We manage multiple services that consist of server groups. For example, the "File" service contains approximately 30 servers . Access to each server is controlled through an Active Directory security group, which includes all authorized users, including those managed through Devolutions PAM .
Currently, a dedicated PAM account must be assigned to each server, resulting in a large number of privileged accounts that need to be created, managed, and maintained.
However, in our environment, there are never more than three administrators working concurrently across the servers of the same service group. Therefore, maintaining 30 separate PAM accounts provides little operational value.
We would like to request a Shared PAM Account Pool feature for service groups. Instead of assigning a dedicated PAM account to every server, a configurable pool of accounts could be shared across all servers within a service group. In this example, a pool of three PAM accounts would be sufficient for all 30 file servers
.
When an administrator requests access to a server within the service group, an available PAM account would be automatically allocated from the pool. Once the session is completed and the account is checked back in, it becomes available for the next administrator.
Important: A Just-In-Time (JIT) approach that creates a new account on demand and deletes it after use is not a suitable alternative in our environment. The required waiting time for Active Directory replication can introduce delays and negatively impact operational efficiency. We require immediately available privileged accounts without dependency on AD replication timing.
Benefits
Significant reduction in the number of PAM accounts that must be managed.
Lower administrative overhead.
Faster onboarding of new servers into existing service groups.
Improved scalability for large environments.
Better alignment between the number of PAM accounts and the actual number of concurrent administrators.
No delays caused by AD replication as can occur with JIT-created accounts.
This feature would provide a practical and efficient solution for organizations where servers are managed in service-based groups and concurrent administrative usage is considerably lower than the total number of managed systems.