The latest update for our Privileged Account and Session Management product module (v.117) is here!
PASM version 117 introduces several enhancements and fixes, the most important of which are covered in these release notes.
Enhancement for Azure Portal integration
An improved connection method has been implemented for better integration between Microsoft’s Azure Portal and Heimdal PASM.
The complete PASM Azure Login Setup Guide contains the following steps:
1. Register a new app in the Azure Portal
Add an application name of your choosing. The Redirect URI settings should be set to “Single-page application (SPA)” and the domain you are hosting your PASM solution on, followed by “/auth/azure-login”.
For example, if your PASM server's IP Address is set to 192.168.0.101, this means you that your single-page application (SPA) URI will be: https://192.168.0.101/auth/azure-login
2. Add the specific token claims to your app.
Under your new app registration, go to “Token Configuration”, and select “Add optional claim”.
Select “ID” and add the following claims to the application: “given_name”, “family_name”, “email”, “upn”.
When prompted to grant Graph API permissions, click the checkbox and click “Add”.
3. Add the new settings to the PASM Dashboard
You must update the Azure login settings in the PASM Dashboard with the details of your newly created app. Go to your application’s overview to get the settings:
Enter these settings on the PASM Dashboard Settings page, under the Azure section.
Before saving any new settings, you must first check that connecting to the app works. Use the “Test” button to validate the settings.
A Microsoft sign-in pop-up should appear when accessing the setting (if it doesn't, check that your browser isn't blocking pop-ups).
We advise you to enable consent on behalf of your organization. If you have disabled user consent for users in your organization, you must consent on behalf of your organization for the Azure login to work properly for all users.
Once the connection is validated, the "Save" button becomes available. Save your settings to finalize the setup.
Accounts Enhancement: Last (user) login timestamp visibility
The PASM Accounts section has been enhanced with a new Last Login column from the Users view. This improvement provides administrators with greater visibility into user activity, making it easier to identify inactive accounts
A new Last Login column (displaying the timestamp of each user’s most recent successful login) has been added to the Users view under the Accounts section.
Just-in-Time (JIT) Enhancement: Improved Active Directory Group selection
The Just-in-Time configuration has been enhanced to simplify Active Directory group selection and improve flexibility. Group discovery is no longer limited to the Builtin folder, allowing organizations to use their existing Active Directory structure without additional configuration, reducing setup complexity and accelerating deployment.
The group discovery mechanism now searches for the entire Active Directory tree instead of only the Builtin folder, providing greater flexibility and simplifying JIT configuration in environments with custom group structures.