Enable PAM (Privileged Access Management) in Active Directory
Published on 26 Sep 2023Clap
This feature requires DCs and a forest functional level 2016. Once this feature has been activated, it cannot be deactivated.
To activate :
Enable-ADOptionalFeature "Privileged Access Management Feature" -Scope ForestOrConfigurationSet -Target tondomaine.com
Activation causes the following changes in AD:
- The attribute
msDS-EnabledFeature
of each NTDS Sttings objects has the valueCN=Privileged Access Management Feature,CN=Optional Features,CN=Directory Service,CN=Windows NT,CN=Services,CN=Configuration,DC=domain,DC=com
- The object
CN=Partitions,CN=Configuration,DC=ad,DC=itprotips,DC=com
contains the attributemsDS-EnabledFeature
withCN=Privileged Access Management Feature,CN=Optional Features,CN=Directory Service,CN=Windows NT,CN=Services,CN=Configuration,DC=domain,DC=com
- The object
CN=Privileged Access Management Feature,CN=Optional Features,CN=Directory Service,CN=Windows NT,CN=Services,CN=Configuration,DC=ad,DC=itprotips,DC=com
contains the backlinkmsDS-EnabledFeatureBL
.
Clap
Comments