This guide walks you through the steps to set up Devolutions PAM in your environment quickly, so you can protect privileged accounts, enforce policies, and gain control over sensitive access with minimal configuration time.
-
Configure a PAM Domain service account.
The PAM Domain service account will be required at a later stage. Make sure to keep the username and password handy.
-
An optional step is to create a test account for PAM.
-
Make sure the Scheduler service is running.
-
Configure your PAM domain provider in Devolutions Server by going to Administration – Privileged access – Providers.
-
Click the plus sign top right to add a new Provider.
-
Select Domain user and continue.
-
Enter the required configuration and specify the Domain service account created in step 1.
-
Click Save.
-
Set up the Scan configuration (prompted when saving the PAM provider).
-
Select the OUs where the Privileged account (or test account) is located.
-
Check Start scan on save under Actions.
-
Click Save.
-
Open the provider’s properties and navigate to the Checkout policy tab.
-
Create a check-out policy.
-
Create a PAM vault.
-
Import accounts from the Scan.
-
Here is the risk level associated with each account discovered during a scan.
Group name | Privilege tier | Description |
---|---|---|
Domain admins | Tier 0 | Full control over domain resources. |
Enterprise admins | Tier 0 | Full control over forest-wide configuration. |
Schema admins | Tier 0 | Can modify the AD schema. |
Administrators | Tier 0 | Built-in administrators on all domain controllers. |
Account operators | Tier 1 | Can manage user/group accounts. Risk of privilege escalation. |
Server operators | Tier 1 | Can log on locally to DCs and manage services. |
Backup operators | Tier 1 | Can back up protected system files; often overlooked. |
Group policy creator owners | Tier 1 | Can create/edit GPOs —can introduce persistence. |
DNS admins | Tier 1 | Can control DNS zones —potential for domain spoofing. |
Configure an entry to use the PAM account.
Refer to this section if you want to enable Just-in-Time elevation and Just-in-Time provisioning in your PAM environment.