NetIQ Privileged Account Manager 3.5 includes new features, improves usability and resolves several previous issues.

Similar documents
NetIQ Privileged Account Manager 3.2 Patch Update 4 Release Notes

NetIQ Privileged Account Manager 3.2 Patch Update 3 Release Notes

NetIQ Privileged Account Manager 3.2 Patch Update 2 Release Notes

Access Manager 4.3 Service Pack 2 Release Notes

Self Service Password Reset 4.1 Patch Update 6 Release Notes

NetIQ SecureLogin 8.5 enhances the product capability and resolves several previous issues.

NetIQ SecureLogin 8.7 enhances the product capability and resolves several previous issues.

NetIQ Identity Manager Analyzer 4.7 Release Notes

July 2018 These release notes provide information about the The Privileged Appliance and Modules release.

Sentinel 8.0 includes new features, improves usability, and resolves several previous issues.

NetIQ Identity Governance includes new features, improves usability, and resolves several previous issues.

Advanced Authentication 6.0 includes new features, improves usability, and resolves several previous issues.

ZENworks Service Desk 8.0 Using ZENworks with ZENworks Service Desk. November 2018

3 System Requirements for SecureLogin

Access Manager 4.2 Service Pack 2 (4.2.2) supersedes Access Manager 4.2 Service Pack1 (4.2.1).

Access Manager 4.3 Service Pack 3 Release Notes

Access Manager 4.2 Service Pack 5 (4.2.5) supersedes Access Manager 4.2 Service Pack 4.

Access Manager 4.2 Service Pack 1 (4.2.1) supersedes Access Manager 4.2.

The following sections outline the key features, functions, and resolved issues in this release:

Secret Server Demo Outline

3 System Requirements for SecureLogin

This patch update resolves specific previous issues. This document outlines why you should install this patch update.

Access Manager Appliance 4.4 Service Pack 2 Release Notes

NetIQ imanager 3.0 Release Notes. 1 What s New. 1.1 New Features. January Bit Support

vrealize Operations Manager Customization and Administration Guide vrealize Operations Manager 6.4

Service Desk 7.2 Installation Guide. March 2016

Access Manager 3.2 Service Pack 2 IR1 resolves several previous issues.

ZENworks 2017 Update 1 Quick Reference - Bundle Features and Options

ZENworks 2017 What s New Reference. December 2016

Evaluation Guide Host Access Management and Security Server 12.4 SP1 ( )

This Readme describes the NetIQ Access Manager 3.1 SP5 release.

SuperLumin Nemesis. Getting Started Guide. February 2011

ZENworks 2017 Audit Management Reference. December 2016

Access Manager 4.4 Service Pack 3 Release Notes

ZENworks Mobile Workspace ios Installation. September 2017

NetIQ Access Gateway for Cloud 1.0 Release Notes. 1 System Requirements. April 2012

Agent and Agent Browser. Updated Friday, January 26, Autotask Corporation

Access Manager 4.0 includes new features, improves usability, and resolves several previous issues.

22 August 2018 NETOP REMOTE CONTROL PORTAL USER S GUIDE

Enterprise Vault.cloud CloudLink Google Account Synchronization Guide. CloudLink to 4.0.3

ZENworks Reporting System Reference. January 2017

Contains the Linux Identity Server, the Linux Administration Console, the ESP-enabled SSL VPN Server, and the Traditional SSL VPN Server.

Web Self Service Administrator Guide. Version 1.1.2

HySecure Quick Start Guide. HySecure 5.0

StreamSets Control Hub Installation Guide

Ekran System v.6.0 Privileged User Accounts and Sessions (PASM)

ObserveIT 7.1 Release Notes

LifeSize Control Installation Guide

Dell SupportAssist Version 1.3 for Servers Release Notes

ZENworks 11 Support Pack 4 Management Zone Settings Reference. October 2016

CommandCenter Secure Gateway

KYOCERA Net Admin User Guide

Protection! User Guide. A d m i n i s t r a t o r G u i d e. v L i c e n s i n g S e r v e r. Protect your investments with Protection!

