Deployment considerations for SAS® 9.4 when using a Privileged Access Management (PAM) solution


This article covers what should be considered when using a PAM solution with a SAS 9.4 deployment on Red Hat Enterprise Linux.

Overview

Customers planning a SAS 9.4 deployment on Red Hat Enterprise Linux (RHEL) might use a Privileged Access Management (PAM) solution to manage authentication, privilege elevation, service account access, and auditing activities.

SAS supports SAS 9.4M9 on Red Hat Enterprise Linux 8.10. PAM solutions are third-party products and are not specifically certified or supported by SAS. However, the use of a PAM solution does not automatically make a SAS deployment unsupported. Supportability depends on how the PAM solution is implemented and whether it affects the operating system accounts, permissions, authentication mechanisms, or administrative access required by SAS software. 

Does SAS support PAM Solutions?

SAS does not certify or support specific PAM solutions. SAS support is limited to SAS software and SAS product functionality.

The use of a PAM solution does not inherently impact SAS supportability. However, SAS supportability can be affected if PAM policies, controls, or integrations restrict or modify the operating system access and privileges required by SAS installation, administration, maintenance, or runtime processes. 

Areas to Consider

When evaluating a PAM solution for a SAS 9.4 deployment, consider the following areas:

Authentication Integration

Determine whether the PAM solution will do the following:

Ensure that SAS users and administrators can authenticate successfully and retain the permissions required for platform administration.

Privilege Elevation

Determine whether the PAM solution will be used as the following:

SAS installation, configuration, maintenance, and administrative tasks often require elevated operating system privileges. Verify that the PAM solution's policies allow these activities to be performed successfully.

Service Account Management

Review how the PAM solution will manage the following:

Changes to service account credentials, authentication methods, or permissions should be validated to ensure SAS services continue to start and operate correctly.

Auditing and Monitoring

If the PAM solution is configured for the following, verify that these controls do not interfere with SAS processes, scheduled jobs, or platform administration activities:

Supported Operating System

SAS 9.4M9 supports Red Hat Enterprise Linux 8.10.

Before deployment, review the following resources:

Recommendations

Before installing SAS, do the following:

  1. Identify how the PAM solution will be used in the environment.
  2. Document any authentication, authorization, or privilege-management controls that will affect SAS administrators, users, or service accounts.
  3. Validate authentication and authorization requirements.
  4. Confirm that SAS installation and service accounts can perform required tasks.
  5. Verify that privilege elevation policies do not restrict SAS administration, maintenance, or troubleshooting activities.
  6. Validate password rotation, credential vaulting, and service account management processes for SAS services.
  7. Test SAS installation and operational procedures in a non-production environment when possible.

Summary

SAS 9.4M9 is supported on Red Hat Enterprise Linux 8.10. Privileged Access Management (PAM) solutions are third-party products and are not specifically certified or supported by SAS. Customers should validate that PAM authentication, privilege management, service account controls, credential management, and auditing configurations do not interfere with the installation, configuration, administration, maintenance, or operation of SAS software.SAS Support can assist with SAS software issues but cannot validate, certify, or troubleshoot the functionality of third-party PAM products. Based on the information provided in the customer inquiry, no SAS-specific compatibility concerns have been identified. However, customers are responsible for validating that their PAM implementation supports the operating system access requirements of SAS software.