Chapter 2: Active Directory Domain Services 2022 Flashcards
(6 cards)
How does PAM work with AD 2022?
A user is added to a group with a Time-to-Live (TTL) value and, once it expires, the user is removed from the group automatically.
Describe JEA (Just enough administration)
Enables delegated PAM for anything managed by PowerShell for a set amount of time.
What are the four steps of implementing privileged access management?
- Prepare
- Protect
- Operate
- Monitor
Describe how PAM is prepared?
Identify the privileged access groups in your
existing AD forest and start to remove users from them
How does PAM protect authentication and authorization?
By defining how a user can request privileged
access when required and how the requests
will be handled
Describe how PAM operates
Once the privileged access request is approved, the user account
will be added to the security group and will only be valid for the time defined by the authorization policy