ManageEngine PAM360 integrates with ManageEngine ADManager Plus (ADMP) to provide a comprehensive solution for managing and securing access to Active Directory (AD) environments. This integration enables IT administrators to centralize the management of AD security groups and streamline privilege elevation for domain users.
PAM360 connects to ADManager Plus using its API and the server credentials configured during setup. Once integrated, all the AD security groups managed in ADMP are automatically fetched and listed in PAM360. Administrators can then manage these groups - adding or removing domain accounts, directly from the PAM360 interface, eliminating the need to switch between tools. This allows for efficient enforcement of access control policies and facilitates just-in-time privilege elevation for domain accounts based on organizational needs.
Additionally, the integration strengthens password management between the two solutions. In earlier versions, whenever a domain account password was rotated in PAM360, the updated password had to be manually entered in ADMP to maintain uninterrupted access. Without this manual update, AD users could face issues such as failed password resets or locked accounts, leading to increased help desk requests. Starting from build 7300, PAM360 addresses this limitation by enabling the association of domain accounts in ADMP with their counterparts in PAM360. Once mapped, any password rotation performed in PAM360 is automatically synchronized with the corresponding account in ADMP. This ensures password consistency across both platforms, minimizes administrative overhead, and helps maintain seamless user operations across the Active Directory environment.
Additional Detail
Refer this document to learn more about AD groups management in ADManager Plus.
This document discusses the process of integrating PAM360 with ADMP. At the end of this document, you will have learned the following:
Before commencing the integration, verify if all of the below prerequisites are satisfied:
importCert.bat <Absolute-Path-of-the-ADMP-Certificate>
You can perform all the configurations related to the PAM360 - ADManager Plus integration from the PAM360 portal. To configure the integration, provide the host name and port details of the machine where ADManager Plus is installed. Once you have entered all the required details and saved the configuration, PAM360 will try to set up a connection with ADManager Plus. After the successful connection, the domain details will be retrieved from ADManager Plus and saved in the PAM360 database, and the integration will be established.



The PAM360 - ADManager Plus integration is enabled now. Proceed with mapping of domain accounts to the AD security groups.
Caution
Before proceeding, ensure that an Active Directory user is imported into PAM360 and granted administrator privileges. The same user should also exist as a valid technician in ADManager Plus inorder to delegate the required tasks.
Once the PAM360 - ADManager Plus integration is complete, follow the below steps to perform policy configuration. The Policy Configuration option lets you elevate domain accounts to security groups just in time (AD security groups already exist in the Domain Controller and by extension, in the ADManager Plus also).


Now, when the resource is shared to a user with Password User or Password Auditor user roles, they can request for password access or elevation. This request can be approved or rejected by any admin in the Authorized Administrator list as long as their user role satisfies the following criteria: The user designated to perform privilege elevation must have an Administrator role in PAM360 (i.e., any one of the following user roles: Privileged Administrator, Administrator, and Password Administrator), and in ADManager Plus, they must have a user role with any of the following permissions: modify users and modify groups. However, the users who receive privilege elevation in PAM360 need not have any special permissions in ADManager Plus. Click here to learn more about user roles in PAM360.
Caution
Associating domain accounts in ADMP with PAM360 ensures seamless password synchronization. When a password rotation occurs in PAM360, it automatically updates the corresponding password in ADMP. To associate the domain account details, follow these steps:
Additional Detail
This option is only applicable for Windows Domain resources and with an active ADMP integration.

Additional Details
Upon associating the ADMP domain account details in PAM360, the automatic synchronization of the domain account password will occur when the remote password reset is executed from PAM360.
If you encounter issues during the integration or while using it, follow these tips to resolve common problems:
If you encounter any persistent issues, please contact our support at pam360-support@manageengine.com.