Managing PAM360 User Accounts11 minutes to read
This document provides a comprehensive guidance on managing the user accounts within your PAM360 environment. Roles Required to Perform this Operation
You will learn the following with respect to managing users in this document:
1. Editing the PAM360 User AccountUser with the provided privilege can modify various details for existing users such as their role, email address, access level, password policy, department, and Two Factor Authentication (2FA), etc. To do so,
To know more about each user field, refer to the add user help documentation for details. Add Users Manually - Builds Preceding 6700 | Builds Following 6700 Note: If you are currently logged in as an administrator, you will not be able to alter your own access level or scope. In such cases, you will need to request another administrator to make the necessary changes. 2. Modifying REST API and SDK AccessNote: Applicable only for builds beyond 6700. You can also modify the REST API and SDK user access from the Users tab, instead editing into a user account.
3. Modifying Mobile Application and Browser Extension AccessTo modify the mobile application access for the users,
To modify the browser extension access for the users,
Note: Mobile application and browser extension access cannot be modified for the currently logged-in user accounts. 4. Deleting the PAM360 User AccountUsers with the provided operation can delete users from PAM360 who are no longer necessary for the organization. To remove a user from PAM360,
Note: Users imported from AD, Microsoft Entra ID, and LDAP directories cannot be moved to Trash. Notes: The below notes apply for both permanent deletion and deletion from trash. ![]() 4.1 Restoring Users from TrashTo restore a user account that has been moved to Trash, go to the Users tab and click on the Trash icon located at the top right corner. A list of users in the Trash will appear in a pop-up box, allowing you to select and restore the desired users. Since PAM360 requires that the resources owned by a user be transferred to another user before deletion, there will be no loss of enterprise data. However, all personal data stored by the user will be permanently deleted. The audit trails will comprehensively record all such changes and deletions. The audit trails documenting the user's activities will remain intact in the database even after the user is deleted. Audit trails relevant to the deleted users will not be erased. 4.2 Deleting an Administrator User AccountBefore proceeding to delete an administrator user account, check for any resources owned by the user. If exist, the resources should be transferred to another user with an administrator-type role by the resource owner by following the below steps,
Note: The logged in administrator cannot delete their own user account from PAM360. Upon successful ownership transfer, the administrator user account can be deleted from the PAM360 by another administrator. 4.3 Handling User Accounts Deleted from Active Directory/Microsoft Entra ID/LDAP DirectoriesWhenever a user account is deleted directly at the user directory from which it was imported to PAM360 i.e. from Active Directory, Microsoft Entra ID or LDAP directory, PAM360 identifies those deleted user accounts at the time of next synchronization schedule. The identified user accounts are then subsequently disabled in PAM360 and held as locked accounts. Note: PAM360 will identify deleted user accounts only if you have set up synchronization with the respective user directory. After disabling the user accounts, PAM360 informs the administrators or users with user management privileges via email as well as an alert notification within the product. Clicking the alert notification will open a dialog box as shown below: The administrator can review the locked accounts and then choose to delete those user accounts permanently from PAM360 by clicking the Delete button. Further, the administrator can also review the locked accounts directly using the user filter provided in the Users page and can delete the disabled accounts individually or in bulk. On the other hand, to activate the accounts,
5. Managing Notification Email Addresses in PAM360PAM360 allows you to configure generic email addresses as recipients of notification emails for scheduled tasks' completion statuses and license expiry alerts. You can keep track of all such external email addresses being used in PAM360 and also delete them if needed. Additionally, the email addresses of users captured in the User Sessions audit can also be managed using this provision, in the event of those users being removed from PAM360. To view the list of notification email addresses,
| |