Before You Begin
Perform the following steps in BeyondTrust Password Safe:
Create an Application User
- Create a dedicated application user in BeyondTrust to be used by Commvault.
Configure a User Group
-
Create a new user group for the application user.
-
In Group Details, enable the following features with Read-Only permissions:
- Password Safe Account Management
- Password Safe Configuration Management
Note
These permissions allow Commvault to use APIs to look up credential accounts.
Define Smart Rules and Smart Groups
-
Configure Smart Rules for the specific assets and managed accounts whose credentials Commvault should access.
-
Add these assets/accounts into Smart Groups.
-
Associate these Smart Groups with the Commvault application user group.
Configure PAM access Policy
-
Create a PAM access policy for the Commvault application.
-
Enable the View Password and Auto Approve options.
Note
These options are set at the PAM access policy configuration level.
-
Assign the application user group to the Requestor role.
-
Link the access policy to the Requestor role.
Enable API access for managed accounts
- For every managed account that Commvault will access, make sure API access is enabled. This setting must be turned on at the individual managed account level.
Collect connection information
-
Note down the following details to be used in Commvault while adding the BeyondTrust credential vault:
- BeyondTrust Password Safe URL
- Application User credentials (Client ID, Client Secret if applicable)
- Name of Smart Groups and access policy created for Commvault.
Procedure
-
From the navigation pane, go to Manage > Security.
The Security page appears.
-
Click the Credential vault tile.
The Manage credentials page appears.
-
Click the Vault configuration tab, and then click Add from the upper-right corner of the page.
The Add credential vault dialog box appears.
-
From the Vendor list, select BeyondTrust, and then enter the following information:
-
Name: Enter a unique name for the BeyondTrust credential vault.
-
Server URL: Enter the URL of the BeyondTrust Password Safe server.
-
Client ID: Enter the client ID created in BeyondTrust.
-
Client secret: Enter the client secret corresponding to the client ID.
-
Access nodes: Displays the default node that can access the BeyondTrust vault. You can select other nodes from the list.
-
Description: Enter a short description for the BeyondTrust credential vault.
-
-
Click Save.