during the release planning cycle.

Additional Information