KACE® Privilege Manager for Windows 4.4 Quick Start Guide
Total Page:16
File Type:pdf, Size:1020Kb
KACE Privilege Manager for Windows 4.4 Quick Start Guide © 2020 Quest Software Inc. ALL RIGHTS RESERVED. This guide contains proprietary information protected by copyright. The software described in this guide is furnished under a software license or nondisclosure agreement. This software may be used or copied only in accordance with the terms of the applicable agreement. No part of this guide may be reproduced or transmitted in any form or by any means, electronic or mechanical, including photocopying and recording for any purpose other than the purchaser’s personal use without the written permission of Quest Software Inc. The information in this document is provided in connection with Quest Software products. No license, express or implied, by estoppel or otherwise, to any intellectual property right is granted by this document or in connection with the sale of Quest Software products. EXCEPT AS SET FORTH IN THE TERMS AND CONDITIONS AS SPECIFIED IN THE LICENSE AGREEMENT FOR THIS PRODUCT, QUEST SOFTWARE ASSUMES NO LIABILITY WHATSOEVER AND DISCLAIMS ANY EXPRESS, IMPLIED OR STATUTORY WARRANTY RELATING TO ITS PRODUCTS INCLUDING, BUT NOT LIMITED TO, THE IMPLIED WARRANTY OF MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE, OR NON-INFRINGEMENT. IN NO EVENT SHALL QUEST SOFTWARE BE LIABLE FOR ANY DIRECT, INDIRECT, CONSEQUENTIAL, PUNITIVE, SPECIAL OR INCIDENTAL DAMAGES (INCLUDING, WITHOUT LIMITATION, DAMAGES FOR LOSS OF PROFITS, BUSINESS INTERRUPTION OR LOSS OF INFORMATION) ARISING OUT OF THE USE OR INABILITY TO USE THIS DOCUMENT, EVEN IF QUEST SOFTWARE HAS BEEN ADVISED OF THE POSSIBILITY OF SUCH DAMAGES. Quest Software makes no representations or warranties with respect to the accuracy or completeness of the contents of this document and reserves the right to make changes to specifications and product descriptions at any time without notice. Quest Software does not make any commitment to update the information contained in this document.. If you have any questions regarding your potential use of this material, contact: Quest Software Inc. Attn: LEGAL Dept 4 Polaris Way Aliso Viejo, CA 92656 Refer to our Web site (https://www.quest.com) for regional and international office information. Patents Quest Software is proud of our advanced technology. Patents and pending patents may apply to this product. For the most current information about applicable patents for this product, please visit our website at https://www.quest.com/legal. Trademarks Quest, the Quest logo, and Join the Innovation are trademarks and registered trademarks of Quest Software Inc. For a complete list of Quest marks, visit https://www.quest.com/legal/trademark-information.aspx. All other trademarks and registered trademarks are property of their respective owners. Legend CAUTION: A CAUTION icon indicates potential damage to hardware or loss of data if instructions are not followed. IMPORTANT, NOTE, TIP, MOBILE, or VIDEO: An information icon indicates supporting information. Privilege Manager for Windows Quick Start Guide Updated - May 2020 Version - 4.4 Contents About this guide 4 System requirements 5 Hardware, software, and operating system requirements 5 Network requirements 6 Required permissions 6 Reporting database requirements 6 Components 7 Console 7 Server 7 Client 7 Preparing your environment for least privileged use 8 Product Licensing 8 Configuring access to ports, websites, and processes 9 Installing the Cconsole 9 Configuring the Server 10 Installing the Client 13 Configuring reporting, discovery, and remediation settings 14 Configuring Client data collection 14 Configuring Instant Elevation 15 Configuring Self-Service Elevation 15 Configuring privileged application discovery 15 Configuring approved privileged applications 16 Processing discovered privileged applications 16 Deploying rules 16 Removing local admin rights 16 Using the Active Directory Users and Computers utility 16 Using the Users with Local Admin Rights screen 17 Maintaining a least privileged use environment 18 Processing Self-Service Elevation Requests 18 Using the Console Email Configuration screen 18 Using Group Policy Settings 18 About us 19 Technical support resources 19 Privilege Manager for Windows 4.4 Quick Start Guide 3 1 About this guide Welcome to the KACE Privilege Manager for Windows Quick Start Guide. Privilege Manager lets system administrators grant selected privileges to users so they can update their own PCs, reducing help desk calls while maintaining a secure network. This guide instructs system administrators on how to set up the Privilege Manager Console, Server, and Client. This guide also provides an overview of the product’s key features and the wizards that will help you use them. For more