The Balabit s Privileged Session Management 5 F5 Azure Reference Guide

Netwrix Auditor. Release Notes. Version: 9.6 6/15/2018

Centrify Infrastructure Services

Click Studios. Passwordstate. Remote Session Launcher. Installation Instructions

Command Center :19:47 UTC Citrix Systems, Inc. All rights reserved. Terms of Use Trademarks Privacy Statement

AUTHORIZED DOCUMENTATION. Using ZENworks with Novell Service Desk Novell Service Desk February 03,

IBM Virtual Machine Manager 2.0

VMware AirWatch Product Provisioning and Staging for Windows Rugged Guide Using Product Provisioning for managing Windows Rugged devices.

Oracle Enterprise Manager Ops Center. Prerequisites. Installation. Readme 12c Release 2 ( )

Venafi Platform. Architecture 1 Architecture Basic. Professional Services Venafi. All Rights Reserved.

AUTHORIZED DOCUMENTATION

NetIQ Privileged Account Manager 3.2 Installation Guide. December 2017

Command Center :20:00 UTC Citrix Systems, Inc. All rights reserved. Terms of Use Trademarks Privacy Statement

VMware AirWatch Content Gateway Guide for Linux For Linux

Juniper Secure Analytics Patch Release Notes

ZENworks 2017 Update 1 Full Disk Encryption Pre-Boot Authentication Reference. July 2017

Oracle Enterprise Single Sign-on Logon Manager. Installation and Setup Guide Release E

Notification Template Limitations. Bridge Limitations

Security Content Update Getting Started Guide (Version: CCS 12.x)

VMware AirWatch Content Gateway for Linux. VMware Workspace ONE UEM 1811 Unified Access Gateway

VMware Identity Manager Administration. MAY 2018 VMware Identity Manager 3.2

Access Manager 4.1 Service Pack 1 includes updates to dependent components and resolves several previous issues.

ZENworks 2017 Full Disk Encryption Pre-Boot Authentication Reference. December 2016

Installation Guide Advanced Authentication - Logon Filter. Version 6.1

User Guide SecureLogin 8.1

Symantec pcanywhere 12.5 SP4 Release Notes

Using ZENworks with Novell Service Desk

Axon Fixed Limitations... 1 Known Limitations... 3 Informatica Global Customer Support... 5

Secret Server User Guide

Veritas ediscovery Platform

BIG-IP Access Policy Manager : Portal Access. Version 12.1

Server Monitoring. AppDynamics Pro Documentation. Version 4.1.x. Page 1

Deploying VMware Identity Manager in the DMZ. JULY 2018 VMware Identity Manager 3.2

Remote Support 19.1 Web Rep Console

Automated Sign-on for Mainframe Administrator Guide

User and System Administration

SC-T35/SC-T45/SC-T46/SC-T47 ViewSonic Device Manager User Guide

Quick Installation Guide

Setting Up Resources in VMware Identity Manager (On Premises) Modified on 30 AUG 2017 VMware AirWatch 9.1.1

Edge Device Manager Quick Start Guide. Version R15

Upgrading Software and Firmware

Novell Identity Manager

Installation Guide Worksoft Certify

Sentinel 8.1 SP1 includes new features, improves usability, and resolves several previous issues.

For information about how to purchase and download this product, see the PlateSpin Protect product website.

Gateway Guide. Leostream Gateway. Advanced Capacity and Connection Management for Hybrid Clouds

CA XCOM Data Transport Gateway

Transcription:

Privileged Account Manager 3.5 Release Notes July 2018 NetIQ Privileged Account Manager 3.5 includes new features, improves usability and resolves several previous issues. Many of these improvements were made in direct response to suggestions from our customers. We thank you for your time and valuable input. We hope you continue to help us ensure that our products meet all your needs. You can post feedback in the Privileged Account Manager Community Support Forum, our online community that also includes product information, blogs, and links to helpful resources. The documentation for this product is available on the NetIQ website in HTML and PDF formats on a page that does not require you to log in. If you have suggestions for documentation improvements, click the comment icon on any page in the HTML version of the documentation posted at the Privileged Account Manager Documentation website. To download this product, see the Micro Focus Downloads website. 1 What s New? The following sections outline the key features and functions provided by this version, as well as the issues resolved in this release: Section 1.1, Enhancements to Privileged Access to Enterprise Applications, on page 1 Section 1.2, User Experience Improvements, on page 2 Section 1.3, Enhancements to Integration Ready Interfaces, on page 3 Section 1.4, Performance and Scalability Improvements, on page 4 Section 1.5, Privileged Access to Resources Using Telnet, on page 4 Section 1.6, Enhancements to Privileged Account Discovery, on page 4 Section 1.7, Authentication Support for Email Alerts, on page 4 Section 1.8, Updates to Supported Platforms, on page 4 Section 1.9, Software Fixes, on page 4 1.1 Enhancements to Privileged Access to Enterprise Applications Privileged Access to Enterprise Applications Using Single Sign-On Application to Application Password Management Enhancements to Database Monitoring and Credential Checkout 1.1.1 Privileged Access to Enterprise Applications Using Single Sign-On In addition to credential checkout, Privileged Account Manager now provides the capability to single sign-on (SSO) to any enterprise application managed by Privileged Account Manager. You can now monitor and record sessions to enterprise applications without installing the agent in the target. You can get SSO access to resources, such as enterprise applications, databases, mainframes, Windows Privileged Account Manager 3.5 Release Notes 1

