Systems and methods for pause and resume functionality for shared privileged remote access (PRA) sessions
Systems and methods for pause and resume functionality for shared Privileged Remote Access (PRA) sessions. The methods include steps of, responsive to determining one or more users are allowed to access an application associated with infrastructure, determining the one or more users' security and access policies, and creating a Privileged Remote Access (PRA) session for the one or more users; brokering a connection between one or more user devices associated with the one or more users and the application through a lightweight connector, and enabling the one or more users to send commands to the application; receiving a pause command from one of the one or more users; and responsive to receiving the pause command, blocking commands from the one or more users from reaching the application.
1 . A method comprising steps of:
responsive to determining one or more users are allowed to access an application associated with infrastructure, determining the one or more users' security and access policies, and creating a Privileged Remote Access (PRA) session joinable by multiple concurrent users including an administrator, the administrator being provided, based on the administrator's security and access policies, with a user interface (UI) control to issue a pause command that applies to one or more selected users in the shared session without terminating or transferring the session to another device;
brokering a connection between one or more user devices associated with the one or more users and the application through a lightweight connector, and enabling the one or more users to send commands to the application;
receiving a pause command from one of the one or more users; and
responsive to receiving the pause command, blocking commands from the one or more users from reaching the application while continuing to transmit, in real time, pixels of the application to the one or more selected users so that they can view the PRA session during the pause, and selectively resuming the blocked commands responsive to a resume command from the administrator without reloading application state,
wherein the pause command includes instructions to only pause the PRA session for one user of the one or more users, and wherein the steps further comprise:
blocking commands from the one user from reaching the application.
2 . The method of claim 1 , wherein the steps further comprise:
receiving a resume command; and
responsive to receiving the resume command, enabling the one or more users to send commands to the application.
3 . The method of claim 2 , wherein the steps further comprise:
providing a User Interface (UI) to a specific user of the one or more users, wherein the Ul provides the specific user with the ability to send pause and resume commands.
4 . The method of claim 3 , wherein the Ul is provided to the specific user based on the specific user's security and access policies.
5 . The method of claim 1 , wherein the lightweight connector is one of a virtual machine and a docker container hosted in the infrastructure.
6 . The method of claim 1 , wherein the steps further comprise:
providing a communication channel to allow communication between the one or more users while blocking commands.
7 . The method of claim 1 , wherein the steps further comprise:
performing browser isolation to the one or more user devices such that only pixels are transmitted thereto and only keystrokes and mouse commands are transmitted to the application.
8 . The method of claim 7 , wherein the steps comprise:
responsive to receiving a pause command, blocking commands from the one or more user devices from reaching the application while continuing to transmit pixels to the one or more user devices.
9 . The method of claim 7 , wherein the same pixels are transmitted to each of the one or more user devices during the PRA session.
10 . A non-transitory computer-readable medium comprising instructions, wherein the instructions are executable by a cloud-based system to perform steps of:
responsive to determining one or more users are allowed to access an application associated with infrastructure, determining the one or more users' security and access policies, and creating a Privileged Remote Access (PRA) session joinable by multiple concurrent users including an administrator, the administrator being provided, based on the administrator's security and access policies, with a user interface (UI) control to issue a pause command that applies to one or more selected users in the shared session without terminating or transferring the session to another device;
brokering a connection between one or more user devices associated with the one or more users and the application through a lightweight connector, and enabling the one or more users to send commands to the application;
receiving a pause command from one of the one or more users; and
responsive to receiving the pause command, blocking commands from the one or more users from reaching the application while continuing to transmit, in real time, pixels of the application to the one or more selected users so that they can view the PRA session during the pause, and selectively resuming the blocked commands responsive to a resume command from the administrator without reloading application state,
wherein the pause command includes instructions to only pause the PRA session for one user of the one or more users, and wherein the steps further comprise:
blocking commands from the one user from reaching the application.
11 . The non-transitory computer-readable medium of claim 10 , wherein the steps further comprise:
receiving a resume command; and
responsive to receiving the resume command, enabling the one or more users to send commands to the application.
12 . The non-transitory computer-readable medium of claim 11 , wherein the steps further comprise:
providing a User Interface (UI) to a specific user of the one or more users, wherein the UI provides the specific user with the ability to send pause and resume commands.
13 . The non-transitory computer-readable medium of claim 12 , wherein the UI is provided to the specific user based on the specific user's security and access policies.
14 . The non-transitory computer-readable medium of claim 10 , wherein the lightweight connector is one of a virtual machine and a docker container hosted in the infrastructure.
15 . The non-transitory computer-readable medium of claim 10 , wherein the steps further comprise:
providing a communication channel to allow communication between the one or more users while blocking commands.
16 . The non-transitory computer-readable medium of claim 10 , wherein the steps further comprise:
performing browser isolation to the one or more user devices such that only pixels are transmitted thereto and only keystrokes and mouse commands are transmitted to the application.
17 . The non-transitory computer-readable medium of claim 16 , wherein the steps comprise:
responsive to receiving a pause command, blocking commands from the one or more user devices from reaching the application while continuing to transmit pixels to the one or more user devices.
18 . The non-transitory computer-readable medium of claim 16 , wherein the same pixels are transmitted to each of the one or more user devices during the PRA session.