information, refer to these additional resources: For system administrators: l Privilege Manager Administrator Guide: Learn how to use Privilege Manager. Find in-depth instructions on how to prepare your environment for least privileged use, maintain a least privileged environment, run reports, and interface with Microsoft tools. l Privilege Manager for Windows Console: Find more information on the Getting Started screen under the Additional Resources tab. For end users with the Privilege Manager Client service installed on their computers: l Privilege Manager for Windows User Guide: Learn the basics of using Privilege Manager for Windows, including how to use Self-Service Elevation, Instant Elevation, and view rules. Privilege Manager for Windows 4.4 Quick Start Guide 4 About this guide 2 System requirements Hardware, software, and operating system requirements IMPORTANT: The security status of the installation file can become "blocked" after download, inhibiting the ability of the product to be properly installed. Please see KB 262298 for information on detecting and resolving this issue. Hardware Software Operating System Console and Processor: 2.00 GHz, .NET Framework 4.0 Microsoft Windows 10 (including Server dual core equivalent Microsoft Group Policy 64-bit) (recommended) Memory: 4.00 GB Management Console Microsoft Windows 8.1 (including Disk space: 100 MB PDF reader to open the 64-bit) (Console) Privilege Manager Microsoft Windows 7 (including IMPORTANT: guides 64-bit) Additional space Microsoft Windows Server 2019 is required for the Microsoft Windows Server 2016 Privilege Manager Microsoft Windows Server 2012 database. For R2 complete information, see Microsoft Windows Server 2012 the Database Standard/Enterprise Planning chapter Microsoft Windows Server 2008 in the R2 Standard/Enterprise Administrator Microsoft Windows Server 2008 Guide. Standard/Enterprise (including Screen resolution: 64-bit) 1024x768 or higher Privilege Manager for Windows 4.4 Quick Start Guide 5 System requirements Client As recommended by the N/A Microsoft Windows 10 (including OS 64-bit) Microsoft Windows 8.1 (including 64-bit) Microsoft Windows 7 (including 64-bit) Microsoft Windows Server 2019 Microsoft Windows Server 2016 Microsoft Windows Server 2012 R2 Microsoft Windows Server 2012 Standard/Enterprise Microsoft Windows Server 2008 R2 Standard/Enterprise Microsoft Windows Server 2008 Standard/Enterprise (including 64-bit) Network requirements The Privilege Manager Console and Client must be installed on a computer within the Active Directory domain. Required permissions l Local administrator rights to start the Console. l Write permissions for Group Policy objects (GPOs) to be configured. Reporting database requirements When setting up the Privilege Manager for Windows Server, Microsoft SQL Server (hosted either locally on the Privilege Manager for Windows machine or remotely) is required. Privilege Manager supports Microsoft SQL Server 2008 to Microsoft SQL Server 2019. Privilege Manager for Windows can optionally install SQL Server 2014 SP2 Express. Privilege Manager for Windows 4.4 Quick Start Guide 6 System requirements 3 Components Console Server Client There are three software components included with Privilege Manager: the Console, Server and Client. Console The Privilege Manager Console, installed via PAConsole_Pro.msi, is a management application. It is installed on a domain computer (serveror workstation) and is used to create and manage rules within the Group Policy. Any user who has permission to edit a GPO can use the Console to set privileges. Server The Privilege Manager Server, installed through the Console, is a service which has several functions. It can deploy the Client, collect and report on data, and discover and process applications that require elevated privileges. Client The Privilege Manager Client, installed through PAClient.msi, is a service that runs on each client computer. It applies the rules created in the Console by monitoring processes as they are launched on the Client and elevates or lowers the privileges for processes that are configured to be monitored. This is done by injecting an administrative token into the process or revoking it. Microsoft Active Directory and Group Policy are used to distribute Privilege Manager rules to client computers. Privilege Manager can modify privileges only for a standard user account, not a guest account. Elevated privileges can be revoked even if the user is a local admin. Privilege Manager for Windows 4.4 Quick Start Guide 7 Components 4 Preparing your environment for least privileged use Product Licensing Configuring access to ports, websites, and processes Installing the Cconsole Configuring the Server Installing the Client Configuring reporting, discovery, and remediation settings Configuring approved privileged