Skip to content

Managed accounts

The Managed accounts module lists the local or domain accounts whose password is taken over by CyberElements, and serves as the entry point for following their rotations. What can be done there depends entirely on the password vault mode set in the general options — the two modes do not rely on the same mechanism.

In Systancia Access mode, the Systancia Access agents deployed on the machines carry the load: they discover where the account is used, change its password when due and propagate it to every one of those uses. The module is then fully administrable — declaring an account, editing it, deleting it, forcing a rotation, displaying the current password.

In Embedded mode, there is no agent: the password is held by the platform's embedded vault and rotation is driven by the password policies applied to the vault aliases. The module then merely reports on those accounts and their rotations: it exposes no action.

How to tell which mode is in force

In Embedded mode the toolbar carries no button — no +, no Edit, no ×, no Force password renewal — double-clicking a row opens nothing, and the Type column disappears from the grid. If you can see those buttons, you are in Systancia Access mode.


Account list — both modes

The window opens on the paginated list of accounts. When empty, it displays No managed account available. A search field filters the list on a substring of the name.

Column Description
Name Name of the managed account.
Domain Domain or machine the account lives on.
Type Local account or Service account. ⚠ Column present only in Systancia Access mode.
Last rotation Date of the last rotation, formatted DD/MM/YYYY. As long as no rotation has taken place, the cell displays Password renewal pending.
Rotations Number of rotations performed on that account, followed by a rotation icon.

Systancia Access mode — managing the accounts

This section only applies to Systancia Access mode. In Embedded mode, none of these actions is offered.

Add an account

The + button opens the Add managed account window.

Field Description
Name Name of the account to manage. The \ / " [ ] : \| < > + = ; , ? * @ characters are rejected; a faulty entry displays Invalid name: some special characters are forbidden.
Host Mandatory. Domain or machine hosting the account. Punctuation characters are rejected there too.
Initial password Mandatory. Current password of the account, before the agents take it over.
Local account / Service account Nature of the account. Both buttons are inactive in this version: any account created from this form is a service account.

Click Validate to save.

The uses of an account are managed in another module

It is the Systancia Access agent that detects the uses of an account — Windows services, scheduled tasks, vault aliases, SSH or MSSQL databases. They are therefore not declared here: they are reviewed and adjusted from the Managed account usages module, which allows each use to be included in or excluded from the rotation.

Edit an account

Select an account and click the Properties icon, or double-click the row. The Edit managed account window offers the same fields, with two differences: Name and Host become plain displayed text, and Initial password disappears — it only makes sense at the initial takeover.

Display the current password

When editing, a Display current password button may be offered. Clicking it asks for confirmation with the message Are you sure you want to display the password? If it is displayed, it will be renewed within n minute(s) by the agents concernedn being the renewal delay configured for the platform. On confirmation, the password appears next to the button.

Three conditions to see that button

It only appears in Systancia Access mode, only when editing an existing account, and only if the platform's global configuration allows passwords to be displayed. Besides, if no rotation has produced a password yet, the value displayed is Unknown password.

Force password renewal

Select one or more accounts and click Force password renewal. A confirmation is requested, in the singular or plural depending on the selection. On confirmation, the request is passed to the agents and the list is refreshed.

Delete an account

Select one or more accounts and click the × button. A confirmation is requested, in the singular or plural. Multiple selection is supported.


Embedded mode — read-only

This section only applies to Embedded mode.

The accounts listed are those carried by the embedded vault aliases. The grid gives their name, their domain, the date of their last rotation and the number of rotations performed; the Type column is not displayed.

No action is offered from this module: there is nothing to declare, edit or delete there, and rotation is not triggered from it.

To… Go to…
declare the account and its password Password vault, as an alias
set the rotation frequency and rules Password policies
check that an exposure was indeed followed by a rotation History of exposure