Emergency Measures in PAM360

Establishing well-defined emergency procedures is critical when suspicious activity is detected in PAM360 or when immediate containment measures are required. In such situations, privileged administrators can temporarily restrict specific communication channels to and from the PAM360 server to limit potential attack vectors, prevent unauthorized access or further interaction, and contain the impact of a security incident. These measures help privileged administrators respond quickly to emerging threats while allowing time to assess the situation, investigate the source of the activity, and determine the appropriate remediation steps.

PAM360 provides the following options to restrict specific communication channels during an emergency:

You can disable one or more of these options based on the nature of the security incident and the communication channels that need to be restricted.

Caution

Disabling an access channel may affect the corresponding PAM360 features, applications, integrations, or services. Enable these options only when required as part of your organization's emergency response procedures.

Configure Emergency Measures

Follow these steps to configure emergency measures:

  1. Navigate to Admin >> Server Hardening >> Emergency Measures.
  2. Select the required options:
    • Disable API Access
    • Disable Agent Access
    • Disable SCIM API Access
    • Disable Application Gateway Access
  3. Click Save.

The selected communication channels will remain restricted until the corresponding options are deselected and the changes are saved.

Additional Emergency Actions

Depending on the nature of the security incident, you may also need to take additional containment or communication measures:




Top