Feature Request - Support for Custom AD Attributes in PAM Account Scanning

Feature Request - Support for Custom AD Attributes in PAM Account Scanning

1 vote

avatar

Hi Devolutions Team,
We are currently using Devolutions PAM to manage accounts across multiple remote domains and have implemented a solution to map remote accounts to personnel in our local domain (where Devolutions Server/RDM is hosted). This mapping enables us to automatically apply appropriate permissions to each PAM account within our PAM vaults.
Current Workflow:
Our current process relies on custom Active Directory attributes set on remote AD accounts. We:

  1. Export the entire AD catalog from the remote domain
  2. Run a custom script to match remote AD accounts to Devolutions users based on these custom attributes
  3. Apply permissions accordingly

This workflow is functional but requires manual intervention and external scripting.
Feature Request:
We would like the ability for Devolutions PAM to read and import custom AD attributes during account discovery. Specifically:

  • Capability: Extract custom AD attributes (beyond standard attributes) during PAM scans
  • Configuration: Option to specify custom attributes at either the PAM Provider or PAM Scan Template level
  • Storage: Store these attributes as metadata on PAM accounts
  • Use Case: Enable automated permission mapping and other business logic based on custom AD data

Technical Feasibility:
Since PAM already performs LDAPS queries to retrieve standard AD attributes during account discovery, extending this to include configurable custom attributes should be technically achievable.
Business Value:
This enhancement would:

  • Eliminate manual export/import processes
  • Reduce administrative overhead
  • Enable real-time synchronization of custom metadata
  • Improve automation capabilities for permission management

Would this be something you could consider for a future release? We'd be happy to provide additional details about our use case if helpful.
Thank you for your consideration.
Best regards,
Tony

All Comments (0)