Devolutions PAM Configuration for JIT Provisioning and JIT Elevation (Lab Series #4)
May 27, 2026
After we completed most of basic set up for Devolutions Servers in previous video, now it comes to the configuration of JIT access provisioning and JIT privilege elevation.
This video will cover lots of fundamental PAM configuration: license, domain authenticaiton, Domain User provider, PAM vault, Permissions to vault, Just in time access provisioning, and just in time privilege elevation.
Related Post:
✍Devolutions PAM Getting Started (Policies) and Gateway Installation - https://blog.51sec.org/2026/05/devolutions-pam-onboarding-getting.html
✍Install Devolutions Server and RDM Connecting to Data Source - https://blog.51sec.org/2026/05/install-devolutions-server-and-rdm.html
Related Videos:
🌟Install RDM & Gateway, Connect to Devolutions Server, Enable Session Recording (Devolutions LAB 2)
🌟Install Devolutions All-In-One PAM LAB Server from Scratch (Devolutions LAB 1) - https://youtu.be/Ct3uyYZzfMs
🌟Import Cert for Devolutions Gateway, Enable Open-in-browser feature (Devolutions LAB 3) - https://youtu.be/D8SEYXgu69s
🌟Devolutions PAM Configuration for JIT Provisioning and JIT Elevation - https://youtu.be/cA70STYJQ_w
💖Chapters:
0:00 - Introduction
0:55 - Lets start it
2:40 - 1. License and Enable Domain Authentication
5:11 - 2. Enable PAM for Admin
6:26 - 3. Accounts Discovery, Accoubts Onboard, Manage Privileged Accounts
13:24 - 4. JIT Privilege Elevation & JIT Access Provisioning
23:21 - End Scene
✅#51Sec #NetSec #Cyber #Security #CyberSecurity #HomeLab
If you found this video has some useful information, please give me a thumb up and subscribe this channel to get more updates:
⚡https://www.youtube.com/c/Netsec?sub_confirmation=1
⚡Resource Collection and Bookmarks: https://sites.51sec.org/
Learning and Sharing - 🔊海内存知己,天涯若比邻! A bosom friend afar brings a distant land near!
Discord: https://discord.gg/fCW9phn, Blog: https://blog.51sec.org
Show More Show Less View Video Transcript
0:01
[music]
0:06
>> Hello everyone. Let's continue our
0:08
Delinea PAM journey.
0:11
This is our third one in this series.
0:14
Previously, we already talked about how
0:16
to install Delinea server, how to
0:18
install RDM plus gateway, and how to
0:22
configure
0:24
monitor session, remote access,
0:27
web session, all those basic stuff using
0:31
a free Delinea server.
0:34
In this video, I'm going to show you how
0:35
to add license to learn you can test it
0:39
PAM feature. We also going to integrate
0:41
it with our domain controller, so we're
0:44
going to use in domain user to log in
0:46
and adding our first provider domain
0:48
user provider, so we can manage our
0:51
domain privilege account. Now, let's
0:54
start it.
0:59
Before we start the lab, let's go over
1:02
the topology again.
1:04
We have Windows 2025 with all service
1:08
required AD, DNS. We also installed the
1:13
Delinea servers, gateway, DB all-in-one
1:16
server to make it very simple. Also, I
1:19
have RDM client on the same machine for
1:21
testing.
1:23
I also have a workstation 10.0.0.5
1:27
this IP, which is same network as the
1:30
Delinea server to make it simple.
1:32
We can use the browser or RDM to log in
1:35
to simulating a user. Remote, we have
1:38
couple of remote target we can use for
1:41
testing.
1:42
The most important part we have some
1:45
service account and user account created
1:48
for this testing. We have vault DB
1:51
owner, domain admin user, which we used
1:55
to log in to our those machines to start
1:57
testing. We also have DVLS-Admin
2:01
this built-in admin account for
2:03
Devolutions Server. I also have this
2:06
service account provided for next step,
2:09
which is our domain user provider. Of
2:12
course, I have some test user accounts
2:15
and privileged user accounts. We going
2:17
to use this lab to testing pen function,
2:21
which is
2:22
just in time access. We log in with test
2:24
user. Then we can elevate our permission
2:27
to privileged account user, and then we
2:31
can do RDP, etc., etc.
