Managing General Settings26 minutes to read
Using the General Settings section of PAM360, you can carry out important setting changes such as enforcing Password Policies, enabling the Forgot Password option to reset user passwords, configuring to send Email Notifications on user creation or role modification, provision for managing Personal Passwords, exporting resources, remote password reset and so on. Configuring General SettingsTo configure the general settings in PAM360, navigate to Admin >> Settings >> General Settings. You will see different settings categorized under the following sections. Click each link to view the details:
1. Password RetrievalTo view and manage all global settings related to password retrieval, click Password Retrieval from the left pane. 1.1 Allow plain text view of passwords, if auto logon is configuredEnable this option to allow the users to view the passwords of shared resources in plain text when auto logon is configured. If this option is disabled, users cannot retrieve the password, however they can still launch remote sessions through auto logon. This restriction applies only to Password Users, Password Auditors and custom user type roles with the same privileges as Password Users and Auditors. 1.2 Allow Autologon for URL-configured resources via the browser extension, if plain text view of passwords if disabledEnable this feature to allow users to log in to websites and web applications without entering the credentials manually. While enabling this option, ensure that you have enforced the necessary security measures in the client-side browser and user systems. 1.3 Automatically hide passwords after 10 seconds (specify '0' to never hide passwords automatically)By default, passwords are hidden behind a string of hash symbols. On clicking the string, the passwords appear in plain text. By default, the passwords are shown for 10 seconds only, after which they will be automatically hidden. Specify the desired value in seconds in the Automatically hide passwords after X seconds option. If you specify 0, passwords will continue to remain in plain text until you click the password to hide. 1.4 Maximum X approval admins (You may give minimum of 1 to maximum of 10 admins)Select a maximum number of admins (up to 10 admins) needed to approve a password request for resources which have the password access control workflow set up. The number of admins selected here will reflect in the Password Access Control workflow configuration, under the option "Enforce approval by at least __ administrators". 1.5 Automatically clear clipboard data after 30 seconds (specify '0' to never clear clipboard automatically)PAM360 uses the clipboard utility of browsers to copy passwords when you copy them from PAM360. By default, the copied passwords will be available for 30 seconds. In this option, specify the time in seconds after which the clipboard will be cleared and the copied password will no longer be available. If you specify 0, clipboard will not be cleared automatically. 1.6 Enforce users to provide reason for password retrievalEnable this option to enforce users to provide a reason for requesting access to the password. This reason for retrieval will be recorded in the audit logs. 1.7 Allow users to retrieve password without ticket IDIf ticketing system integration is done in your environment, then by default, users will be prompted to provide a ticket ID while requesting for a password. Enable this option to allow users to retrieve passwords without providing a ticket ID. 1.8 Display password history for users with View Only and Modify share permissionsPassword History (available under Account Actions) shows the previously used passwords for a particular account as well as the details on who modified it. Enable the option Display password history for users with View Only and Modify share permissions to display the password history details for users with View Only and Modify share permissions. 1.9 Allow all admin users to manipulate the entire explorer treeOnce this option is enabled, PAM360 creates an organization-wide, global explorer tree structure containing the names of resource groups under a root node and the following things will apply:
Show unshared resource groups to all admins: If this option is enabled, resource groups of all the admins will be available visible to other admins but they will be disabled as the resource groups are not shared. If this option is disabled then only the shared resource groups will be available for the admins. 1.10 Collapse password explorer tree view in Resources and Connections tabBy default, the nodes of the password explorer tree are shown in expanded form. Enable this option to collapse the explorer tree view. 1.11 Disable SSH, SQL and Telnet console chatBy default, SSH, SQL and Telnet console chat will be enabled. Select this option to disable the console chat for remote sessions. 1.12 Allow users to download the private keyIf this option is enabled, the user will be able to download the private key that is added to an account shared with them. Click here for more about adding a key to an account. 2. Password ResetTo view and manage all global settings related to password reset in PAM360, click Password Reset from the left pane. 2.1 Enforce users to provide a reason when changing the resource passwordEnable this option to prompt users to enter a reason while attempting to change the password of a resource. This reason will be recorded in the audit logs. 2.2 Allow users to reset password without giving a ticket IDIf ticketing system integration is done in your environment, then by default, users will be prompted to provide a ticket ID when they try to reset the password of a resource. Enable this option to allow users to reset passwords without providing a ticket ID. 2.3 Default selection for user-initiated remote password change action. Users can override this setting while modifying passwordsWhen changing the password of a resource in the PAM360 console, by default the password changes are applied in the remote resource instantaneously. (Resource types supported for remote synchronization are: Windows, Windows Domain, and Linux). Select the option Do not apply changes to the resource to not change the password in the remote resource automatically. 2.4 Wait for X seconds between stopping and starting the services after service account password resetYou can configure PAM360 to wait for a specified time (in seconds) before stopping and restarting the services after automatically resetting the service account password. This is useful in cases where service account password reset is enabled for a Windows Domain account and the corresponding domain password is changed. 2.5 Enforce users to provide two different accounts for use with remote password reset for UNIX / Linux resourcesEnable this option to enforce users to provide provide two different accounts for password reset for Unix/Linux resources. If this option is disabled, then users will be allowed to enable remote synchronization with just one account. To know more about remote password reset, click here. 3. Resource/Password CreationTo view and manage all global settings related to resource/password creation in PAM360, click Resource / Password creation from the left pane. 3.1 Enforce password policy during resource or password creationBy default, password policies are enforced for passwords in PAM360 only at the time of password change. Enable this option to check policy compliance at the time of resource/account addition itself. Once you enable this, you will be permitted to add your resource / account only if the password is in accordance with the password policy defined in PAM360. When agents are deployed in resources for remote password reset, the accounts in the resource are automatically added to PAM360. There is also option to synchronize account addition or deletion afterwards.
4. Resource Group ManagementTo view and manage all global settings related to resource group management in PAM360, click Resource Group Management from the left pane. 4.1 Resource group creation optionsYou can allow users to create:
Select the required option and click Save. 5. Remote Session Management
| |