Importing Users from Microsoft Entra ID13 minutes to read
Integrate Microsoft Entra ID with PAM360 and import users and user groups from Microsoft Entra ID. Through this integration, users can login to PAM360 using their Microsoft Entra ID credentials, in both Windows and Linux platforms. After integration into PAM360, the user details and user group structure is maintained exactly as it is in the Microsoft Entra ID platform. Note: You can only import users who don't have multi-factor authentication (MFA) enabled in the Microsoft Entra ID portal. Following are detailed steps to register PAM360 in the Azure portal and import users into PAM360:
2.1 Importing Users from Microsoft Entra ID 2.2 Specifying Appropriate User Roles 2.3 Enabling Microsoft Entra ID Authentication 2.4 Managing Microsoft Entra ID Synchronization Schedules 1. Registering PAM360 in Microsoft Entra ID PortalTo integrate PAM360 with Microsoft Entra ID and import users, PAM360 should first be added as a native client application in your Microsoft Entra ID portal. Follow the steps given below to register PAM360 as an application:
Once you have registered PAM360 with appropriate permissions, go to PAM360's web interface and start importing users using the steps detailed below. 2. Steps to Import Users from Microsoft Entra ID
Note: You can also import users by navigating to Users >> Add Users >> Import from Microsoft Entra ID. However, Microsoft Entra ID Authentication can only be enabled from Admin >> Authentication >> Microsoft Entra ID. 2.1 Importing Users from Microsoft Entra ID
Note: For the existing users, the User Access Token method will continue to work (without further imports or synchronization) until Microsoft deprecates its API services. ![]() Note: The configurations applied during the initial import will be retained in subsequent schedules unless modified.
Notes:
Note: The imports configured with the synchronization interval will be added as a schedule on the Microsoft Entra ID Synchronization Schedules page. ![]() 2.2 Specifying Appropriate User RolesAfter import, all the users imported from Microsoft Entra ID will be assigned the default user role. To delegate roles more effectively, in the Change Roles for Users dialogue box that opens, individually assign the respective user role using the Change Role button beside the desired user in the Actions column. You can also assign specific roles to individual users imported from Microsoft Entra ID at any time by following these steps:
Note: Assign Administrator role to at least one user from the list of users imported from Microsoft Entra ID as administrator privileges are required to carry out user management and other system operations in PAM360. 2.3 Enabling Microsoft Entra ID AuthenticationThe third step is to enable Microsoft Entra ID authentication—enabling this will allow your users to login to PAM360 using their Microsoft Entra ID domain password. Note that this feature will work only for users who have already been imported to the local database from Microsoft Entra ID. Before enabling Microsoft Entra ID authentication, ensure that AD authentication is disabled.
2.4 Managing Microsoft Entra ID Synchronization Schedules
| |