2:34
So, now let's start the lab.
2:40
Currently,
2:42
we only able to sign in using our
2:44
Devolutions Server user. As a free
2:47
version, we only can sign in with one
2:49
user.
2:50
So, let's our built-in
2:55
There's no other authentication method
2:57
available since we haven't enable any.
2:59
But, what we going to do is we going to
3:01
enable our domain authentication.
3:05
So, go into administration, server
3:07
settings, authentication.
3:10
Authenticate with domain user. You also
3:13
have other options, but for this lab,
3:17
domain user authentication is enough. We
3:20
going to set up a Devolutions Server
3:21
user as our main primary authentication
3:24
method. You don't need to enable single
3:27
sign-on and emergency code
3:29
authentication. Save. Save button is
3:32
here.
3:34
As you can see, domain authentication is
3:36
available here now. But, we have to do
3:39
one more thing, enable license.
3:42
Because free license only allows just
3:45
one login.
3:46
Free version designed for solo work.
3:49
Let's do the 30-day trial. Then we can
3:52
use five users.
4:01
Sometimes, it may not working.
4:06
In this case,
4:07
you may need to enter your license and
4:09
to continue.
4:11
Let's add the existing key if you got it
4:13
from Devolutions trial or your customer
4:17
manager.
4:18
So, you can add it.
4:20
Add it or you also can import it.
4:24
So, either way works.
4:27
So, now our license has been added
4:30
successfully. You can enable auto assign
4:34
or you can assign to certain group.
4:37
But, for now,
4:39
we just
4:41
using this for demo
4:43
trial license.
4:44
So, we have signed out. Now, we should
4:47
be able to see we have new
4:50
authentication method Cyber to Local. As
4:53
mentioned before, we have a couple users
4:55
created.
4:56
DPN user one, DPN user two. We're going
4:59
to use one of them to log in.
5:05
Perfect. So, now we have integrated our
5:08
Devolutions Server with our domain.
5:15
Now, we have our license added. So,
5:18
let's go back in as a admin here.
5:21
Now, if you go to users,
5:24
you should be able to see multiple
5:26
users. Now, we have DVL as dash admin.
5:29
We also have
5:30
DPN user one at cyber to local as for
5:33
testing. Let's go to enable PAN for our
5:37
this lab.
5:38
We do have Devolutions Gateway. So, at
5:40
this moment, we have added license. But,
5:43
when we go to administration, we won't
5:45
be able to see PAM modules here, even we
5:49
already have license for it.
5:51
But we haven't assigned our privileged
5:54
access management license to anyone yet.
5:57
So, what are we going to do is we going
5:58
to assign to our DVLS-Admin.
6:02
So, we want to
6:04
our admin be able to use
6:08
PAM this module. So, now PAM module is
6:11
ready for us to use. Our next step is
6:15
going to add a new provider, which is a
6:18
domain user into our PAM solution, and
6:23
then we can manage our domain privilege
6:25
account.
6:30
As mentioned at the beginning, we're
6:32
going to log in as
6:34
the PAM user
6:36
and then elevating our privilege account
6:41
and then performing privilege tasks in
6:44
our target server.
6:46
That's our target. Of course, we are
6:48
able to locating our privilege account
6:53
users
6:54
password, and also we can use workflow
6:58
to approval change for access, and then
7:02
to session recording those kind of
7:05
tasks. So, we're going to demonstrate
7:07
that slowly step-by-step through here.
7:11
The first step we can of course we're
7:12
going to add the provider.
7:14
We're going to add domain user. This is
7:17
our provider. You have quite a few.
7:20
We're using Azure and ID or AWS, SQL
7:25
user, MongoDB user, and uh SSH.
7:31
We're going to use domain user. We're
7:33
going to use cyber.local
7:36
domain
7:37
user
7:38
domain name at our testing.
