You need to define HBAC rules that target system-auth PAM service on
this host then.

But yes, any practical PAM service would work as long as you have
appropriate HBAC rules for this service.

Is an HBAC Service in IPA the counterpart to the PAM file on an ipa client residing in /etc/pam.d/ ?

