PAM360 offers the flexibility to access its features through the PAM360 mobile application. The PAM360 mobile application in Android supports the powerful and efficient functionalities of the PAM360 solution to your fingertips, enabling you to manage and control your organization's privileged accounts and passwords with ease and security from your mobile device.
The mobile application offers several advantages, such as enhanced flexibility , monitoring capabilities, and overall security management of the privileged resources in your environment. You can access and manage your privileged resources and accounts just as securely as on PAM360's desktop installation. The app encrypts and stores all your data with AES-256 encryption, ensuring the highest level of data protection. Additionally, all the communication between the PAM360 server and the Android application is secured over an encrypted channel using the HTTPS protocol over SSL.
With the mobile application, you can actively view resources, accounts, SSL certificates, CSRs, and SSH keys while managing sensitive personal information. With the suite of features it offers, the PAM360 Android application ensures that you maintain control over your organization's critical resources on the go. This guide aims to familiarize you with its key features, setup process, and operational functionalities, allowing you to leverage the PAM360's mobile capabilities.
Caution
This document will guide you through the following topics:
The PAM360 mobile application offers a comprehensive suite of features to help you manage privileged accounts and resources within your environment effectively, even when you are away from your desktop. The following table highlights each feature and its purpose, helping you make the most of PAM360 on the go.
| Capabilities | Description |
|---|---|
View Passwords | Access passwords you own or manage for quick reference. |
Request Password Access | Send password access requests for resources shared with you with configured access control workflow. |
Manage Access Requests | Approve or reject access requests directly from your mobile device. |
Check In/Out Passwords | Check in or check out passwords as needed. |
View Resource Groups | See all resource groups that you own, manage, or those shared with you. |
Launch Remote Sessions | Initiate RDP sessions to Windows resources directly from your mobile device. |
View SSH Keys | Access stored SSH keys for your managed resources. |
Manage SSL Certificates | View, create SSL certificates, and generate CSRs as needed. |
Personal Password Management | Securely view and manage personal passwords stored within the personal tab. |
Advanced Search | Locate specific resources or accounts |
Offline Access | Cache essential passwords for uninterrupted offline access. |
The PAM360 mobile application supports Two-Factor Authentication (TFA) for enhanced security. Once enabled, users must authenticate through two successive stages to access the PAM360's mobile interface. The first level of authentication can be achieved in one of the three following ways: PAM360's native authentication, Active Directory/LDAP/Microsoft Entra ID credentials, SAML SSO. The second level of authentication can be performed using any of the TFA provisions supported by PAM360. Refer to this document to see the different TFA provisions supported by PAM360. Administrators can selectively allow or restrict mobile application access for users. To restrict mobile access:


To allow password caching for users, follow these steps:

To securely access and manage your privileged accounts on the go, you must first set up the PAM360 Android application. Installing the PAM360 mobile app is as simple as installing any other mobile application. Follow these steps to install the application:
Once the installation is complete, launch the ManageEngine PAM360 app and enter the following required details to get started:
Additional Detail
If you are a PAM360 MSP user, you will be prompted to enter your organization name after entering the server name/IP address. Users created under specific organizations must enter their respective organization names in the Organization field to access their PAM360 accounts. Entering an incorrect or invalid organization name will prevent access to the PAM360 account.



Caution
Upon logging into your PAM360 account through the Android application, you will see the Menu icon in the bottom-left corner of the home screen. Click the menu icon to reveal the Navigation Menu, which will slide up from the bottom. You can switch between MSP and client organizations through the navigation menu if you are a PAM360 MSP user. This section provides instructions for managing client organizations in the PAM360 mobile application.
PAM360's Android application empowers MSP administrators to manage administrative passwords for different client organizations separately from a single management console. The application categorizes client organizations into distinct sections, allowing you to tap and view all the associated passwords within a specific organization.



