Solution
To solve the mentioned tasks, the Indeed Privileged Access Manager (Indeed PAM) software suite is used. The suite stores privileged accounts centrally and manages them.
Indeed Privileged Access Management has the following features.
Password Management Functions
- Granting an administrative access (or session) without revealing the privileged account password
- Regular change of passwords for privileged accounts
- An opportunity to grant administrative access to the defined resources (servers) only.
Supported account types
- Microsoft Active Directory
- Windows OS accounts
- Linux OS accounts (passwords and SSH-keys)
- Accounts for access to networking hardware
Search for privileged accounts
The Indeed PAM contains a module that searches for privileged accounts, registers those in the system and prompts to get those under control.
Regular automatic change of passwords for privileged accounts
The Indeed PAM regularly changes the passwords of privileged accounts to a random value, complying with the requirements to both the complexity of passwords and the interval between password changes.
General architecture scheme of Indeed PAM to solve the password management task is given below.