lithnet / access-manager

Access Manager provides web-based access to local admin (LAPS) passwords, BitLocker recovery keys, and just-in-time administrative access to Windows computers in a modern, secure, and user-friendly way.
Other
239 stars 20 forks source link

Admin Approval #123

Closed davedave1234 closed 2 years ago

davedave1234 commented 2 years ago

I would like to know if there is a current way to, or something you can implement that would, allow me the ability to approve requests made by regular users.

For example: I want to give all my service desk access to request LAPS passwords all the time and just receive an email notifying that they did, this is easy and working great. I would also like to give my users ability to request LAPS passwords and/or JIT access but I would like an email sent with an "Approve" link, or something similar, to me and my administrators so that the users don't get access unless we approve and can not give them selves access without us being aware.

As a work around I have setup an authorization policy and as a procedural process it is enabled with an expiration time when a user needs access. This is a manual process and is open to user error.

I want to add that I love the product.

ryannewington commented 2 years ago

Hi @davedave1234

Thanks for the kind feedback.

While approvals are on our feature list to consider in the future, there are no solid plans to implement this capability. We're focused at the moment on helping organizations protect themselves from bad guys by gating credentials and access away from them. Approvals don't help in that threat model. That being said, I can certainly understand the desire for this capability, so we certainly haven't ruled out delivering it in a future version, it's just that we are prioritizing the features that protect orgs against bad actors at the moment.

davedave1234 commented 2 years ago

I totally understand and appreciate the great product you have already provided.