servers, Linux or UNIX severs, and network devices using the appropriate application clients. For more information about privileged access to enterprise applications using SSO, see the section Configuring Application Single Sign-On in the Privileged Account Manager Installation Guide. This is an add-on feature. Therefore, you must purchase additional license to use this feature. 1.1.2 Application to Application Password Management Using Application to Application Password Management (AAPM), an application can get privileged access to any application managed by Privileged Account Manager to perform automated or scheduled tasks. This eliminates the need to include the application credentials in clear text in scripts and configuration files. For more information about AAPM feature, see the section Application to Application Password Management in the Privileged Account Manager Administration Guide. 1.1.3 Enhancements to Database Monitoring and Credential Checkout Database monitoring and credential checkout capabilities are now extended for the following databases: Sybase MySQL MariaDB PostgreSQL For more information about configuring privileged access to databases, see the section Privileged Access to Databases in the Privileged Account Manager Administration Guide. 1.2 User Experience Improvements New User Console New Administration Console 1.2.1 New User Console Privileged Account Manager now provides a new HTML5-based responsive user console, which replaces the old Myaccess console. The new user console includes the following additional features: Tagging Resource Accesses: You can now group resource accesses and give a customized label to the group. These groups help you to identify and search the resource accesses easily. For more information about tagging the resource accesses, see the context-sensitive help in the user console. Context-Sensitive Help: These are task-based help files embedded in the user console to improve usability. To view the context-sensitive help, click the question mark icon on the appropriate user console page. You can now access the user console using the URL https://<pam server host name/ip address>/pam. 2 Privileged Account Manager 3.5 Release Notes

1.2.2 New Administration Console In addition to the old administration console, this release provides a new HTML5-based responsive administration console. To access the new administration console, use the URL https://<pam server host name/ip address>/pam. You must have the administrator role to access the new administration console. The new administration console includes only the following: Access Reports 1.2.2.1 Access You can access all other features from the legacy administration console. The Access Dashboard is now referred as Access. In the Access tab, you can perform the following: View the access requests from the user and perform appropriate action on the request, such as approve, deny or revoke. Review credential checkouts and force check-in the credentials if required. View, request, and access the resource accesses granted to you. These user console capabilities are now included as part of the administration console to make all the features available to the administrator in one console. 1.2.2.2 Reports The Reporting Console is now referred as Reports. The Reports tab now contains only the Session Reports which includes some predefined reports such as All sessions, Disconnect sessions and so on. You can click the appropriate report to view the report data and perform the following: Customize the predefined report and save as a new report. Filter the report data based on a set of filtering criteria. Export the report to a CSV file. 1.3 Enhancements to Integration Ready Interfaces Enhancements to REST API Application to Application Password Management 1.3.1 Enhancements to REST API Privileged Account Manager provides REST APIs for integrating with any third-party applications such as ServiceNow. Using Privileged Account Manager REST API, you can perform the following: Policy management User management Credential Vault management Application credential check-in and check out Privileged Account Manager 3.5 Release Notes 3

