0:06
Hello everyone. Welcome to my new
0:09
episode regarding Devolutions. It all
0:12
starts from a webinar I attended a
0:14
couple days ago for the Devolutions PAM
0:17
solution. It seems very promising
0:20
product from Devolutions. They can do
0:23
what PAM can do such as discovery for
0:27
your privileged account, remote
0:32
without disclosing your password, and
0:35
then managing your privileged accounts
0:37
life cycle, set up right password
0:39
policy, and also session recording,
0:43
scheduled password rotation, workflows,
0:47
multi-level approval for granular
0:50
control access. All those functions
0:53
seems very promising. Um that
0:57
very popular because of their RDP
1:00
product, which kind of all IT pros maybe
1:05
in certain degrees use this product
1:07
because it's free and they can
1:09
seamlessly connecting to your target,
1:12
normally Windows, VPN, Linux, or cloud.
1:17
I started to learn this product, but I
1:19
found that there's one thing I always
1:22
confusing is how their documentation is
1:24
so bad while their product is so
1:27
promising. They didn't gave enough
1:30
explanation or step-by-step guide, even
1:32
they do have getting started
1:34
documentation. For example, the
1:36
topologies. That's only thing I found.
1:38
There's no diagram here. Where is the
1:41
single server topology? Where are those
1:44
components? How they are talking to each
1:46
other? Gateway, hub, business PAM
1:48
server, how they work together? Not even
1:51
one topology I can find out.
1:55
It also provide 1 hour free discover
1:58
lab. You can launch a lab and play with
2:01
it, which is awesome. I did that. And
2:04
then I'll spin it up and testing it
2:08
slowly, but just 1 hour. That's
2:11
driving crazy, so I decided to create my
2:13
own lab to play with it since I like to
2:16
know more about the their pen product. I
2:20
might creating a series of videos just
2:23
like I did that before for CyberArk. So,
2:26
this is basic diagram I'm going to using
2:28
in my lab. Now, let's jump into it. I'm
2:31
going to explain the topology and what
2:32
I'm going to do in this lab.
2:38
Since this is lab environment, I'm not
2:42
going to split all component into
2:45
multiple servers. I'm going to just
2:48
using one server to configure everything
2:50
in it to make it simplest as I can. I'm
2:54
going to have Windows 2025 server,
2:58
which I have already installed it. It's
3:00
just Windows 2025 basic installation.
3:03
Nothing has been configured. It's in the
3:05
Azure cloud with 16 GB
3:12
storage, which I believe is enough.
3:16
Later on, I'm going to promote it as our
3:18
domain controller and starting to
3:21
install SQL Express and also the motion
3:25
server, gateway, of course, enable pen.
3:28
The RDM actually going to be on my local
3:32
machine, which remotely connect into the
3:34
server either using browser or either
3:37
using RDM client. Target going to be
3:40
different Windows machine, Linux
3:44
or database, or web application we can
3:46
remotely connect into. So, that's very
3:49
basic topology. For now, we just need to
3:53
set this Windows Server up and promote
3:57
it as domain controller and starting to
4:05
Installing domain services, this process
4:08
is actually a boring process. So, I'm
4:11
going to mute myself and and play some
4:14
audio in the background. I'm going to
4:17
make it play multiple time faster. You
4:19
can skip it if you know this part
4:22
already. This is just for demonstration
5:57
>> After system rebooted, we should be able
6:00
to log in using the same credential.
6:02
Now we have to create three service
6:06
DB owner, DB runner, and the DB
6:11
We can go to users and the computers.
6:22
I'm going to create a new OU.
6:28
We call it a DB hand.
6:38
We're going to use a vault DB owner.
6:50
You going to make sure it going to be
6:52
our local administrator group or domain
6:54
administrator since it's domain
7:09
So, domain admins also part of
7:11
administrators group.
7:17
Continue create our second user.
7:30
Since they are service accounts, so I'm
7:34
make sure they are not expired, not
7:50
>> And they are part of domain users. So,
7:53
that completed our domain configuration
7:56
and the service account configuration.
