Enable Just-in-Time elevation and provisioning

After deploying AD PAM in your environment, you can enable Just-in-Time elevation and provisioning to grant temporary privileged access on demand.

Just-in-Time elevation

  1. Add the permission to create user groups to your PAM domain provider account in AD.

  2. Identify the user groups in AD you would like to be available for Just-in-Time elevation.

  3. Back in Devolutions Server or Devolutions Hub Business, go to AdministrationPrivileged accessProviders, and click Edit on your PAM provider.

  4. Select the JIT privilege elevation section on the left menu.

  5. Select the user group identified earlier.

  6. If you would like to limit the JIT access to specific accounts, click Enable Privilege Sets.

  7. Add a prefix to the group name, such as DVLS-JIT-.

  8. Select a location for the temporary groups to be created.

  9. If you have multiple DC, configure a Replication latency to make sure the JIT has time to replicate between all DCs. Click Save.

Just-in-Time provisioning

  1. Open the Active Directory User and Computers (ADUC) console, right-click on the organizational unit (OU) containing your PAM account, and select Delegate Control....

  2. Follow the wizard, and make sure to check the Create, delete, and manage user accounts permission during the task delegation step.

    For least privileges purposes, you can Create a custom task to delegate to add only the minimal permissions required to create users in AD.

  3. Back in Devolutions Server or Devolutions Hub Business, go to AdministrationPrivileged accessProviders, and click Edit on your PAM provider.

  4. Open the JIT privilege elevation tab, and select the user group identified earlier.

  5. Choose a location for the temporary users to be created.

  6. If you have multiple Domain controllers (DCs), configure Replication latency to give JIT changes enough time to replicate across all DCs, and click on Save.

  7. In your PAM vault, add a new domain user.

  8. Enter the username for the account.

  9. Check the Just-In-Time (JIT) account check box, and click Save.

Devolutions Forum logo Share your feedback