Installing PAM360 Agent26 minutes to read
The PAM360 agent can be deployed on remote devices that are not directly connected to the PAM360 server to facilitate PAM360-related operations or to collect device data for implementing a Zero Trust security model, depending on the installation option selected. Installing the PAM360 agent on your target systems is essential for extending the capabilities of PAM360, enabling secure management of privileged remote resources that are not directly connected to the PAM360 server. This document provides detailed steps to install, manage, and uninstall the PAM360 agents on Windows, Windows Domain, Linux, and Mac devices along with the necessary information to configure the required agent settings. Before proceeding with the installation procedure, ensure that the account you use to install the agent on the remote host has sufficient privileges to carry out these operations. Note: Administrative/root privilege is required in the target system for agent installation and management. This help document covers the following topics in detail:
1. Downloading the PAM360 AgentsFollow these steps to download the PAM360 agent package on your machine from the PAM360 web interface.
2. Configuring Agent SettingsNote: While installing the PAM360 Windows agent, the agent properties are displayed on the agent installation wizard, allowing you to modify the parameters during installation. For Linux and macOS agents, the agent properties can only be updated by editing the agent.conf file. Open the agent.conf / agent.json file from the downloaded agent package. Below are the parameters listed in the agent file, many of which can be customized to meet your specific requirements:
PAM360 allows the restriction of user accounts that are added via agents (C# and Go) during account discovery, using regex patterns. To do the same, use the below UserQuery and accountFilter commands:
The commands UserQuery, accountFilter and fetchDisabledAccount are applicable from build 5301 and later only. Once any of the above parameters are modified, restart the agent service. 3. Installing Windows/Windows Domain Agent in the Resources/User Devices3.1 Installation using Command Prompta. To Install the Agent in the Resources
b. To Install the Agent in the User Devices for Zero Trust Approach
c. To Start the Agent Service in the Resources/User Devices
d. To Update the Agent in the Resources In case the PAM360 agent was previously installed by a different administrator, use this command to update the user account under which the agent server will be added as a resource. The agent server will be added as a resource under the new admin user without the need to uninstall and reinstall the agent. However, the new administrator will not have access to the accounts that were previously under the agent server. To gain access to the accounts, the previous admin has to transfer the ownership of the resource to the new admin.
e. To update the Agent in the User Devices for Zero Trust Approach
f. To Stop the Agent Service in the Resources/User Devices
3.2 Installation using PAM360 Agent Installer | |