Privilege Control for Servers with Platform Agent

This feature is currently available only to customers participating in a Private Preview. If you'd like to participate and be among the first to try this feature, ask our support or account team for details.

This section describes the IBM Security Platform Agent. This is just one of the types of agent you can use for PCS. For the Active Directory-based Privilege Control Agent, see Setting Up PCS with Privilege Control Agent. For an overview of the differences between the two agents, see Privilege Control Agent and Platform Agent.

The Platform Agent brings IBM Security's Privileged Access Management (PAM) capabilities to the servers and computer endpoints in your corporate network. The Platform Agent is a next-generation agent for Privilege Control for Servers (PCS) as well as other IBM Security products. The Platform Agent is built on the same framework as the Platform Engine.

This page gives a brief description of the services provided by the Platform Agent. They are explained in more depth in the rest of this documentation.

The Platform Agent

Agents are software that runs on an endpoint and connects directly to Verify Privileged Identity Platform, which acts as its control plane. Agents send self-discovery, asset, and activity data to the platform, and receive policies to govern authorization on that machine such as login and privilege elevation. Agents enforce policies locally, brokering privileged logins and elevated actions and reporting the results back to the platform for audit.

The Platform Agent is a peer or successor agent to the existing Privilege Control Agent. The Platform Agent is for PCS customers who wish to better handle cloud-first use cases. The Platform Agent, unlike the Privilege Control Agent, does not join an Active Directory domain. It enrolls directly with Verify Privileged Identity Platform and uses the same policy in the platform as the Privilege Control Agent. The Platform Agent is best suited to Windows and Linux (non-UNIX) environments with cloud-first deployments. While it can support Active Directory users and groups, if joining to a domain is required, the Privilege Control Agent is a better choice.

Policies

Policies provide users with machine-level (server) permissions for logging in to remote computers and servers managed by Verify Privileged Identity Platform and performing elevated actions on them. By assigning machine-level policies, you can ensure that each asset adheres to compliance standards, maintaining both security and efficiency across your network.

Policies can contain both Platform Agent and Privilege Control Agent targets. However, the Privilege Control Agent can only provide enforcement for AD-based users.

For more information, see Setting Up Policies (Platform Agent).

Inventory

The Inventory service delivers a user-friendly, asset-centric perspective of computers within your infrastructure. It empowers the user to readily view and manage assets, and to launch remote sessions directly on computers that have been discovered through the Platform Agent's self-discovery. For more information, see Inventory.

Engines

In Verify Privileged Identity Platform, an engine is a system daemon that runs on an endpoint and exchanges data with the platform. It sends information about the engine’s application and capabilities, and it receives information about the applications and workloads it needs to execute. It executes the workloads and reports status to the platform. Engines are not required to deploy or use the Platform Agent, but they are designed from the same common framework. For more information about engines, see Verify Privileged Identity Platform Engine Management.

Sites

Sites are groups of engines and agents selected on a common principle, such as network or subnet, geographical location (office, city, continent), data center, or any other characteristics. Update preferences, proxy settings, and engine workload settings are organized at the site level. For information about how to create and manage sites, see Managing Platform Engine Sites.

Next Steps

For information about how to install and set up the Platform Agent and PCS, see Setting Up PCS with Platform Agent.