7:42
Domain controller
7:44
which is the same
7:50
same on the server because all in one
7:53
set up credential type
7:57
we're going to use
8:00
our service account here.
8:06
Test connection.
8:07
Now works.
8:09
You can use LDAP or LDAPS, that's a
8:12
matter.
8:13
And add it.
8:16
So, now we're going to add a new task
8:19
which is to do the account discovery.
8:21
Dovolutions able to use the account that
8:24
you configured to automatically discover
8:27
the account in your domain. So, we're
8:30
going to say domain user discovery. You
8:34
can
8:35
define
8:38
the OU
8:40
or you can choose multiple of them. So,
8:42
for this demo purpose I would just
8:45
choose two of them. Select.
8:47
You also can set up uh
8:49
recurrence. Repeat it every couple days.
8:54
You want to do it again. So, for demo
8:55
purpose, I'm going to leave it.
8:58
Once down, the domain user discovery
9:01
should automatically happen. You can go
9:03
back and and then look at account
9:05
discovery configuration which we already
9:08
defined through our domain user provider
9:12
creation process. So, status is queued.
9:16
So, we can let it run and we can all
9:18
come back later. But for now, we have
9:21
onboarded our provider here. There's a
9:24
couple policy you may want to define
9:27
which is account lifecycle policy,
9:30
password policy, also just-in-time
9:34
privilege elevation. And we will do that
9:37
later on. We can all test it to onboard.
9:40
our privilege account and we will see
9:43
how we can manage our privilege account.
9:47
Go back discovery.
9:49
You wait a bit once it's finished it we
9:51
will show you the result here.
9:55
One thing you might notice it may take a
9:57
very long time that usually caused by
10:02
scheduler.
10:03
As you can see scheduler
10:05
service isn't started yet so we can
10:09
quickly go to companions to start the
10:13
service.
10:15
Here you can see starting the scheduler
10:17
service.
10:18
With default installation the scheduler
10:21
service may not auto start it. So that's
10:25
something you may want to check. Once we
10:27
enable the scheduler service we got
10:31
eight results here.
10:34
We found eight
10:36
account
10:37
which we should be able to import it
10:40
into
10:41
our system the evolution system.
10:45
Here we have
10:46
DPM
10:48
privilege account one, DPM privilege
10:50
account two. So we going to lose two
10:52
because that's what we going to test
10:54
for. So we check both
10:57
and here
10:58
import selected account.
11:01
You need to put a destination.
11:04
So we can add
11:06
a pen vault.
11:07
So if you don't have a vault already
11:10
then you need to add it in. We don't
11:12
have one so this is first time so we
11:15
going to say
11:16
pen vault
11:18
for
11:20
domain visibility default
11:24
users
11:26
user groups
11:28
vault owners.
11:29
So we We want to have DPM user one to
11:34
take a look like. So, we just going to
11:36
check this one.
11:39
Add it.
11:40
Account life cycle policy, we didn't
11:42
create those policy yet like password
11:44
policy, account life cycle. We're going
11:46
to use the default one for now.
11:50
Here's the option. You can reset
11:51
password on import. We want to do that.
11:55
Once we import it, we want the our D
11:58
evolution to manage those privileged
12:00
account. That's the whole purpose why we
12:02
doing this.
12:03
Okay.
12:04
Close.
12:06
You will notice there's a new vault
12:08
created here, PAM vault. On the list PAM
12:12
domain vault, there are two accounts
12:14
here.
12:15
You can see history.
12:18
You can see more
12:20
password history.
12:22
Modified by DVL-admin.
12:25
Previously, there's no password.
12:28
Same as seen on the PAM preview 2.
12:32
What we can do here, we can
12:35
check out
12:36
and we can reset password.
12:40
We can do that. Let's give you a quick
12:42
check. Reset password line history.
12:44
Again, you can see the password has been
12:46
updated. Now, you should be able to see
12:49
password history what I have created
12:52
for. That's the new password.
12:54
Based on the password policy default one
12:57
and then they will reset it for you.
