Customize Email Notifications

Email notifications are used to alert users on particular Password Safe actions, such as connection profile alerts, release requests, and password check failures.

Email Notifications Sent by Password Safe

The below table lists the email notifications that are sent to Password Safe users. It includes the event type that occurs to initiate the email notification and the account types that receive the email.

Local Accounts (Includes Non-Domain Asset and Database Managed Systems)

Event Account Not configurable Configurable by template settings
Release Request Managed NA
  • Account's Approver
  • Requester (CC)
  • Asset's ISA
Request Response Managed NA
  • Account's Approver (CC)
  • Requester
  • Asset's ISA
Password Change Failure Managed
  • Managed System's ISA
  • Built-in Administrators group members
  • Managed System contact person (Managed Systems settings UI)
NA
Functional
  • Managed System's ISA
  • Built-in Administrators group members
  • Managed System contact person (Managed Systems settings UI)
NA
Password Check Failure Managed
  • Managed System's ISA
  • Built-in Administrators group members
  • Managed System contact person (Managed Systems settings UI)
NA
Functional
  • Managed System's ISA
  • Built-in Administrators group members
  • Managed System contact person (Managed Systems settings UI)
NA
Propagation Event Failure Managed
  • Managed System contact person (Managed Systems settings UI)
NA
Privileged Password Release Managed
  • Managed Account Release Notification Recipients (Managed Accounts settings UI)
NA
Non-Managed Release Expiration Managed
  • Managed Account Release Notification Recipients (Managed Accounts settings UI)
NA

Domain Accounts

Event Account Not configurable Configurable by template settings
Release Request Managed NA
  • Account's Approver
  • Requester (CC)
  • Domain Management permission (with Read/Write)
Request Response Managed NA
  • Account's Approver (CC)
  • Requester
  • Domain Management permission (with Read/Write)
Password Change Failure Managed
  • Domain Management permission (with Read/Write)
  • Built-in Administrators group members
  • Managed System contact person (Managed Systems settings UI)
NA
Functional
  • Domain Management permission (with Read/Write)
  • Built-in Administrators group members
  • Managed System contact person (Managed Systems settings UI)
NA
Password Check Failure Managed
  • Domain Management permission (with Read/Write)
  • Built-in Administrators group members
  • Managed System contact person (Managed Systems settings UI)
NA
Functional
  • Domain Management permission (with Read/Write)
  • Built-in Administrators group members
  • Managed System contact person (Managed Systems settings UI)
NA
Propagation Event Failure Managed
  • Managed System contact person (Managed Systems settings UI)
NA
Privileged Password Release Managed
  • Managed Account Release Notification Recipients (Managed Accounts settings UI)
NA
Non-Managed Release Expiration Managed
  • Managed Account Release Notification Recipients (Managed Accounts settings UI)
NA

Customize Mail Templates

The subject line and message body for a template can be customized in Password Safe configuration.

  1. In the BeyondInsight console, go to Configuration > Privileged Access Management > Mail Templates.

Configure mail template in Password Safe

  1. Select a mail template type from the list.
  2. Type the subject line text.
  3. In the Message Body field, add the text for the email:
    • Copy a tag from the Body Tags section to a location in the message body.
    • When working within cumulative alert emails, ensure you add any additional body tags within the <ROW></ROW> elements.
    • To include hyperlinks that link directly to the approval and denial pages for a file or password request, use the :approvallink: and :denylink: message body tags.
  4. Click Save Template.

 

Only one <ROW></ROW> tag can be added to the mail template. If you wish to add more tags, they must be added to the row already present within the template. For example:
<ROW>:AlertTimeUTC: | :AlertTimeClient: | :ComputerName: | :AccountName: | :AccountDomain: | :DNSName: | :IPAddress: | :EventCode: | :EventReferenceId: | :SubjectSID:</ROW>