This guide walks you through the steps to set up Devolutions PAM in your environment quickly, so you can protect privileged accounts, enforce policies, and gain control over sensitive access with minimal configuration time.
-
Configure a PAM Domain service account.
An optional step is to create a test account for PAM.
-
Make sure the Scheduler service is running.
-
Configure your PAM domain provider in Devolutions Server by going to Administration – Privileged access – Providers.
-
Click Add new PAM provider.
-
Enter the required configuration and uncheck Add PAM vault.
-
Click Save.
-
Set up the Scan configuration (prompted when saving the PAM provider).
-
Select the OUs where the Privileged account (or test account) is located.
-
Check Start scan on save under Actions.
-
Click Save.
-
Create a check-out policy.
-
Create a PAM vault.
-
Import account from the Scan.
-
Configure an entry to use the PAM account.
Add the permission to create user groups to your PAM domain provider account in AD.
Identify the user groups in AD you would like to be available for Just-in-Time elevation.
Edit your PAM domain provider.
Open the JIT privilege elevation tab.
Select the user group identified earlier.
If you would like to limit the JIT access to specific accounts, click Enable Privilege Sets.
Add a prefix to the group name, such as DVLS-JIT-.
Select a location for the temporary groups to be created.
If you have multiple DC, configure a Replication latency to make sure the JIT has time to replicate between all DCs.
Save.
Add the permission to create and delete users to your PAM domain provider account in AD.
Edit your PAM domain provider.
Open the JIT privilege elevation tab.
Select the user group identified earlier.
Select a location for the temporary users to be created.
If you have multiple Domain controllers (DCs), configure Replication latency to give JIT changes enough time to replicate across all DCs.
Click Save.
In your PAM vault , add a new domain user.
Enter the username for the account.
Check the Just-In-Time (JIT) account check box.
Click Save.