Install the Devolutions Cloud Services to enable PAM and encryption integration

The Devolutions Cloud Services installer facilitates the installation and configuration of different features such as the Privileged access management module, the Encryption service (SSO-enabled feature) and the Devolutions Cloud reporting service. The installed service will establish communication between your Devolutions Cloud and your internal resources.

Multiple instances of Devolutions Cloud Services can be run simultaneously for higher availability. Devolutions Cloud will simply use the one executed first and leave the others on standby. Should one fail, Devolutions Cloud will automatically use the next service in line.

A Friendly name can be attributed to each service during installation to help differentiate them.

Create an Application identity

  1. In Devolutions Cloud, click on AdministrationApplication identities.

  2. Select Add application identity (+).

  3. Enter a name and click Add.

  4. Copy the Application secret and Application key, and paste them somewhere safe. Alternatively, you can download them as a PDF file. These will be needed during Devolutions Cloud Services installation later on.

Edit permissions for application identities

  1. In Devolutions Cloud, Click AdministrationSystem permissions.

  2. Click the Edit icon (+).

  3. In the System tab, give both Manage privileged access tasks and Manage privileged access providers permissions to your application identity created during step 1. Click on Update.

You need to grant permission on the vault either at System level or Individual PAM vault level.

For all system vaults

  1. In Devolutions Cloud, go to AdministrationConfiguration and securitySystem permissions.

  2. Click the Edit button.

  3. Select Vaults and choose your Application user in the drop-down menu under the Contributor section.

  4. Click Update to close the window.

For a specific PAM vault

  1. In Devolutions Cloud, go to Administration – Management – Vaults

  2. Click the Add button (+).

  3. Select PAM vault in the menu to create your PAM vault.

  4. Go to the Security menu and select the Edit tab.

  5. Choose your Application user in the drop-down menu under the Contributor section.

  6. Click Add to close the window.

Installation of Devolutions Cloud Services

  1. Download Devolutions Cloud Services, and launch the installer.

  2. After reading and accepting the End-user license agreement, check PAM from the Custom setup feature list.

  3. Enter your Host URL, as well as the Application secret and Application key you saved at the end of step 1. You can then test your connection to see if everything is working properly. Click on Finish.

Create an application service

To create an application service, go to Administration, then select Application services under Configuration and security.

Click on the Add (+) button and select PAM service. Some information is needed, such as an Application service name, a Description, and the Application identity.

Check Devolutions Cloud Services logs

Devolutions Cloud Services' logs are available in Windows Event Viewer. The service should be able to connect to the created provider. The provider needs to be added in Devolutions Cloud.

It is also possible to see the Devolutions Cloud Services as a service in the Services window of Windows which shows the current status and where it can be started or stopped.

See also

Devolutions Forum logo Partagez vos commentaires