0 vote
Hi
I would like to suggest an idea related to providers in PAM. In a cloned multi-environment, meaning each environment (PROD, UAT, DEV) is a clone of the production environment, Domain controllers are also replicated with the same name, etc. The environments are seperated on a network level. This causes an issue, when wanting to manage accounts in the different environments, as it is not currently possible to refer to domain controllers other than by name.
"DomainController_A" in PROD can only be added once as a PAM provider (assuming DVLS server is running in PROD), while "DomainControlller_A" in DEV can not be added. Thereby, the accounts in DEV can not be managed by the PAM module.
It would be beneficial if support for such environments can be implemented.
Maybe the "easy" way of doing it, is allowing to reference the domain controllers by IP addresses, which would be different in each environment. Meaning that you are able to reference the domain controllers by a set of IP addresses (additionally being able to asign a display name per IP address in the DVLS interface, for each DC), so that the PAM module is not dependent on one DC, but rather the full set of DCs for availability purposes.
Another possible solutions could be having an "agent" in each environment, talking back to the DVLS server, allowing DVLS Server and the agents to handle identity of DCs, password and account management etc. with custom IDs for each DC, completely not relying on the actual environment setup. Maybe a more bullet proof solution and also more compatible with different customer environments.
Thanks!
Hello,
Thanks for your request. In the latest version 2023.3 you should be able to refer to the DC in the PAM Provider by IP address, and you can name each of your PAM providers a display name. You should be able to setup separate PAM providers for each environment.
Please let me know if you have problems with this and I can help you configure it, or if we need to make changes I can understand more the problems you are facing and ensure that our PAM providers support your needs. I'm also happy to jump on a call and you can show me exactly what you would like to do.
Best Regards,
Paul Dumais
Thanks for the response! I was initially told, by the support, that this was not the case, and it was suggested that i make this feature request, hence why we are here. Happy to hear that it is indeed possible.
I will give it a look, when i get to it. Otherwise, i will reach out for assistance.
Thanks!
Great to hear. Yes please send me a message and I can assist anytime.
Paul