The REST API documentation is now available in the new administration console and the new user console. To view the REST API documentation, click the logged in user name and then click REST API on the administration or the user console. 1.3.2 Application to Application Password Management Using Application to Application Password Management (AAPM), you can integrate an application with any application managed by Privileged Account Manager to perform automated or scheduled tasks. For more information about the AAPM feature, see the Application to Application Password Management section in the Privileged Account Manager Administration Guide. 1.4 Performance and Scalability Improvements The video conversion mechanism is optimized and the default frame rate is set to 5. This reduces the temporary disk space requirements of agents. Privileged Account Manager now provides an option to off-load the video generation process to dedicated video off-load agents. This makes your agents lightweight by consuming less CPU and RAM. Off-loading the video generation operation is highly recommended when you are using SSH relay with X11 forwarding and privileged access to applications using SSO. For more information about configuring video off-load, see the section Video Off-Load in the Privileged Account Manager Administration Guide. 1.5 Privileged Access to Resources Using Telnet SSH relay is now enhanced to support privileged access to target resources, such as network switches, and mainframes using the Telnet protocol. 1.6 Enhancements to Privileged Account Discovery Privileged Account Sniffer is now enhanced to discover service accounts in Windows computers that are standalone or part of a domain. In addition, the user interface of the tool is also enhanced for better user experience. For more information about Privileged Account Sniffer, see the section Discovering Privileged Accounts in the Privileged Account Manager Administration Guide. 1.7 Authentication Support for Email Alerts Privileged Account Manager can now send emails even when an SMTP server mandates authentication for sending emails. 1.8 Updates to Supported Platforms There are several updates to the Privileged Account Manager supported platforms. For the complete list of supported platforms, see the Technical Information website. 1.9 Software Fixes Privileged Account Manager 3.5 includes software fixes that resolve several issues. Command Control Authorization Fails When the Command Included in Rule Is not Enclosed in Asterisks X11 Forwarding is not Supported on CPCKSH SHELL Summary of Added Target Systems Page is Blank after Importing Domain configuration 4 Privileged Account Manager 3.5 Release Notes

LDAP Authentication fails When Password Contains Multiple '$' Characters Unable to Start or Stop Privileged Account Manager Services Using systemctl Command Audit Events Are Not Sent For Commands executed in PCKSH or CPCKSH with Enhanced Access Control Secure Shell Relay Connection Fails with an Error Intermittent connectivity issues and client timeout from WinSCP SFTP through Privileged Account Manager ssh-relay Secure Shell Relay Connection Fails for credential type SSH Key SSH connection Fails to some HP Switches When the Banner is Enabled on A Target Server Unable to Access Privileged Account Manager Console Using Hostname in Internet Explorer in Certain Configurations Windows NPUM Manager Crashes when RDP is Attempted to a Citrix Host with NPUM Agent Installed User Sessions Are Disconnected During Direct RDP Using the Run as Privileged User option Displays an Error Audits missing in Direct RDP Session as Privileged Account Manager Does not Monitor Certain Operations Session Recordings Are Trimmed when Screen Scaling is Set to 125% or Higher Unable to Disconnect Session Or Customize Screen Size from User Console View Authorized Command Control Rule Name Through Metadata Launching a New Page from Admin Console Does Not Require Re-authentication Unauthorized Users can Configure Syslog Settings Incorrect permissions on Some of the Directories in Backup Package Manager 1.9.1 Command Control Authorization Fails When the Command Included in Rule Is not Enclosed in Asterisks You can either enter the full path of the executable or include the executable name inside asterisks as per your requirement. You need to enclose the path of executable in double quotes if path of file includes a space. (Bug 1097864) 1.9.2 X11 Forwarding is not Supported on CPCKSH SHELL X11 forwarding is supported on CPCKSH SHELL by setting the /usr/bin/pcksh to -o x11forwarding. (Bug 598519) 1.9.3 Summary of Added Target Systems Page is Blank after Importing Domain configuration In the Privileged Account Sniffer tool, after importing domain configuration, the Summary of Added Target Systems page displays the complete configuration available in the imported XML file. The imported domain configuration updates all the fields in the Domain Details page except the Password field. You can initiate the discovery from the Summary of Added Target Systems page.(bug 1062456) Privileged Account Manager 3.5 Release Notes 5

