Users with the built-in Session Manager role in Privileged Access Manager (PAM) encounter an "Error: PAM-UI-1005: Authorization failed. User does not have permission for this action" when attempting to terminate active connections via the GUI or REST API. This issue affects PAM from version 4.2.3 to 4.3.2 and occurs even when the role is scoped to "All Users" and "All Devices."
This is a known product defect (DE687793). The Session Manager role incorrectly requires "Monitor" or "Service Manager" privileges instead of the expected "Session Read" or "Session Manage" rights to execute the DELETE operation on active connections.
This defect will be fixed in PAM release 4.3.3 and higher (4.3.3 not published as of September 2026).
For PAM 4.3.1 or 4.3.2 environments to check if possible to obtain the patch