MIM PAM elevated user cannot access active directory sites and policy's....

Abdelrahman khalil 170 Reputation points
2023-06-14T13:38:53.1966667+00:00

Hello Guys,

I've deployed a PAM solution like the following: created a new bastion forest defined roles, PRIV users and candidates and a working sample pam web portal and PRIV users can have access to the roles and log into their machines once they have the roles. however, my issue is when a user takes the shadow principle and be member of the schema admins, domain admins and enterprise admins the user Connot access any of the group Policys, trust, only could access the AD sites and users.

and when trying to open the file share server as well and change to the PRIV domain to add users from it to be able to access the share on the source forest it won't let select the PRIV users or find them like I've done as the guide when delegating the PAM services accounts to the source AD

any help !

Microsoft Security | Microsoft Identity Manager
0 comments No comments
{count} votes

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.