For the complete documentation index, see llms.txt. This page is also available as Markdown.

Quickly deploy AD PAM in your environment

This guide walks you through the steps to set up Devolutions PAM in your environment quickly, so you can protect privileged accounts, enforce policies, and gain control over sensitive access with minimal configuration time.

Devolutions Server (self-hosted)

  1. Configure a PAM Domain service account.

    The PAM Domain service account will be required at a later stage. Make sure to keep the username and password handy.

  2. An optional step is to create a test account for PAM.

  3. Make sure the Scheduler service is running.

  4. Configure your PAM domain provider in Devolutions Server by going to AdministrationPrivileged accessProviders.

  5. Click the plus sign in the top right to add a new provider.

  6. Select Domain user and continue.

  7. Enter the required configuration and specify the Domain service account created in step 1. Click Save.

  8. Set up the account discovery configuration (prompted when saving the PAM provider).

  9. Select the OUs where the privileged account (or test account) is located.

  10. Check Start scan on save under Actions. Click Save.

  11. Open the provider’s properties and navigate to the Checkout policy tab.

  12. Create a check-out policy and a PAM vault.

  13. Import accounts from the Scan (see table below).

  14. Configure an entry to use the PAM account.

Here is the risk level associated with each account discovered during a scan.

Group name
Privilege tier
Description

Domain admins

Tier 0

Full control over domain resources.

Enterprise admins

Tier 0

Full control over forest-wide configuration.

Schema admins

Tier 0

Can modify the AD schema.

Administrators

Tier 0

Built-in administrators on all domain controllers.

Account operators

Tier 1

Can manage user/group accounts. Risk of privilege escalation.

Server operators

Tier 1

Can log on locally to DCs and manage services.

Backup operators

Tier 1

Can back up protected system files; often overlooked.

Group policy creator owners

Tier 1

Can create/edit GPOs —can introduce persistence.

DNS admins

Tier 1

Can control DNS zones —potential for domain spoofing.

Devolutions Cloud (Cloud)

  1. Configure a PAM Domain service account.

    The PAM Domain service account will be required at a later stage. Make sure to keep the username and password handy.

  2. An optional step is to create a test account for PAM.

  3. Install the PAM service.

  4. Configure your PAM domain provider in Devolutions Cloud by going to AdministrationPrivileged accessProviders.

  5. Click the plus sign in the top right to add a new provider.

  6. Select Domain user and continue.

  7. Enter the required configuration and specify the Domain service account created in step 1. Click Save.

  8. Open the provider’s properties and navigate to the Checkout policy tab.

  9. Create a check-out policy and a PAM vault by clicking Add vault.

  10. Configure an entry to use the PAM account.

  11. Run the Account discovery next to the provider (see table below).

  12. Select the OUs where the privileged account (or test account) is located.

  13. After selecting the destination, security, and password settings, click Import.

Here is the risk level associated with each account discovered during an Account discovery.

Group name
Privilege tier
Description

Domain admins

Tier 0

Full control over domain resources.

Enterprise admins

Tier 0

Full control over forest-wide configuration.

Schema admins

Tier 0

Can modify the AD schema.

Administrators

Tier 0

Built-in administrators on all domain controllers.

Account operators

Tier 1

Can manage user/group accounts. Risk of privilege escalation.

Server operators

Tier 1

Can log on locally to DCs and manage services.

Backup operators

Tier 1

Can back up protected system files; often overlooked.

Group policy creator owners

Tier 1

Can create/edit GPOs —can introduce persistence.

DNS admins

Tier 1

Can control DNS zones —potential for domain spoofing.

Read Enable Just-in-Time elevation and provisioning to grant temporary privileged access on demand.

See also

Last updated

Was this helpful?