Allow Service Account Manual Managed Credentials to take a user specified password

What is a one sentence summary of your feature request?

Allow Service Account Manual Managed Credentials to take a user specified password

Please describe your idea in detail. What is your problem, why do you feel this idea is the best solution, etc.

We are needing to allow a 3rd party contractor to impersonate a service account during an NPS session, in order to not affect legacy equipment/production that we cannot bring into NPS we are not able to rotate the password on the service account. Once an account in NPS is defined as a Service account(has dependencies), you are only able to have NPS set the password instead of giving it a manual input even if the managed is set as manual. This would allow NPS to manage accounts/still have them be impersonable with activities while balancing legacy/business requests and/or needs.

How do you currently solve the challenges you have by not having this feature?

Pass creds to 3rd party to fulfill as needed requests/work.

Hey Ian,

Thanks for posting in the community!

So to be clear about the ask, it sounds like you are looking for an option to manually set a credential that already exists i.e. all the dependent services are already working.

This is a reasonable request that I have seen before in a slightly different context where it was desired to push out a specific value rather than have NPS auto-generate a password.

Possible we could align both use cases and allow a value to be manually set against the service account and optionally allow synchronization out to dependent services.

We’ll review the request and update the post shortly.

All the best,
Martin

Correct, that is the request.

2 Likes

Was curious if this ever went anywhere?

Hi Ian,

Thank you for following up. I took over for Martin last year.

On this topic, I just had a prospective customer ask to be able to expand some of the vaulting capabilities in a similar way, even if for a different reason. The current vaulting is all geared toward NPS use and not a vault for third-parties. I am looking into it. Unfortunately, it will be several months before we are able to make any updates there.

Best Regards,
Billy

Sounds good. NPS currently has a few different departments in our org interested in this capability which would allow us to bring an AD account into a managed state in NPS for account impersonation sessions provisioned via NPS, without affecting the current existing legacy processes outside of NPS, so I look forward to any updates that can come from this. Thank you for the update