PAM360 - Frequently Asked Questions94 minutes to read
1. General
2. Web Interface and Authentication
3. Security
4. Password Synchronization
5. Backup and Disaster Recovery
6. Licensing
7. SSH Key Management
8. SSL Certificate Management
9. Policy-Based Access Privilege - Zero Trust Approach
1. Do I need to install any prerequisite software before using PAM360?Apart from the standard system requirements (both hardware and software), the following elements are essential for the proper functioning of the PAM360 server. These are especially required if you are planning to make use of PAM360's account discovery and password reset provisions.
To check if these software requirements are configured:
In the pop-up box that opens, the configuration status will be displayed. 2. What are the operating systems supported by PAM360?PAM360 supports the following flavors of Windows and Linux operating systems:
3. Can others see the resources added by me?Except for super administrators (if configured in your PAM360 set up), no one including admin users, will be able to see the resources added by you. However, if you share your resources with other administrators, they will be able to see them. 4. Can I add my own attributes to PAM360 resources?Yes, you can extend the attributes of the PAM360 resource and user account to include details that are specific to your needs. Refer this document for more details. 5. What happens if a user leaves the organization without sharing their sensitive passwords with anyone?If an administrative user leaves the organization, they can transfer the resources they own to other administrators. By doing so, they'll have no access to those resources themselves, unless they transfer the resources to themselves. Refer this document for more details. 6. How to add a new Active Directory (AD) domain in PAM360?Administrators can add new domains for both resource discovery and user discovery operations. Follow the below steps for resource discovery:
Refer to this help section for detailed instructions. To add a new domain for user discovery:
Refer to this help section for detailed instructions. 7. How to remove a domain from PAM360?To remove a domain from PAM360, you first need to remove the users that belong to this domain. Once the users are removed, follow the below steps to remove the domain information:
8. How to fix the errors “The list of Groups is too large to display ” and "The list of OUs is too large to display" while importing from AD?To fix these errors, you need to increase the number of OUs and groups allowed during the AD import. Follow the below steps:
9. How can I edit the properties of an existing scheduled task, such as changing the time or the frequency?You can modify the time interval for AD synchronization by following the below steps. To create a new task or edit the existing scheduled tasks, follow the below steps:
Note: Only the owner of the scheduled task can edit or modify the existing schedules by navigating to Admin >> Manage >> Scheduled tasks. 10. Can an AD sync job be set to occur multiple times a day, such as once every 4 hours?Configuring a schedule to run every 4 hours must be done when you import the OU/Group from AD. To import, go to Resources >> Discover Resources >> Import. Here, specify the synchronization interval as per your requirement and import. 11. How to fix the “PAM360 detected harmful content in the data entered by the user and aborted the operation" error occurred while importing resources through a csv/tsv file?As a security measure, PAM360 to restricts certain characters such HTML tags (< , >), "URL: HTTPS://" or "URL: HTTP://", security mark (?), end line and multiple spaces in the notes or any other field in PAM360 to avoid causing security violations in the product. If any of these characters are used in any other fields except the password field, then it causes a violation and the import fails. To avoid this, verify your CSV/TSV file to ensure these characters are removed for a successful import. Note: It is advisable to ensure that the resource & account descriptions do not exceed the max limit of 2000 characters. 12. How do I troubleshoot if importing users/resources from AD fails?Verify the following:
If the above verifications fail, please contact pam360-support@manageengine.com. 13. Can I run custom queries to generate results for integration with other reporting systems?Yes, you can. Please contact our support with your specific request and we will help you with the relevant SQL query to generate XML output. 14. Does domain SSO work across firewalls / VPNs?The domain Single Sign On (Windows-integrated authentication) is achieved in the Windows environment by setting non-standard parameters in the HTTP header, which are usually stripped off by devices like firewalls / VPNs. PAM360 is designed for use within the network. So, if you have users connecting from outside the network, you cannot have SSO enabled. 15. Can I rebrand PAM360 with my own logo and organizational information?Yes. PAM360 provides you with the following options for customization and rebranding:
To carry out the above functionalities:
Note that at any point, this configuration can be disabled. Know how. 16. Does PAM360 record Password viewing attempts and retrievals by users?Yes, PAM360 records all operations that can be possibly performed by an user- including password viewing and copying operations. From audit trails, you can get a comprehensive list of all the actions and attempts by the users with password retrieval. Know more 17. Why does the size of PostgreSQL wal_archive file increase at a rapid pace?This issue occurs when the backup location specified in PAM360 is no longer accessible to save the backup file. In simple terms, whenever the PostgreSQL database backup fails, wal_archive folder size will start increasing. Solution:
This will trigger an instant backup and automatically purge the wal_archive directory. 18. Does PAM360 support High Availability?Yes, refer the High Availability document for more details. 19. What are the various Syslog formats followed by PAM360?The following are three different types of syslog formats that PAM360 uses to send syslog messages to your syslog collector host: i. Resource Audit
ii. User Audit
20. Does PAM360 alter the number of Windows CAL licenses?Generally, RDP sessions are invoked from the PAM360 server and relayed to the end user's browser through a third-party component called Spark Gateway. This component comes bundled with PAM360 and does not have any relation to Windows CAL licenses. Hence, PAM360 does not affect the number of Windows CAL licenses in any way. Users need to purchase as many CAL licenses, as suggested by Microsoft. 21. How do I run the PAM360 service using a group Managed Service Account (gMSA)?To know in detail about running the PAM360 service using a group Managed Service Account, click here. 22. How do I fix the PostgreSQL server start-up failure?Error Scenarios:
| ||||||||||||||