As an MSP admin, you can view and manage all the organizations under your management. Click the Menu icon on the bottom-left corner of the screen, then select the organization name under your account name. On the Organization page, you will see a list of all the organizations that you manage. Select the desired organization to view and manage all the associated resources within that organization. However, you can only view the resources within these organizations if you have added them or if they are shared with you. Users from client organizations can only access the resources belonging to their respective organizations.
The Navigation Menu is designed to provide quick and easy access to various functionalities available in the mobile application. It is divided into the following sub-sections, each serving a specific purpose to streamline the management of your privileged accounts and resources.
You will see the Enterprise view upon logging into the PAM360 application. Here, you can view a list of all the resources you own, manage, or those shared with you. To view the resource and account details:






The enterprise filters include the following:




Users can request access to a password associated with a resource configured with access control workflow. To request a password for an account/resource shared with you, tap the desired account and select the Request option beside the account name. In the Password Request window, enter the reason for requesting access to the selected account and click OK. Once you request a password, the status will change to Waiting for Approval. After an authorized administrator approves your request, the password will be available for Check-Out.



Upon checking out the password, the status will change to In Use, which will be visible to other users in both the Check-In tab and the Account Details section of the account. To relinquish access, click the Check-In option to return the password to the PAM360 vault. If you need access to the password again, you should repeat the request-release workflow. If your PAM360 server is integrated with a ticketing system, you must provide a valid ticket ID along with the reason for the request in the Password Request window while requesting password access or launching RDP sessions. PAM360 will validate the ticket ID with the ticketing system before granting access to the password or initiating the RDP session.


Additional Detail
Starting from PAM360 build 5530, you can launch RDP connections to remote resources directly from the PAM360 Android application.
PAM360 enables administrators to manage password access requests via the PAM360 mobile application. Administrators can view and act upon pending and approved password access requests on the Password Access Requests screen. This section is divided into two tabs: Pending and Check-In.


The Advanced Search feature in PAM360's Android application enables you to locate specific resources or accounts. To use this feature, select Advanced Search from the navigation menu. This section contains two tabs: Enterprise and Personal. You can either enter a keyword in the provided search field and apply one of the available search filters to refine your search. The filters available on the Enterprise tab include, Resource Name, DNS Name, User Account, Resource Type, Resource Description, Department, Location, Domain Name, and Resource URL.
Similarly, the filters available on the personal tab include, Web Accounts, Banking, Credit Cards and Contacts.



Additionally, any custom fields added in the enterprise section and the custom categories created within the personal tab in PAM360's web interface will be available as filters in the Advanced Search section, allowing you to tailor the search function to meet your custom needs.
Caution
You can view all the resource groups you own or those shared with you via the PAM360 mobile application. Select the Resource Groups option from the Navigation Menu to access the resource groups you own or manage. If a resource group has subgroup(s), a right arrow icon will be displayed beside the group name. Click the arrow icon to view the available subgroups. Tap the respective resource group/subgroup to view the list of resources available under that specific group. Select the desired resource to view the list of accounts available within that resource, and tap the desired account to view its details.




To view the SSH keys you own or manage, select SSH Keys from the navigation menu. On the SSH Keys screen, you will see a list of all the SSH keys you own or those shared with you. Tap the desired SSH key to view its details, including Key Type, Length, Fingerprint, Age, and Owner.


To view the SSL certificates, select Certificates from the navigation menu. On the Certificates screen, you will see a list of all the SSL certificates you own and manage. Tap any SSL certificate from the list to view its details, including Common Name/IP Address, Port, Validity Period, SAN, Issuer, Signature Algorithm, Fingerprint, Serial Number, Key Algorithm, and Key Size.
Additionally, you can create an SSL certificate from the PAM360 Android application. To create an SSL certificate, follow these steps:
Your SSL certificate will be created and added to the list. You can view it anytime from the Certificates screen.



Caution
The Create Certificate functionality is supported in the Android application from PAM360 builds 6200 onwards.
The PAM360 mobile application lets you view the Certificate Signing Requests (CSR) created on the web interface. Tap the CSR button from the navigation menu to view the CSR list. Additionally, you can create CSR in the mobile application by following the steps detailed below.



