NetIQ PAM resources: Where to start and what to use

These resources will help you better leverage NetIQ PAM to achieve your least privilege goals for your administrators.

Most privileged access management (PAM) content focuses on the buying decision. But choosing a platform is only the beginning. The value of PAM comes from how completely you bring privileged access under control: discovering accounts, protecting credentials, limiting when and how privilege can be used, monitoring activity, and producing evidence afterward.

OpenText™ NetIQ™ Privileged Access Manager has a rich set of product documentation, use-case guides, and technical resources. Because of the product’s NetIQ and Micro Focus history, much of that technical material still lives within the NetIQ documentation library, while broader product information is available from OpenText.

Use PAM as more than a password vault

Credential vaulting remains fundamental, but modern PAM is a much broader control layer.

The Product Overview is the best place to understand that model. It explains how NetIQ PAM combines credential protection, least-privilege delegation, privileged session management, policy control, auditing, and agent or agentless access across different types of endpoints.

That distinction matters. The goal is not simply to store an administrator password more securely, but to determine who can use privileged access, to which resource, at what level, under what conditions, and then retain accountability for what happened.

Use the Product Overview together with the NetIQ PAM product information and PAM Buyer’s Guide to establish that broader model before diving into configuration.

Resources: Product Overview · OpenText PAM product page · PAM Buyer’s Guide

Finding the risk: discover and onboard privileged accounts

You cannot secure privileged accounts you do not know exist.

Start with the Administration Guide. It covers discovery of administrative accounts and Windows service accounts across Windows, Linux, and UNIX systems, and shows how discovered accounts can be brought under PAM control. The guide also covers onboarding discovered accounts into the Credential Vault, including password handling and bulk onboarding.

For many organizations, the hardest part of getting here is identifying and coordinating with all the service and data owners to prepare them for the rollout. Once that groundwork is done, discovery transforms a long list of overprovisioned administrators into tiered sets where access matches actual need — a critical step for scaling the deployment successfully.

Resources: Administration Guide—Discovering privileged accounts · Getting Started

Protect credentials for people, services, and applications

Privileged credentials exist in more places than administrator logins.

The Credential Vault documentation covers credential checkout, shared keys, password management, and automated password rotation. PAM can automatically reset checked-out credentials and manage rotation for supported resource types, reducing the useful lifetime of an exposed password.

The Administration Guide covers Application-to-Application Password Management (AAPM). Instead of embedding privileged credentials in configuration files or scripts, applications can retrieve credentials from PAM through its REST API. That extends privileged credential management to applications and other non-human access scenarios, where secrets can otherwise become difficult to track and rotate. Getting this right offers real value because it allows you to eliminate unmanaged privileged secrets.

Resources: Administration Guide—Credential Vault, Password Management, Shared Keys and AAPM · User Guide—Credential Checkout

Replace standing privilege with policy-driven access

The next step is to reduce how much privilege exists all the time.

NetIQ PAM’s Access Control engine organizes privileged access around user roles, resource pools, assignments, and permissions. Policies can take into account factors such as the resource, privilege level, allowed access time, monitoring requirements, and remediation when risk is detected.

That provides the foundation for moving from permanent administrative rights toward access that is more targeted and time-bound.

The Administration Guide also documents just-in-time access and emergency access. JIT limits privileged access to when it is actually needed, while emergency access provides a controlled path when a user needs access outside existing rules. Emergency requests can be approved for a defined duration, audited, and revoked when necessary.

Together, these controls let teams reduce standing privilege without making legitimate administration impossible.

Resources: Administration Guide—Access Control, Just-in-Time Access and Emergency Access · User Guide—Emergency Access Requests

Control what happens after access is granted

NetIQ PAM can broker privileged access to Windows and Linux/UNIX systems through RDP and SSH, including agentless, web-based options through RDP and SSH, including agentless, web-based options. Users can reach target systems without necessarily receiving the underlying privileged credential, while administrators can monitor active sessions in real time. In web RDP and web SSH scenarios, sessions can also be recorded for later review — commonly used when investigating suspicious behavior.

PAM’s controls can go more granular than the session level. Within Access Control, administrators can define application command lists to allow or deny specific commands. Enhanced Access Control extends that model to file and directory operations, application processes, registry access, and starting or stopping services. This goes beyond simply implementing least-privilege access: rather than just defining whether someone is trusted for a session, it controls what privileged actions they’re allowed to perform during that session.

Resources: Business Use Case Guide · Administration Guide—Agent and Agentless Access, Access Control and Enhanced Access Control

Turn privileged activity into audit evidence

PAM can make accountability part of everyday privileged access rather than an audit exercise assembled after the fact. The Administration Guide contains extensive reporting and auditing capabilities, while the Product Overview describes dedicated audit components and dashboards for sessions, risky activity, disconnected sessions, credential checkout, and emergency requests.

Depending on the access method, NetIQ PAM can record privileged activity, including session activity and other available audit data. See the Administration Guide: Managing Reports and Audits for details on supported auditing and reporting capabilities.

Resources: Administration Guide—Managing Reports and Audits · Product Overview

See the controls working together: the Business Use Case Guide

Individual capabilities matter most when they work together. The Business Use Case Guide provides four useful end-to-end examples: securing web-based RDP, monitoring elevated web SSH access, provisioning just-in-time access to AWS using IAM roles, and implementing Zero Trust controls for an SSH target. These scenarios are useful both for existing customers and evaluators because they show how resources, roles, policies, credential protection, monitoring, and remediation combine to produce an actual security outcome. They are also good starting points for your own proof-of-concept or expansion roadmap.

Resources: Business Use Case Guide

Connect PAM to identity, authentication, and monitoring

PAM can use enterprise directory users and groups in its access model and integrates with OpenText™ NetIQ™ Advanced Authentication for additional authentication. Its documentation also covers OpenText™ NetIQ™ Identity Manager integration, while audit information can be forwarded to platforms such as OpenText™ Sentinel through syslog.

Deployment flexibility matters too. Agent-based controls provide deeper endpoint capabilities where required, while agentless SSH and RDP options can reduce the need to install software on target systems. That flexibility helps organizations apply a common privileged-access strategy across a heterogeneous environment rather than forcing every system and administrator into one access method.

Resources: Product Overview · Administration Guide—External Services and Agent/Agentless Capability · Identity Manager Driver Guide

From resources to results

These resources show how NetIQ PAM moves beyond password storage to discover privileged accounts, protect human and machine credentials, reduce standing privilege, govern sessions and commands, support emergency access, and make privileged activity accountable.

And if you are still deciding, pair them with the PAM Buyer’s Guide: Use these resources to understand what NetIQ PAM can do, then use the PAM Buyer’s Guide to evaluate those capabilities against the privileged-access requirements that matter most to your organization.

Kent Purdy

Kent has 25 years’ experience working with data center products and technologies, fifteen of which were specific to Identity and Access Management solutions. His current focus is on trends, technologies, and use cases specific to identity and access management industry.
Check Also
Close