8:03
Now, we're going to install uh SQL
8:05
Server Express 2025. So, we're going to
8:10
Um just for your information, um we are
8:17
which is one of our administrators
8:22
To search for SQL Server download,
8:24
you can go to this download page.
8:31
We're going to start to install it.
11:01
>> Since we are not using this one, so I
11:04
think it should be okay. Let's close it.
11:10
We can uh launch the configuration
11:14
We're going to check our network
11:19
We're going to look at the SQL Server
11:28
TCP/IP, we can enable that.
11:44
Okay, let's conclude our SQL Server
11:47
Express 2025 installation.
11:55
So we cannot download the Devolutions
11:58
You can search Devolutions download.
12:01
Devolutions Server installation going to
12:03
help you to configure lab IIS.
12:06
We're going to go to the download
12:09
Download center has everything.
12:11
There's a pen, there's a server. Doesn't
12:14
matter which one you pick, it's the same
12:16
thing. Eventually, it's the same EXE
12:21
So it's set up DVLS console. So that's
12:25
usually we call it Devolutions console.
12:28
After finish console installation, then
12:31
you can create your Devolutions Server
12:41
don't want to bother into go through
12:42
this customization since this is lab
12:46
You make it simple to do.
13:03
Now it is installing pretty quickly
13:07
And you might notice this flashing icon
13:17
Okay, they're installing us Devolutions
13:30
>> Now we can launch the console.
13:33
Say yes. Click IIS Diagnostics.
13:37
We do not have IIS installed, so install
13:40
prerequisite. So let me launch the
13:43
PowerShell script to get all those
13:44
components to be installed.
13:48
prerequisite installed successfully.
14:04
HTTP localhost, which is
14:08
you can see IIS has also been installed
14:11
So let's conclude this section
14:21
Now let's start to install Devolutions
14:26
So it's from the console you can see
14:29
install new instance.
14:31
We already did IIS installation, so this
14:34
will be our last step to deploy our
14:39
Basic installation certificate.
14:42
So a SQL installation has been detected.
14:46
We just need to put the essay
14:55
Perfect. Since they are
14:57
on the same box, so it can be very easy
15:01
to connect it through.
15:03
You also can install Devolutions Gateway
15:06
side-by-side installation, but that's
15:09
not the purpose for this right now. So
15:13
we will just get Devolutions Server up
15:16
and running. We can connect to it. In
15:19
the future, we will add that into our
15:22
topology and get it done.
15:25
Let's click install and continue before
15:30
Here is all information that your
15:31
installation SQL Express password. Let's
15:35
copy those information save as for the
15:38
backup. We can save on desktop for now.
16:21
>> So your local Tableau Server web page
16:25
has been opened automatically. So now
16:30
continue because we are using
16:32
self-signed certificate. So you will get
16:35
this warning message.
16:42
So it's still installing.
16:45
It's in the maintenance mode now and
16:47
getting to production.
16:50
So now we get the we get the login
16:52
window to sign in to our Tableau Server.
16:56
So we do have our username password.
16:59
That's the default one we can use.
17:03
And then we also get this installation
17:05
successful message. Let's close that.
17:09
Go back to the login
17:13
Uh it will prompt you to
17:15
change your password.
17:23
Now we have Devolutions Server 3 has
17:29
You should be able to see the
17:30
administration panel.
17:34
There's a nice things is onboarding
17:36
list, so you will see there are quite a
17:39
11 task pending you to do for
17:42
onboarding. But at this moment, we
17:44
already have our Devolutions Server free
17:48
version has been installed. It's full
17:50
functional. We can log in and we can
17:54
browse through the settings.
17:57
In our next video, I'm going to show
18:00
[snorts] you how you can connect into
18:01
it. How can you open a port? How can you
18:04
configuring other components to work
18:07
together? Especially when you can create
18:10
in your vault and then grant the
18:12
permission to your users granularly. So,
18:15
that's for all this video. That's the
18:18
first one for Devolutions pen series. I
18:22
hope you enjoyed it and uh learned
18:24
something new from here. If you like it,
18:26
give me a thumbs up and uh subscribe my
18:28
channel if you haven't to support me.
18:31
I'll see you in my next one.