13:00
That's basic PAM procedures how you can
13:03
import it, onboard your privileged
13:05
account, and rotating the password. So,
13:08
our next step going to do a little bit
13:10
more which is just-in-time access. We're
13:13
going to elevate it into different
13:16
privilege. Right now, it's just domain
13:18
user. We're going to elevate it to a
13:19
higher privilege and then use it to log
13:22
into our destination.
13:28
So, in this screen, we're going to
13:30
configure three things. One is our
13:32
permission to allow our D Pen user one
13:35
to access
13:37
the Pen vault and also access those
13:39
privileged account. We also need to
13:41
configure just-in-time provisioning, so
13:44
they won't have access until they
13:46
request for it. And then, once the
13:49
domain approved the request, they will
13:51
have access. We call it just-in-time
13:53
provisioning. Then, we also would like
13:56
them to have just-in-time elevation. By
13:58
default, those accounts doesn't have
14:02
privileged permissions, such as domain
14:04
admins. They are not in domain admins
14:07
groups.
14:08
So, we're going to provide just-in-time
14:11
elevation.
14:12
So, when they request access, they also
14:15
can request elevated permission to
14:17
higher level, which is domain admin we
14:21
configured for D Pen privileged account
14:24
one. So, we will do that step-by-step.
14:26
The first thing we come into the
14:28
permission.
14:29
So, we go down to the vault level, give
14:31
the permission. By default, it's
14:33
disallowed.
14:36
Click add button, permissions.
14:39
Default, disallowed. We're going to
14:41
custom. We're going to
14:43
select
14:46
D Pen user one.
14:48
Um we're going to do
14:50
custom.
14:52
Going to grant access
14:53
D Pen user one.
14:55
We're going to give a couple
14:57
permissions, view,
15:00
view password, view sensitive
15:01
information,
15:03
connect, view password, view sensitive
15:06
information. Those will be for the
15:08
opening the browser web session. We also
15:10
want it to have checkout because level
15:13
required. If they want to checkout, we
15:16
want to enable that feature.
15:20
So, once we have that, select update.
15:23
We can open an alarm in private window.
15:27
That's simulating
15:30
the PAM user one to log in. Of course,
15:33
we need to change authentication mode.
15:35
Set it up to local. We going to use in
15:37
PAM user one, sign in. So, this is under
15:40
user PAM user one's view. You do see
15:44
they don't have administration menu
15:47
since they are not administrator.
15:50
But, they do able to see PAM domain one,
15:53
domain two.
15:58
They can do check out. They can request
16:00
check out.
16:03
Here's their permission what they have.
16:06
They also don't have access to the
16:08
server vault,
16:10
which we going to configure it later on.
16:13
So, that's their permission. Now, we
16:15
going to configure just-in-time
16:17
provisioning.
16:18
So, we go back to PAM privilege one. We
16:21
going to have properties.
16:24
We going to have check out policy.
16:27
We going to tell them this is custom
16:29
check out policy. Check out mode is
16:31
default mandatory. And then, we want to
16:34
have approval. Right now, it's no. So,
16:38
we going to have mandatory on JIT
16:40
elevation. If you don't want to elevated
16:43
privilege, then I don't need approval.
16:46
You can go ahead to use it. But, once
16:48
you go to JIT elevation, yes.
16:51
Okay, we can update that.
16:54
We also want to set up the privilege,
16:57
what kind of privilege they can elevate
17:00
to. So, that will go back to
17:02
administration.
17:05
PAM module, providers.
17:08
This is a provider we created. We going
17:10
to configure JIT privilege elevation.
17:14
Here, we going to choose a privilege,
17:17
which is
17:19
group DPA MRI one. So, this is a group
17:23
we already set up as a domain admin.
17:27
So, we want to elevate it that account
17:30
to this domain admin group.
17:35
There's a couple things you need to
17:36
configure. We're going to do
17:39
JIT, that's a prefix.
17:43
Temporary group creation location, it's
17:46
important. You may want to choose
17:48
the panda or test OU
17:50
account creation location. Same thing.
17:56
Choose the panda select.
