Skip to main content

Example Password Vault PEP

Password Vault Policy Enforcement Point

Use case example

We want to define a policy to restrict access to the Soffid Password Vault.

The users who are assigned to the SOFFID_ADMIN role (from this point forward: end-users) will have limitations to perform some actions on the folder "demoFolder" of the Soffid Password Vault

  1. The end-users only be able to access the accounts of that folder on labour time. The permissions will be denied in other case.

Policy set

WeFirst of all, we define a policy set thatwhich willcould applycontain another policy sets and policies.

image-1628240486192.png

 

Policy set 2

Then, we can create another policy set as child of the former to usersmanage who have been assigned a specific role in order to access to a specific vaultthe folder and to define the accountssubject, saved atin that folder.case users with SOFFID_ADMIN role assigned.

image-1628146516248.pngimage-1628240781296.png

That policy set will include a policy aboutcontain the time to access and other policy about specific user restricctions.policies.

image-1628146662661.pngimage-1628240820879.png

Policies

Policy 1

ThatThe policyend-users only be able to access the accounts of that folder on labour time. The permissions will be denied in other case.

image-1628240889871.png

Rule 

We define the periodrule ofthat timepermit in which the user could connectaccess to the resources.end-user  

image-1627986571853.png

Rules

The Labour time rule will allow access between two specific hours.

image-1627986753840.pngimage-1628241172154.png

TheAnd we define other rule willto deny access.

image-1627986800434.png

Policy 2

That policy will define restrictions for a specific user.

image-1627986711299.png

Rules

That rule will deny the access to a specific user.

image-1627986886900.png

That rule will permit the access to the other users.

image-1627986907426.pngimage-1628241209362.png

Download XML

You can download a XML file with the example: policy-demoFolder.xml

Configure PEP

image-1628239716307.png