Integrating PAM360 with ManageEngine ADManager Plus12 minutes to read
This document discusses the process of integrating PAM360 with ManageEngine ADManager Plus (ADMP). At the end of this document, you will have learned the following:
1. Key Benefits of IntegrationManageEngine PAM360 integrates with ManageEngine ADManager Plus, a management and reporting solution that allows IT Administrators and Technicians to manage Active Directory objects and groups and generate reports. The PAM360-ADManager Plus integration allows you to perform timely elevation and delegation of domain users in the Active Directory (AD) security groups through the ADManager Plus server. By leveraging the ADManager Plus integration, enforce access control for PAM360 users on domain accounts and provide just-in-time privilege elevation for the domain accounts . You can also add and remove accounts from the AD security groups right from the PAM360 interface. Once the integration is complete, all the security groups from the active directory server will be available in PAM360. In addition, ADManager Plus leverages PAM360 to manage its domain accounts password, particularly for privileged accounts. Previously, when a password rotation for a domain account was performed via PAM360, the same password had to be manually updated in ADMP for seamless access continuity. Without this update, ADMP would retain the old password, restricting AD users from performing tasks such as password resets, account unlocks, and more, potentially increasing help desk calls. From build 7300 onwards, the domain account details in ADMP can be associated with the same in PAM360. As a result, whenever the domain account password is rotated via PAM360, the updated password from PAM360 gets automatically synchronized with the associated domain account in ADMP. Read more about AD groups management in ADManager Plus here. 2. How does the Integration Work?PAM360 sources data from ADManager Plus via its API and using the server details of ADManager Plus. The AD security groups listed in ADManager Plus will be consolidated and listed in PAM360. The AD domain users imported into PAM360 can be given controlled access to the security groups populated from ADManager Plus. 3. Prerequisites for Performing the IntegrationBefore commencing the integration, verify if all of the below prerequisites are satisfied:
4. Steps to Configure the IntegrationYou can perform all the configurations related to the PAM360-ADManager Plus integration from the PAM360 portal. To configure the integration, provide the host name and port details of the machine where ADManager Plus is installed. Once you have entered all the required details and saved the configuration, PAM360 will try to set up a connection with ADManager Plus. After the successful connection, the domain details will be retrieved from ADManager Plus and saved in the PAM360 database, and the integration will be established.
Note: Only the users with the ManageEngine Integration role will see the ManageEngine option under Integration. Buttons and Definitions:
The PAM360 - ADManager Plus integration is enabled now. Proceed with mapping of domain accounts to the AD security groups. 5. Steps to Map Accounts to ADManager Plus Security GroupsPrerequisite: Import an Active Directory user into PAM360 (if not already available) and enable administrator privileges for this user. Ensure the imported user is also a valid technician in ADManager Plus to delegate the required tasks. Once the PAM360-ADManager Plus integration is complete, follow the below steps to perform policy configuration. The Policy Configuration option lets you elevate domain accounts to security groups just in time (AD security groups already exist in the Domain Controller and by extension, in the ADManager Plus also).
Now when the resource is shared to a user with Password User/Password Auditor capabilities, they can request for password access or elevation. This request can be approved/rejected by any admin in the Authorized Administrator list as long as their user role satisfies the following criteria:
Important Notes:
6. Associating Domain Accounts in ADMP with PAM360
| ||||||||||||