Hello, I’m currently planning for upgrading to AD DS 2016 and, since the primary driver is the new PAM/PIM/JiTA/JEA capabilities, I’d like to hear from people who are currently using these technologies. Specifically, I’d like to hear any gotchas/caveats (or the lack of, if that’s your experience), if you use it in-prod or with a shadow forest, and if you’re using MIM 2016, PowerShell or both as management interfaces. Other than these two blog posts, I haven’t found much deep-dive info on these technologies. Also the blog posts seem to imply that PAM is possible without deploying a shadow forest or using MIM, but the documentation as I understand it says that both are requirements. Side note: If you are using the above in a forest with non-contiguous domains/namespaces (i.e. example.local and example.company.com) I would really like to hear from you.
Thanks in advance, CJD