Configure PAM
Introduction
Once the Jump servers have been installed, following the steps defined on the PAM Jump Server installation page, it will be mandatory to configure the jump servers on the Soffid Console, to do that you can visit the Configure PAM session servers page.
Soffid console provides you a powerful tool, that is Network discovery tool. It is able to identify the machines in each defined network and retrieve information about user accounts, also, it can detect system accounts. Visit the Network discovery page for more information.
Once the machines and Accounts, both user and system, have been discovered, the critical accounts must be located in a protected storage, the Password Vault. It is importan to identify the ownership, and assign properly those accounts to a specific user or a group of users.
Then it is able to configure workflows or approval processes in order to use these accouts. Some accounts, the really risk accounts, need request for permission to use them.
All the sessions will be recorded (Screen, KeyBoard, Clipboard and File transfers).
The ability to configure and manage PAM policies gives Soffid a great power in terms of privileged account management. In this line, it is possible to configure policies based on rules, so when each one of the rules is fulfilled, one or more actions will be triggered according to the configuration. The available actions are to close the session, lock the account, open an issue on a ticketing system and notify the breaking rule. You can find more information visiting the PAM Rules page and the PAM Policies page.
When you have defined the rules, it is essential to indicate when Soffid has to taken in mind them. That can be configured on the Password Vault page, here it is ability to indicate the policy for each folder, or none if there are not policy to apply. When you define a policy for a folder, that policy will apply to all accounts hanging from this folder.
Soffid provides you the functionality that allows searching in PAM recording sessions. With that option you can search recondings video applying serveral filters, for instance, you can search all the recordings videos in which the user write the command "rm" or all the recording videos in which the user write "cat FILE_NAME". For more information visit the Search in PAM recordings page.
Quick access
Links to functionality on Soffid Console related to the configuration of privileged accounts are provided below:
- PAM Jump Server installation
- Configure PAM session servers
- Network discovery
- Password Vault
- Accounts
- PAM Rules
- PAM Policies
- Search in PAM recordings