Managing Accounts and Passwords18 minutes to read
Managing your accounts and passwords in PAM360 made easy. This document discusses the different ways in which users can manage accounts in PAM360 such as viewing, editing, copying, moving accounts and also to change password, view password history and check integrity of passwords stored in PAM360.
1. Viewing AccountsFollow the below steps to view an account that is part of a resource.
You can modify the default 10 seconds from the General Settings page. 1.1 Allowing End-Users to Retrieve Auto Logon Configured Accounts' PasswordsThrough the auto logon feature, PAM360 provides the option to establish a direct connection to the resource, eliminating the need for retrieving the passwords. By default, password users and auditors will be able to retrieve the passwords that are shared with them. However, if auto logon is configured, they might not need access to the passwords. In such cases, you can take a decision to either allow or restrict access to passwords and implement the same through the option "Allow plain text view of passwords, if auto logon is configured" in General Settings. To enable this option,
1.2 Enforcing Users to Provide a Reason for Viewing PasswordsBy default, when a user tries to retrieve the password of a resource, on clicking the asterisks, the passwords appear in plain text. If you want to force your users to provide a reason why access to the password was needed, you can enable the option "Enforce users to provide a reason for password retrieval" in General Settings. To enable this option,
2. Copying PasswordsPAM360 leverages clipboard utility of browsers to copy passwords when you intend to copy and paste passwords. Follow the below steps to copy passwords:
3. Changing PasswordsTo change the passwords of user accounts,
![]()
4. Verifying Passwords Stored in PAM360Passwords of resources such as servers, databases, network devices and other applications are stored in PAM360. It is possible that someone who has administrative access to these resources could access the resource directly and change the password of the administrative account. In such cases, the password stored in PAM360 will be outdated and not be of any use to the users who access PAM360 for the password. To deal with such possibilities, PAM360 provides an option for checking the validity of passwords at any point of time, both on demand and also at periodic intervals. On demand verification for password validity can be performed for a single account or for all the resources/accounts stored in the PAM360 application. 4.1 Verifying Individual PasswordsFollow the below steps to verify the integrity of the password of a single account:
Notes:
4.2 Verifying Passwords in BulkCheck if the passwords stored in PAM360 are in synchronization with the actual passwords of the resources by running this check. Follow the below steps to verify the integrity of the passwords in bulk:
4.3 Scheduled Verification of Passwords in BulkYou can schedule to check the integrity of the passwords stored in PAM360. Follow the steps below:
Now, the integrity check will run based on the schedule configured, and PAM360 will try to establish connection with the target systems for all the accounts in the selected group for which remote password reset has been enabled. Once the connection is established, it tries to login with the credentials stores in PAM360. If login does not succeed, PAM360 concludes that the passwords are out of sync. A consolidated notification will be emailed to all the administrators and auditors. Note: If PAM360 cannot establish a connection with the system due to some network problem, it will not be considered that the password is out of sync. 4.4 Verifying All Passwords Stored in PAM360This option is to perform the integrity check for all the passwords stored in PAM360. Once done, an email will be sent to the administrators. Follow the below steps:
5. Viewing Password HistoryThe history of changes done to the passwords are captured in the form of password history. Information such as the old password, modified by whom, from which machine and the time at which it was modified are all captured in history. To view the password history of an account,
Note: To view the password history of shared resources with access control configured, the administrator should approve the request. 6. Copying Passcard LinkA passcard typically contains details such as Resource Name, Account Name, Password of the account, Owner of the resource and the DNS name, along with any additional resource or account attributes that might be added to it. To view the passcard of an account, you must be logged into PAM360 and the corresponding resource must be owned by you or shared to you. The Passcard link provides consolidated details of an individual account in PAM360 as a shareable link. The link can be accessed by only those to whom the passcard is shared with the relevant privilege (read-only, read-write, or manage). Follow the below steps to copy the Passcard of an account:
7. Editing AccountsAt any point of time, you can edit the details of any of the accounts. To edit an account,
8. Copying AccountsCopy and add accounts under one or more resources. You can then edit the replicated accounts to suit your requirements. The Copy Account feature will come handy when you handle identical accounts of different resources. Remember, the copy action will not create any changes to the account(s) copied. Follow the below steps to copy one or more accounts:
9. Moving AccountsMove one or more accounts that are part of one resource to another resource. When you do so, the selected account(s) will be removed from the present resource. Follow the below steps to move one or more accounts:
| |