1.9.4 LDAP Authentication fails When Password Contains Multiple '$' Characters LDAP passwords can have multiple '$' characters and authentication will be successful. (Bug 1018428) 1.9.5 Unable to Start or Stop Privileged Account Manager Services Using systemctl Command Issue: Privileged Account Manager service in SLES 12 or RHEL 7 cannot be started or stopped by running systemctl start npum and systemctl stop npum commands. (Bug 1014058) Fix: When you install Privileged Account Manager 3.5, you can start or stop Privileged Account Manager services by running the systemctl start npum or systemctl stop npum commands. You can use systemctl status npum command to view the status. 1.9.6 Audit Events Are Not Sent For Commands executed in PCKSH or CPCKSH with Enhanced Access Control Issue: Commands executed in PCKSH or CPCKSH with Enhanced Access Control are not included with command arguments of a command in auditing. (Bug 1039296) Fix: Commands executed in PCKSH or CPCKSH with Enhanced Access Control are included with command arguments of command in auditing. 1.9.7 Secure Shell Relay Connection Fails with an Error Issue: Secure Shell (SSH) relay connection fails with the following error: no matching mac found (Bug 1078801) Fix: SSH relay connection works as expected and does not display an error. 1.9.8 Intermittent connectivity issues and client timeout from WinSCP SFTP through Privileged Account Manager ssh-relay The SFTP connection using WinSCP works as expected.(bug 1086893) 1.9.9 Secure Shell Relay Connection Fails for credential type SSH Key Issue: SSH connection fails for credential of type SSH key when it is created with empty passphrase. (Bug 1050805) Fix: SSH Connection is successful when it contains empty passphrase. 1.9.10 SSH connection Fails to some HP Switches When the Banner is Enabled on A Target Server SSH to a target server with banners enabled and to HP switches works. (Bug 1084662) 1.9.11 Unable to Access Privileged Account Manager Console Using Hostname in Internet Explorer in Certain Configurations Privileged Account Manager can be accessed by using the https://<hostname of PAM server>/ PAM URL on all browsers. (Bug 1030579) 6 Privileged Account Manager 3.5 Release Notes

1.9.12 Windows NPUM Manager Crashes when RDP is Attempted to a Citrix Host with NPUM Agent Installed Privileged Account Manager can do an RDP Relay to machines with Citrix server installed and monitor a session. (Bug 785165) 1.9.13 User Sessions Are Disconnected During Direct RDP Issue: During Direct RDP sessions, end users are unable to connect to servers and get disconnected from the session. This happens when Secondary authentication option in a direct RDP policy of Privileged Account Manager is set to No. (Bug 1096734) Fix: During Direct RDP sessions, users get connected and their sessions are monitored by PAM irrespective of the setting of the secondary authentication flag, in Privileged Account Manager policy. 1.9.14 Using the Run as Privileged User option Displays an Error You can use the Run as Privileged formatting option to get elevated access to a target application, based on user s policy defined in Privileged Account Manager. (Bug 1096551) 1.9.15 Audits missing in Direct RDP Session as Privileged Account Manager Does not Monitor Certain Operations Issue: Privileged Account Manager does not monitor the following on Windows Server: Windows Explorer is not always monitored. Folder and File operations from Windows Explorer are not monitored at the command level. In a reconnected session, applications that were running prior to the disconnection are not monitored. (Bug 1056100) Fix: During a fresh login in Windows session or a reconnected Windows session, PAM agent monitors the operations done using Windows explorer. PAM agent also would monitor the activities done in applications that were already running in a reconnected session. File or folder operations like creation of a file are monitored at command level, like CreateFile <filename>. For delete operations on file or folder using Windows GUI, the operation is monitored using GUI audits like Delete menu clicks. 1.9.16 Session Recordings Are Trimmed when Screen Scaling is Set to 125% or Higher Issue: When screen scaling is set to 125% or higher on the computer from where RDP session is initiated to the target system, then the videos captured for the monitored session are trimmed and the entire screen is not captured. (Bug 1069198) Fix: Even when screen scaling is set to 125% or higher, Privileged Account Manager records the entire screen in video captures. Ensure that the latest Microsoft Windows patches are installed on the computer for this feature to work as expected. Privileged Account Manager 3.5 Release Notes 7

