IIS AppPool Account Password ResetNormally, Windows domain accounts are used as identities to run IIS app pools. Whenever the password of a domain account is changed in the domain controller, the new password has to be updated individually in all associated app pools for web applications to run without any hindrances. With each domain account used to run numerous app pools, manually effecting all password changes is a tedious job for an IT admin. PAM360 has the ability to identify the IIS app pools that are run using a specific Windows domain account stored in PAM360. While resetting the password of the domain accounts stored in PAM360, it will find out the app pools which are run using that particular domain account and will automatically update the change in the app pool identities too after the domain account password is reset. To add app pool accounts to PAM360 and to achieve automated password resets, carry out the following steps in the GUI: Summary of Steps
1. Add Domain Controller as a Resource
2. Add Domain Admin Account and IIS AppPool Accounts.
3. Add Domain Member Servers as New Resources and Create Resource GroupContinue adding the other member servers of the domain - Win1, Win2, Win3, and Win4 as new resources in the same way as explained above.
Alternate step: Automated discovery of resources and associated accountsInstead of manual addition explained in Step 3, you can also discover the required resources and groups in your domain by following the steps given below:
4. Configure Remote Password Reset for IIS AppPool Account.Instead of manual addition explained in Step 3, you can also discover the required resources and groups in your domain by following the steps given below:
5. Associate Resource Groups for the IIS AppPool Account
6. Verify Supported IIS AppPool Accounts
7. Change Password
Additional steps to schedule periodic password resets for IIS App Pool accountsThe aforementioned steps are adequate to carry out password resets for app pool accounts anytime on demand. If you would like to configure automatic password resets on a periodic basis, execute the additional steps given below: To configure scheduled password reset for app pool accounts,
Step 1: Pre-notificationWhen passwords are scheduled to be reset at a specific time, notifications can be sent to the users beforehand giving them a heads up on the reset action. To send notifications,
Step 2: Specify the new password
Step 3: Specify the reset scheduleActual creation of the schedule for password reset is specified in this step. The reset can be performed one-time or it could be recurring at periodic intervals. To specify the reset schedule:
Step 4: Post-reset notificationAfter the completion of password reset schedule, notifications regarding the completion of reset can be sent to all those who have access to the passwords. To send notifications,
Upon completion of these steps, PAM360 will continue to automatically reset the app pool account passwords on a periodic basis. | |