Why does a Service associated with a Device Group fail to appear on the Access page?
search cancel

Why does a Service associated with a Device Group fail to appear on the Access page?

book

Article ID: 97311

calendar_today

Updated On:

Products

CA Privileged Access Manager (PAM)

Issue/Introduction

A Service has been successfully associated with a Device Group within CA PAM, but the service does not appear on the end-user's Access page for the devices within that group.

Environment

CA Privileged Access Manager (PAM) - All Versions, AWS - Device Groups

Resolution

To successfully utilize a Device Group policy for a specific service, that service must first be registered to the individual devices as a prerequisite.

  • Prerequisite Requirement: If an individual device does not have the service registered locally, the service configuration applied at the Device Group level will fail to take effect.

  • Policy Precedence: Once a service is registered to an individual device and is also applied at the Device Group level, the Device Group policy will appropriately take precedence over the local device settings.

  • (Note: Applying a service globally to a Device Group without first registering it to the underlying individual devices is currently unsupported. Doing so would require submitting an Enhancement Request to Broadcom.)

Bulk Registration Workaround (AWS Device Imports): When AWS devices are dynamically imported into PAM, they are added without any services registered by default. To resolve this prerequisite efficiently across multiple instances, perform a bulk CSV update:

  1. Navigate to the Devices page in the PAM UI.

  2. Select Export to generate a CSV file containing your list of devices and their current properties.

  3. Open the downloaded CSV file in a spreadsheet editor (e.g., Microsoft Excel) and manually update the records to register the required service(s) to your target devices.

  4. Save your changes and select Import to upload the CSV back into PAM. This will conveniently update all individual devices, allowing your Device Group policies to take effect.