Credential Manager Groups grayed out

Document ID : KB000126718
Last Modified Date : 14/02/2019
Show Technical Document Details
Question:
If the user has either of these roles, he can play with ‘Credential Manager Groups’ tab.
Global Administrator/Operational Administrator/Password Manager

But this does not work in case of inherited roles. Is it expected behavior?

[Step]
1. Create a User Group (Users > Manage User Groups > ADD).
2. Add ‘Global Administrator’ role to the group.
3. Add a user to the created group.
4. Confirm the user has inherited roles.
5. He cannot play with ‘Credential Manager Groups’ tab as it is grayed out.
inherited_roles
Environment:
CA Privileged Access Manager 3.2 and earlier
Answer:
With PAM 3.2 and earlier, it is working as designed.
A user cannot inherit credential manager group assignment.
Assignment of credential manager groups must be done on the individual users.