1.9.17 Unable to Disconnect Session Or Customize Screen Size from User Console You can configure the screen size of the remote desktop session. To configure from the My Access page, click Predefined Tags > Windows. Select a resource and click Access Details > Display Configuration and specify the screen size.(bug 1067339) You can click a Windows SSO session to launch a remote desktop session window and close the window to disconnect the session. 1.9.18 View Authorized Command Control Rule Name Through Metadata Issue: Command Control reports does not contain authorization rule name. (Bug 1064886) Fix: Command Control reports displays authorization rule name. To display Authorized Rule name from meta data, add $<AuthorizedRule>$ in the rule's user message. 1.9.19 Launching a New Page from Admin Console Does Not Require Reauthentication Issue: Launching new pages does not require re-authentication and logging out of open session logs you out of all open sessions. (Bug 1076347) Fix: Launching new pages from Admin Console displays the login page. 1.9.20 Unauthorized Users can Configure Syslog Settings Issue: Syslog Settings when edited by unauthorized users does not display an error. (Bug 1059034) Fix: The fields in the Syslog Settings page are disabled for unauthorized users. 1.9.21 Incorrect permissions on Some of the Directories in Backup Package Manager File and folder permissions have been corrected in Backup Package Manager.(Bug 1092678) 2 System Requirements For information about hardware requirements, supported operating systems and browsers, see the Technical Information website. 3 Installing Privileged Account Manager 3.5 For information about installing Privileged Account Manager 3.5, see the Privileged Account Manager Installation Guide. 4 Upgrading to Privileged Account Manager 3.5 You can upgrade to Privileged Account Manager 3.5 from Privileged Account Manager 3.2 or later. For information about upgrading to Privileged Account Manager 3.5, see Upgrading NetIQ Privileged Account Manager in the Privileged Account Manager Installation Guide. NOTE: Branding of the user console is not supported in Privileged Account Manager 3.5. Therefore, any customizations made to the user console will not be available after upgrading to 3.5. 8 Privileged Account Manager 3.5 Release Notes

5 Known Issues NetIQ Corporation strives to ensure our products provide quality solutions for your enterprise software needs. The following issues are currently being researched. If you need further assistance with any issue, please contact Technical Support. Section 5.1, Privileged Single Sign-on is not Supported in Microsoft Edge, on page 9 Section 5.2, Secure Shel Java Terminal Displays Random Characters Instead of the Typed Characters, on page 9 Section 5.3, Unable to Refresh Data In Access page While Using Internet Explorer 11, on page 10 Section 5.4, Time Zones Are Different In Reporting Console and Output, on page 10 Section 5.5, All Registered Agents become Unregistered after License is added to Privileged Account Manager, on page 10 Section 5.6, Audit videos do not Play in Microsoft Edge Browser, on page 10 Section 5.7, PAM User Console cannot be Customized Branded, on page 10 Section 5.8, Unable to login to PAM console by using Firefox Quantum and Edge browser, when Secondary Authentication is enable for biometrics devices, on page 10 Section 5.9, Newly Created Reports are not Listed Under My Views in Internet Explorer 11 Browser, on page 10 Section 5.10, New sessions are not Updated in Session Table in Internet Explorer 11 browser, on page 10 Section 5.11, Moving Multiple Objects Does Not Work, on page 11 Section 5.12, The Run as privileged user Option Is Not Displayed on a Windows 2012 Server, on page 11 Section 5.13, The Command Control Objects Are Not Displayed When Large Number of Objects Are Added Simultaneously, on page 11 Section 5.14, The Unregistered Hosts List Is Not Displayed, on page 11 Section 5.15, The Changes to the Syslog Settings Do Not Get Applied, on page 11 Section 5.16, Cannot Uninstall Privileged Account Manager 3.2 Through Windows Add/Remove Programs, on page 11 Section 5.17, NPAM Service Commands Does Not Work In SUSE Linux Enterprise Server 12 or Later, on page 12 5.1 Privileged Single Sign-on is not Supported in Microsoft Edge Workaround: Use Microsoft Internet Explorer 11 to enable Privilege Single Sign-on in browsers with Local Group Policy configured. (Bug 1079379) 5.2 Secure Shel Java Terminal Displays Random Characters Instead of the Typed Characters Issue: SSH Java terminal displays random characters instead of the typed characters on Java SSH relay connection to certain network switches. (Bug 1086870) Workaround: Use alternative SSH clients such as command line SSH or PuTTY, or MobaXterm, instead of Java SSH. Privileged Account Manager 3.5 Release Notes 9

