Hi,
Which is the best Privileged Account Management solution for an enterprise? Why?
How is the privileged account management solution deployed? Can it work on-premises or in the cloud in physical or virtual environments, hosted on Windows or Linux OS?
Thank you!
Hi Mr. @Shibu Babuchandran,
Previously Mr. Belenky answered it here What is PAM & Why choose?
You can check the Gartner magic quadrant, Forrester wave for checking the PAM solutions in the market.
As per the organization's requirements and budget, you can easily choose suitable PAM solutions.
Every PAM solution has 3 modalities of deployment: on-premises, hosted and Cloud.
For deployment of what your organization wants as per compliance (Cloud, on-premises), if your organization wants the subscription-based license and doesn't interested to manage the hardware/machines/VM then you can go to the cloud but if your organization wants to Perpetual license then you have a good choice to select on-premises license.
When you choose any PAM solution you must have taken an idea about the license model for your organizational requirements (user-based or hardware-based), HA/DR modality.
Most users are used to the Windows environment. So, if you choose the Windows-based OS then your existing IT person manages it easily and Windows always give the patch update (every week) - you don't need to worry about the critical patches.
Shibu,
Your question is reminiscent to which religion is the true religion.
Most solutions have cloud and hybrid cloud solutions. Most solutions have both Physical and Virtualized solutions.
Most solutions support both Windows and Linux. When you say enterprise I am going to assume that you are referring to “Large and Multi-platform”.
Short Answer: Perform an event in your enterprise to determine your requirements by accomplishing the following:
These items are but a few and should be expanded based on your requirements. Progressing through these will provide clarity for you to determine additional areas to examine. The work product of this event will SIGNIFICANTLY qualify the Vendor selection from the available solutions out there. This will also prevent you from having buyer’s remorse in your initial product selection if it cannot meet the enterprise's needs.
If you are indeed an Enterprise, it would be an idea worth consideration to also examine the “Care and Feeding” of the solution:
A. You should be looking for a managed solution because the expertise to implement and manage these types of solutions is expensive to train and more expensive to keep.
B. It should also be able to weave into your existing administration models with minor alterations for automation.
C. Direct connection to Provider for automated download and installation of updates, security patches, and enhancements.
D. Capabilities to dynamically employ and leverage “Least Privilege” and segregation of duties principles.
E. Capabilities to Auto-Discover new systems and Accounts targeted for management.
F. Auto-Onboarding capabilities for these newly Discovered Systems and Accounts.
G. Analytics and Reporting capabilities to the nth degree.
H. Future modifications altering this solution should be exclusive to new Platforms for onboarding.
Hi,
DISCLAIMER: I belong to the company that is a distributor of Stealthbits (part of Netwrix) in Southern Europe, so I just going to mention this option.
Stealthbits based the privilege assignments in activities, instead of the access. That's why they call their solution Stealthbits Privileged Activity Manager (SbPAM).
The feature that I like most is the activity token. This allows creating a privileged account for the specified task, for the time required and in the desired scope. Once the task is completed, this account is deleted, so none of the user accounts are receiving privileges at any time.
This makes it very easy to accomplish the least privileged access model in a very effective way.
It works with AD, Azure AD and more, and each version includes new and very useful capabilities.
This solution is younger than most of the other solutions, but it is reaching a high maturity very fast, which is very receptive to the customers' demands and suggestions and gives excellent support.
I recommend you to consider it!
Hello @Shibu Babuchandran,
My name is Nurlan and I'm an SE at Remediant, who had spent the last 5 years specifically within PAM space.
Remediant's SecureONE solution specializes in stopping lateral movement by removing standing privileges across Windows, MacOS, and Linux machines. Whether machines are on-network, remote or in the cloud, we can help you minimize the blast radius of stolen credentials. This is a security blindspot for many organizations, regardless of whether they are at the beginning of their PAM journey or had already accumulated a stack of PAM investments.
It's very fast to deploy, can be completed over a couple of days, as opposed to the usual timelines of weeks and months that are associated with the most common type of PAM solutions. You don't need an FTE to manage it and can easily automate everything by leveraging published APIs.
Having said this, it would be beneficial to learn about your immediate objectives.
Are you trying to remove admin privileges from the users, are you trying to lockdown user endpoints (implement allow list/block list) or are you looking to vault your admin credentials?
Maybe you're looking to implement LAPS-like functionality, but not use LAPS itself?
The PAM field as a whole has expanded greatly and the spending on PAM tools has increased among enterprises and SMB companies.
Hi @Shibu Babuchandran ,
Full disclosure - I am an SE for Hitachi ID so naturally, I am biased. That said, Hitachi ID Bravura Privilege is a PAM solution. It scales well to both small and large enterprises and comes complete with all of the extras you normally pay additional fees for with other vendors. Session monitoring, all connectors, vault storage, high availability/fault tolerance, personal vault, etc.
It is available as an on-prem, SaaS or hybrid deployment model. We can provide licensing either by managed systems or by the number of users. All services are performed by non-offshore highly trained employees.
We have many reference customers in all verticals and would be happy to speak with you about any PAM initiatives you may have.
While analyst recommendations and magic quadrants are useful, they often don't tell the whole story. Looking forward to chatting with you.
Bruce Macdonald,
Sr. Sales Engineer
Hi @Richard Nagygyörgy, @Sanjeet Kumar Bhuyan and @ABHILASH TH,
Do you have any recommendations to share with @Shibu Babuchandran and the community?
Thanks!