Hi Inbaselvan, No, that would be a problem. The AD accounts are managed in Active Directory, they cannot be managed from a domain member. And think of the case where a domain admin is in the Administrators group of hundreds of domain members, which is quite common. You wouldn't want PAM to have hundreds of target accounts for the same AD account, they could not stay in sync. The discovery has to be limited to local accounts.
Original Message:
Sent: 03-26-2020 06:32 AM
From: Inbaselvan R
Subject: WIndows domain account discovery
Hello Team,
Using Account discovery, we are able to discover the Windows local accounts but not able to discover the domain accounts which are added to local admin groups.Do PAM support discovery of accounts from local admin groups?Please let me know your thoughts on this.
Regards,
Inbaselvan R