Troubleshooting Password Rotation for Windows Server 2012 R2 in PAM
search cancel

Troubleshooting Password Rotation for Windows Server 2012 R2 in PAM

book

Article ID: 454394

calendar_today

Updated On:

Products

CA Privileged Access Manager (PAM)

Issue/Introduction

This article outlines troubleshooting and configuration options for rotating passwords on Windows Server 2012 R2 targets using Broadcom Privileged Access Manager (PAM). As Windows Server 2012 R2 has reached its standard end of support, the SSH connector may not be officially tested.

Environment

  • Product: PAM 4.2.x
  • Target: Windows Server 2012 R2
  • Connector Type: Windows Remote, Windows Proxy

Cause

The SSH password connector is not officially tested/certified for Windows Server 2012 R2. Compatibility depends on the connector method used (e.g., WMI-based Windows Remote Connector or Windows Proxy).

Resolution

To successfully rotate passwords on Windows Server 2012 R2, use one of the supported alternatives:

  1. Use Windows Remote Connector (WMI):
    • This connector utilizes WMI for password rotation.
    • Ensure the LocalAccountTokenFilterPolicy registry key is set to 1 on the target server.
  2. Use Windows Proxy Connector:
      • If remote WMI connections are restricted, configure the Windows Proxy Connector.
      • Install the Proxy Agent locally on the target server to eliminate remote call dependencies
  3. Review Connector Documentation:

Additional Information

 If the issue persists, ensure that the SMB2 protocol is enabled on the target endpoint. For further assistance with password rotation failures, contact support