Import an AnyIdentity PAM provider

Import an AnyIdentity PAM provider by following the steps below.

  1. To create the provider, first navigate to Administration – Privileged access in Devolutions Server and select Providers.
    Administration – Privileged access – Providers
    Administration – Privileged access – Providers
  2. Click on the + sign to add a provider.
    Add a provider
    Add a provider
  3. Select AnyIdentity and then choose your template. An existing provider template named Microsoft SQL Server Login is displayed here.
    Select an AnyIdentity provider
    Select an AnyIdentity provider
  4. Define a name and provide values for all of the provider properties. In the screenshot below, the Server provider property is marked as Mandatory in the template, indicated by the red asterisk and red box around the field.
    Provider properties
    Provider properties

AnyIdentity providers are designed for connecting to a single identity provider endpoint. It is generally recommended to create one AnyIdentity provider per identity provider.

After providing values for all of the provider properties, there is an option to add a PAM vault for the provider or to add a scan configuration. By default, Add PAM vault is selected; see Scan configuration to learn about adding one.

Add PAM vault
Add PAM vault

On this page, a credential can also be specified to run all actions under, or a specific Windows host can be designated to execute the actions.

Credential and Windows host
Credential and Windows host

By default, an AnyIdentity provider executes all actions on Devolutions Server under the NETWORK SERVICE user account. If a username and password are specified under Run as, AnyIdentity will first attempt to authenticate to the Devolutions Server using that user account and execute all action scripts under that account. If a Host name is specified, AnyIdentity assumes a remote Windows host and will attempt to run all action scripts locally on that host via PowerShell remoting.

Finally, under Settings, a custom password template can be provided, if necessary. All available custom password templates can be found under Administration – Password templates. When the password rotation action runs, it will use the password template defined here to generate a new password.

Password template
Password template

Devolutions Forum logo Give us Feedback