Application Control via PAM3608 minutes to read
PAM360's Application Control, powered by ManageEngine's Application Control Plus, empowers administrators with advanced privilege elevation and delegation management. This functionality allows for effective oversight of applications on organizational endpoints. Using a set of crafted rules, administrators can effortlessly identify and manage applications across PAM360 resources and tailor allowlists and blocklists to control application usage. Additionally, at break-glass scenarios, administrators can temporarily authorize applications on the blocklist. Overall, this operation streamlines the process of allocating application access to users, enhancing security and efficiency within the PAM360 environment across all resources. Notes:
1. Prerequisites
2. Role - Manage Application ControlBy default, users assigned the Privileged Administrator and Administrator roles can configure and manage Application Control in PAM360. Alternatively, you can grant these same responsibilities to users by creating a custom role with the Manage Application Control privilege enabled. Users assigned this custom role will be able to configure and manage Application Control via PAM360. 3. Generating Authentication TokenTo enable the Application Control functionality, it is necessary to generate an authentication token from Application Control Plus. To generate the authentication token, perform the steps that follow:
![]() ![]() 4. Configuring Application Control in PAM360To ensure the expected functionality and perform endpoint privilege management capabilities via the PAM360 environment, configuring Application Control in PAM360 is necessary. To do so:
5. Application Control in PAM360Once communication is established between PAM360 and Application Control Plus, the Application Control window will load for further application management. Here, you can create allowlists and blocklists for endpoints across PAM360, and you can perform the following further application management actions directly from the PAM360 interface:
![]() 6. Configuration and Management Failure ScenariosEncountering difficulties while configuring or managing Application Control in PAM360 can result from various factors. It is essential to address these issues to ensure effective and efficient utilization of the Application Control feature. a. Mismatched Privileged RolesIf a user attempts to manage Application Control via PAM360 but lacks a corresponding privileged role in Application Control Plus, issues may arise. Users should possess similar privileged roles in both platforms to access and manage Application Control seamlessly. b. Module Absence in Endpoint CentralIn cases where the Application Control module is not enabled in Endpoint Central, attempts to configure or manage Application Control will fail. It is crucial to ensure that the Application Control module is activated within Endpoint Central for proper functionality. c. Unauthorized Access and PrivilegesConfiguration or management of Application Control without the appropriate privileges can lead to unauthorized access attempts. Users should be granted the necessary privileges to avoid encountering issues while configuring or managing Application Control within PAM360. d. Authentication Token Update RequirementChanging the login password of the responsible user in Application Control Plus disrupts the functionality of the Application Control module in PAM360. This is because the previously generated authentication token becomes invalid after the password change. To ensure smooth operation, it is essential to update the Application Control configuration with the newly generated authentication token. e. Username DiscrepancyIf a user attempting to access Application Control does not have the same username as in PAM360, issues may arise. Consistency in usernames across platforms is necessary to facilitate seamless access and utilization of Application Control functionalities. Addressing these potential failure scenarios comprehensively ensures the effective and efficient deployment and usage of Application Control within PAM360, enhancing overall security management capabilities. Related Document | |