A Service has been successfully associated with a Device Group within CA PAM, but the service does not appear on the end-user's Access page for the devices within that group.
CA Privileged Access Manager (PAM) - All Versions, AWS - Device Groups
To successfully utilize a Device Group policy for a specific service, that service must first be registered to the individual devices as a prerequisite.
Prerequisite Requirement: If an individual device does not have the service registered locally, the service configuration applied at the Device Group level will fail to take effect.
Policy Precedence: Once a service is registered to an individual device and is also applied at the Device Group level, the Device Group policy will appropriately take precedence over the local device settings.
(Note: Applying a service globally to a Device Group without first registering it to the underlying individual devices is currently unsupported. Doing so would require submitting an Enhancement Request to Broadcom.)
Bulk Registration Workaround (AWS Device Imports): When AWS devices are dynamically imported into PAM, they are added without any services registered by default. To resolve this prerequisite efficiently across multiple instances, perform a bulk CSV update:
Navigate to the Devices page in the PAM UI.
Select Export to generate a CSV file containing your list of devices and their current properties.
Open the downloaded CSV file in a spreadsheet editor (e.g., Microsoft Excel) and manually update the records to register the required service(s) to your target devices.
Save your changes and select Import to upload the CSV back into PAM. This will conveniently update all individual devices, allowing your Device Group policies to take effect.