5.3 Unable to Refresh Data In Access page While Using Internet Explorer 11 Issue: When you click Refresh in the Access page, the updated data is not displayed.(bug 1095367) Workaround: Click Refresh in Internet Explorer browser instead of Refresh in the Access page. 5.4 Time Zones Are Different In Reporting Console and Output Issue: For certain Linux and Unix sessions, the time zone for Start Time is different in the Reporting Console and a playback of the session. (Bug 1041802) Workaround: There is no workaround at this time. 5.5 All Registered Agents become Unregistered after License is added to Privileged Account Manager Workaround: Install PAM License immediately after deploy PAM manager. If License is added later, re-register the agents after you add a new license. (Bug 1100050) 5.6 Audit videos do not Play in Microsoft Edge Browser Workaround: Audit videos can be viewed in other supported browsers. (Bug 1037322) 5.7 PAM User Console cannot be Customized Branded Workaround: There is no workaround at this time.(bug 1094124) 5.8 Unable to login to PAM console by using Firefox Quantum and Edge browser, when Secondary Authentication is enable for biometrics devices Issue: When you use Privileged Account Manager in Microsoft Edge of Firefox Quantum, after you install AAF 6.0, you are unable to enroll biometric devices. (Bug 1097960) Workaround: There is no workaround for Firefox Quantum at this time. For the workaround while using Microsoft Edge, see (https://www.netiq.com/documentation/advanced-authentication-60/ device-service-installation/data/system_requirements.html). 5.9 Newly Created Reports are not Listed Under My Views in Internet Explorer 11 Browser Use browsers other than Internet Explorer 11. To view the list of supported browsers, see the Technical Information website. (Bug 1100985) 5.10 New sessions are not Updated in Session Table in Internet Explorer 11 browser Use browsers other than Internet Explorer 11. To view the list of supported browsers, see the Technical Information website. (Bug 1100970) 10 Privileged Account Manager 3.5 Release Notes

5.11 Moving Multiple Objects Does Not Work Issue: Selecting and moving multiple objects by using the Shift/ Ctrl key does not work. Workaround: To move multiple objects, you can use shift + select the required objects, or use Select All. (Bug 915307) 5.12 The Run as privileged user Option Is Not Displayed on a Windows 2012 Server Issue: When you right-click Start on a Windows 2012 server, the Run as privileged user option does not get displayed. (Bug 901032) Workaround: To workaround this issue, right-click the application in the folder where the application is installed to execute Run as privileged user. 5.13 The Command Control Objects Are Not Displayed When Large Number of Objects Are Added Simultaneously Issue: When Command Control Objects are added simultaneously in large numbers, the objects do not appear in the console. This is an intermittent behavior. (Bug 908307) Workaround: There is no workaround at this time. 5.14 The Unregistered Hosts List Is Not Displayed Issue: In the administration console, when you search for unregistered hosts by clicking Hosts > List Unregistered Hosts > IP Range, the Failed to list unregistered agents error is displayed. (Bug 832747) Workaround: Ensure that when you install Agents, you register it with the Manager for Privileged Account Manager. 5.15 The Changes to the Syslog Settings Do Not Get Applied Issue: In the Reporting console of Privileged Account Manager when you save the changes to syslog settings, such as select SSL, or Allow Persistent Connections, the changes are not applied. (Bug 895993) Workaround: To workaround this issue, restart Privileged Account Manager. 5.16 Cannot Uninstall Privileged Account Manager 3.2 Through Windows Add/Remove Programs Issue: Uninstalling Privileged Account Manager 3.2 through Windows Add/Remove Programs displays an error. This issue occurs only when the Privileged Account Manager is upgraded to 3.2 using Privileged Account Manager 3.2 installer. (Bug 1029461) Workaround: Uninstall Privileged Account Manager through command line or Privileged Account Manager 3.2 installer. Privileged Account Manager 3.5 Release Notes 11

5.17 NPAM Service Commands Does Not Work In SUSE Linux Enterprise Server 12 or Later Issue: The NPAM service commands such as start, stop, restart and status does not work in SUSE Linux Enterprise Server 12 or later. (Bug 1041284) Workaround: To workaround this issue, perform one of the following: Reboot the system using the following command: reboot (or) shutdown -r now Kill and restart the NPAM process using the following command: pkill unifid /etc/init.d/npum start After performing one of the preceding steps, you can verify the NPAM process running status by executing the following command: /etc/init.d/npum status 6 Legal Notice For information about legal notices, trademarks, disclaimers, warranties, export and other use restrictions, U.S. Government rights, patent policy, and FIPS compliance, see https://www.netiq.com/ company/legal/. Copyright 2009-2018 Micro Focus or one of its affiliates. All Rights Reserved. 12 Privileged Account Manager 3.5 Release Notes