17:58
Replication latency, yeah, maybe you
18:01
have some latency there. Once you
18:03
elevate it, you may want to give a
18:05
couple seconds for the replication to
18:08
other domain machines. So, let's go to
18:12
update.
18:13
So, that's the configuration. We also
18:15
want to have a
18:17
new vault.
18:20
Let's get the default vault. We're going
18:21
to campaign server.
18:25
We're going to give the user
18:27
access.
18:28
In the pen server, we're going to add a
18:30
new server.
18:32
RDP
18:46
So, here is important. We're going to
18:48
use a privilege account to log in.
18:50
By default, we don't want our regular
18:53
users able to log in to the server. We
18:56
want them to elevate them to a specific
18:59
privilege account permissions to log in.
19:02
So, then here is
19:04
So, we already configured the
19:07
privilege account, so we're going to
19:09
pick this one.
19:11
We're We're to use in the host IP
19:13
address easy. So, there's no option for
19:15
you username, domain, password because
19:17
we already chose the privilege account
19:19
to login.
19:21
So, you may want to enable
19:23
session recording, all those things, but
19:25
those are
19:26
not important at this moment. We just
19:30
going to
19:31
do basic settings and edit since we
19:34
going to testing other features.
19:38
Let's go back to users
19:40
portal.
19:41
Now, we should be able to see
19:44
this PAM server.
19:47
But at this moment, you can see the
19:49
vault, but you cannot see the server
19:51
under the vault. We still need to set up
19:53
permission.
19:55
Go back
19:56
to admin portal.
19:59
We going to add it permission
20:03
at the root level.
20:05
Default is disallowed.
20:07
We going to allowed.
20:10
We're a custom.
20:14
Grant access
20:16
to the user one. So,
20:19
for user one to use this server, he
20:21
should be able to
20:22
view it, view password, view sensitive
20:25
information, and then to connect. That's
20:27
pretty much everything
20:29
for this server.
20:33
Update.
20:35
Go back to user
20:37
portal here. Refresh.
20:40
Now, let's go back to ADM.
20:44
Let's sign in as the PAM user one.
20:52
Let's change authentication mode. The
20:55
PAM user one. Perfect. We logged in.
20:59
Based on the permission, you should be
21:01
able to see those vaults you have
21:04
access, which is PAM domain vault
21:08
for the domain privilege account or so
21:10
PAM server which is using
21:13
the PAM account to log into those
21:17
servers. So, we have test domain server
21:20
one which open session.
21:22
So, here is come through the interesting
21:25
part. Now, it's 4 hours. We need to
21:28
elevate permission. So, once you clicked
21:31
on that, you need to get the approval.
21:34
So, we give you or as the domain going
21:35
to approve that. Request check out.
21:39
So, request has been sent.
21:41
Now, we go back to
21:43
browser. This our DPM admin logged in.
21:49
You will see this messages.
21:53
Check out request.
21:55
Approval.
21:57
Once you're done, go back to RDM.
22:01
You can see this red email icon.
22:04
You will see those has been approved.
22:07
You can reply for it. This is a previous
22:09
one I tested.
22:11
Close the
22:12
open session again.
22:15
So, there's a 5 seconds we wait to wait.
22:20
Perfect. We logging again.
22:22
So,
22:23
run CMD.
22:26
Who am I?
22:28
DPM privilege one. Again, DPM privilege
22:32
one wasn't having the domain admin role
22:36
which RDP role to log into this server.
22:39
If you don't do elevation, you won't be
22:42
able to log in.
22:43
So, this is the devolution PAM how it
22:46
works, how to set up just-in-time
22:48
access, just-in-time elevation,
22:51
just-in-time privilege and also typical
22:54
PAM features. You also can do schedule,
22:57
location, schedule checking. Also, you
23:01
can do session recording this fancy
23:04
feature which we presented before. I
23:07
hope you enjoyed this video, learn
23:09
something from the revolution pen. If
23:12
you have any questions, leave me a
23:14
comment in this video and let me know. I
23:16
will reply back as long as possible.
23:18
Thank you for watching. See you in my
23:20
next video.
23:23
>> [music]
23:30
[music]
23:37
[music]
Science