Your CSR will be added to the list. You can view it anytime from the CSR screen.
Caution
You can access the personal data stored within the personal tab from the PAM360 mobile application. Before you can access the personal tab on the mobile application, you must first set a passphrase for the personal tab via the PAM360 web interface. Once you set up a passphrase, you can add your personal details, such as Web Accounts, Banking, Credit Cards, and Contacts, and access them via the mobile application. When you access the Personal tab via the mobile application for the first time, you will be prompted to set up a swift login option, eliminating the need to enter your personal passphrase every time. You can choose from the following options: Biometric, PIN, or Device's Screen Lock. Select None if you prefer not to set up Swift Login for your account.


Upon entering the Personal tab, you will see the list of available categories. The custom fields and categories added to the personal tab via the PAM360 web interface will be available on the PAM360 mobile application while adding an account to the personal tab. Select the desired category to view the list of accounts available under that particular category.


Additional Detail
PAM360 android application provides TOTP support for personal accounts from version 2.8.0 onwards.
On the respective Category page, you can:


To exit the personal tab, tap the Lock icon at the top right corner. You will return to the home screen, and the personal tab will be locked. To access the data stored in the personal tab again, you must reenter the passphrase or authenticate using the configured Swift Login method.
The Settings menu on the PAM360 Android application offers a comprehensive collection of options organized into different categories, enabling you to customize and secure your mobile application experience based on your preference. Tap the Navigation Menu icon on the home page and select the Settings option to access the PAM360 mobile settings. On the Settings page, you can view and manage login options, customize various security and privacy settings, review the privacy policy, and modify general application settings.



These settings are organized into various categories as shown below:
1. Login
Additional Detail
If the High Availability feature is enabled in your environment, the secondary server address is also displayed under the Login section.
2. Smart Login
The Smart Login feature in PAM360 offers a seamless way to access the PAM360 web interface by scanning a QR code displayed on the web login page using the PAM360 mobile application. This direct login method simplifies the process, providing password-less authentication and significantly reducing the effort required for web login while maintaining robust security. To log into the web application using the Smart Login option, follow these steps:
Additional Detail
To access the PAM360 web interface using the Smart Login method, enable the Smart Login option on the Admin >> Customization >> General Settings >> User Management page.
3. Security
Additional Detail
To enable fingerprint login in the mobile application, navigate to Admin >> Customization >> General Settings >> User Management and enable the Enable logins to mobile apps with fingerprint authentication option.




4. Privacy
5. Themes (UI Mode) - Tap on this option to change the theme of the PAM360 Android application. You can choose between Light, Dark, or Battery Saver mode.
6. General


PAM360's Android application provides a secure offline mode that enables you to access the privileged passwords in your environment when you do not have access to the internet.
To access passwords in offline mode, you must download the required passwords first. To download passwords for offline access, access the Enterprise Filters, and click the downward arrow beside the required list of passwords. The application allows you to download a group of passwords from the Enterprise section using the enterprise filters. Tap the download icon on the top-right corner of the screen on the desired filter view to download all the associated resources along with their corresponding accounts and passwords. For example, tapping the download icon on the Favorites view will download all resources and their respective accounts marked as favorites for offline access. Additionally, you can download resource groups and personal passwords for offline access.
Additional Detail
The Secure Offline Mode is enabled only when the Allow password caching for offline access via mobile option is enabled in the Admin >> Customization >>General Settings >> User Management page.
Click the Wi-Fi icon on the top-right corner of the Navigation Menu to switch between offline and online modes. In offline mode, you can access previously cached passwords and other data. Offline mode is useful when you are not connected to the internet or while working with sensitive information without an active connection. In online mode, the application syncs with the PAM360 server, allowing you to access real-time data, request passwords, and manage resources as usual. Ensure you switch to online mode to update or retrieve the latest information from the PAM360 server.
The PAM360 Android application provides two widget options: Smart Login and Password Access Requests. These widgets enable quick access to PAM360 functionalities, allowing users to log in seamlessly and manage access requests efficiently.
This widget displays the number of password access requests awaiting administrator approval. Tapping the widget opens the Password Access Requests section in the mobile application, where administrators can approve or reject pending requests.
The Smart Login widget allows users to securely log into PAM360 via a web browser using the smart login feature.
Once authenticated, you will be logged into PAM360 without manually entering credentials.
Additional Details
If you face any issues with the mobile application, get in touch with our technical support team.