- User preferences enhancement: Timezone and Date format selection
- Connection management enhancement: bulk connection import via CSV
- Connection management enhancement: active session takeover confirmation
- AD user enhancement: mandatory MFA on first login
- Roles management enhancement: Active Directory role mapping
- UI Enhancement: Pending Sessions Renamed to Active Sessions
- Permission requests enhancement: expired requests hidden by default
The latest update for our Privileged Account and Session Management product module (v.119) is here!
PASM version 119 brings a range of general improvements and fixes, alongside several key enhancements detailed in the sections below.
User preferences enhancement: Timezone and Date format selection
The Users view has been enhanced with new settings for Time Zone and Preferred Date Format, allowing each user to personalize how date and time information is displayed across PASM. Once selected, these preferences are applied consistently throughout the platform.
Two new dropdown fields have been added to the User Edit modal: Timezone and Preferred date format. The Timezone option allows users to select the time zone used for displaying date and time information across PASM, with Automatic selected by default.
The Preferred date format option allows PASM users to choose from four available date formats, defining how dates are displayed across the UI. DD.MM.YYYY is selected by default.
The same preferences are also available when creating a new user, with the default values automatically preselected. Once saved, the selected Timezone and Preferred date format are immediately applied across PASM, including application grids and views, user-specific date and time information and CSV exports.
Regular users can also access and update these preferences directly from their own user profile, giving them control over how date and time information is displayed without requiring administrator intervention.
Connection management enhancement: bulk connection import via CSV
A new Import from CSV button has been added to the Connections page, allowing PASM users to add multiple connections at once using a structured CSV file. This simplifies connection management by removing the need to create RDP or SSH connections individually.
Users can download a predefined CSV template directly from the import window and populate it with the required RDP or SSH connection details. When uploaded, the file is validated against the expected structure and connection data, with only valid entries added to the Connections grid.
Note: The standard CSV file downloaded from the Connections page cannot be used for importing connections. To export existing connections for subsequent import, use the new Advanced CSV Download option.
In addition, a new Advanced CSV Download option is available to Administrator users, generating a detailed export containing the connection data required for subsequent imports, except for passwords. This allows existing connection information to be exported, updated as needed and reused for bulk import.
Successfully imported connections are immediately displayed in the Connections grid and can be used and managed in the same way as connections created individually.
Connection management enhancement: active session takeover confirmation
A new confirmation pop-up is displayed whenever a PASM user attempts to connect to a session that is already active, making it clear that proceeding will take over the existing connection from the current user.
The confirmation is displayed regardless of whether the active session belongs to the same user or another PASM user.
Note: for Administrators, the pop-up displays the email address of the user with the active session. For regular users, it only indicates that the connection is currently being used by another user.
PASM users can then choose to cancel the connection attempt or terminate the existing active session and proceed.
AD user enhancement: mandatory MFA on first login
Multi-factor authentication (MFA), already available as an administrator-configurable option for local PASM users, has now been extended to Active Directory (AD) users. When an AD user logs in for the first time, MFA is automatically required before access to PASM is granted.
During this initial login, the user is required to complete the MFA setup and authentication before continuing. This requirement applies only to the first login; once completed, subsequent logins follow the existing authentication flow. By enforcing MFA at this initial stage, PASM adds an additional security layer for first-time AD user access.
Roles management enhancement: Active Directory role mapping
Active Directory (AD) group mapping has been added to PASM Roles, allowing administrators to associate AD groups with specific PASM roles. Based on these mappings, AD users can be assigned the appropriate roles according to their group membership.
A new AD Groups mapping field is available when editing a role, allowing administrators to associate one or multiple AD groups with that role.
The configured groups are displayed in the Roles grid and are also included in role CSV exports under the Mapped AD Groups column.
To optimize AD group retrieval, PASM caches retrieved groups for one hour. Administrators can manually refresh this information from Settings -> Active Directory, clearing the existing cache and retrieving the latest AD groups from the configured Active Directory environment.
If PASM is unable to retrieve the available AD groups, an error message is displayed to clearly indicate that the retrieval was unsuccessful.
UI Enhancement: Pending Sessions Renamed to Active Sessions
The Pending Sessions tab has been renamed Active Sessions to provide greater clarity and more accurately reflect the sessions displayed in this area. The new name is now used consistently across PASM.
Existing permissions, functionality, buttons and available actions remain unchanged. Users who previously had access to Pending Sessions will continue to have access to the renamed Active Sessions view.
Permission requests enhancement: expired requests hidden by default
The Permission Requests tab has been enhanced to hide expired requests from the grid by default, providing a clearer view of currently active pending requests.
The Show pending requests only filter is now enabled by default. Users can disable it whenever they need to view all permission requests, including expired ones and re-enable it to return to the default view showing only active pending requests.