In today’s digital landscape, where data breaches and cyberattacks increasingly target privileged accounts, securing privileged resources and their associated accounts has become critical. This begins with an understanding of what privileged resources are, their attributes, and how to manage them securely.
ManageEngine PAM360 is a comprehensive privileged access management solution designed to regulate and monitor access to sensitive accounts across various organizational resources. In PAM360, privileged endpoints can be added as resources and managed securely. The type of resource depends on the underlying endpoint, and PAM360 supports a wide range, including databases, servers, applications, network devices, and cloud services. Each resource type comes with its own set of parameters that govern access, authentication, and usage. If your organization’s endpoint is not available as a predefined resource type, PAM360 allows you to configure and manage it as a custom resource type, thereby ensuring consistent protection against unauthorized access and potential security threats.
This document provides an overview of the resource types (i.e., privileged endpoints) supported in PAM360, along with the key attributes that PAM360 requires to access, authenticate, and manage the resource.
Currently PAM360 supports 85+ distinct resource types, each serving specific functions within an organization's infrastructure. These resource types are categorized based on their functionality, making identification and management easier. However, PAM360 does not restrict users to these predefined types. You can create and manage custom resource types from the Resources tab. This flexibility allows you to tailor PAM360’s resource management capabilities to meet your organizational requirements. Out of the box, PAM360 supports various resource types as shown below:
Operating System
Cisco Devices
Cloud Devices
| Network Devices
| Database Servers
File Stores
MQ Applications
Enterprise Applications
Others
|
Attributes are key parameters that define and distinguish a resource within a network. In PAM360, these attributes form the foundation for identifying and managing these devices and endpoints within your network. Each resource type, such as servers, applications, or cloud services, features its own set of attributes that enable PAM360 to securely connect to the resource and perform the resource and password management operations. The following sample image shows the list of attributes associated with the Windows resource type.
Similarly, each resource type features its own set of attributes. While some resource types may share identical attributes, others may feature unique or additional attributes specific to them. This section provides a comprehensive understanding of attributes associated with each resource type and details their significance in resource management. The following list defines each attribute, describing its purpose, usage, and relevance in the context of resource configuration and management within PAM360.
Additional Details
The DNS name for all resources, except cloud services, is specified as a tree of domain names. However, for cloud services, it is specified as a URL. Example., abc.manageengine.com for resources and https://identity.api.rackspacecloud.com/v2.0 for cloud services.
Caution
When adding a resource, ensure that you enter the complete resource URL in this field to enable proper access to the web application. For example, https://sso.godaddy.com can be entered to access the GoDaddy Single Sign-On portal. Alternatively, to establish an HTTPS Gateway Connection to the resource, you can also specify the appropriate HTTPS-based web link in this field.
The Windows resources feature all twelve attributes listed above. The Windows Domain resources feature an additional attribute in addition to the above-mentioned list: Secondary DC DNS Name. This attribute denotes the DNS name or IP address of the secondary domain controller to which the resource is associated. It ensures uninterrupted access to the resource in the event of a failure of the primary domain controller. Other resource types within the Operating Systems category, and those in the Cisco Devices and Network Devices categories, feature ten of the above-listed attributes. Similarly, the resource types in the Database Servers, File Stores, and MQ Applications categories feature nine of the above-listed attributes. Certain resource types feature specific attributes that are unique to them. The Azure App resource type features two such attributes that are crucial identifiers used for authentication and authorization purposes. These attributes are:
Caution
All resource types do not share the same set of attributes. The inherent attributes vary depending on the resource type and their management requirements.