Mastering Identity and Access Management with Microsoft Azure
上QQ阅读APP看书,第一时间看更新

MIM privileged access management

MIM 2016 provides a privileged access management (PAM) solution, restricts privileged access within an existing AD environment.

PAM solves the following two targets:

  • You can get back the authority over a compromised AD environment if you provide a separate bastion environment that is more protected from malicious attacks
  • With the isolation of privileged accounts, you can limit the risk of losing sensible credentials

PAM helps to address the following problems:

  • Pass-the-hash and pass-the-ticket attacks
  • Kerberos compromises or spear phishing
  • Unauthorized privilege escalations
  • Other vulnerabilities and attacks

The following screenshot shows you the role-activation and user-verification processes on the MIM PAM example portal, which you can customize based on your needs:

MIM privileged access management sample portal

Now that you know a bit about MIM's standard functionality, we'll provide you with an overview of an additional solution we developed with a partner company. Hopefully, it gives you an idea of the possibilities that MIM provides and how they can be expanded.