Privileged Access Management (PAM) Implementation
Administrator accounts are what attackers want most: one stolen domain or global admin password can open every system you have. Privileged access management takes away standing admin rights, so they are granted for a task, approved, time-limited and recorded, and keeps the passwords that remain in a vault instead of in people's heads and spreadsheets.
What is included
- A review of who holds admin rights today, and which of them are needed
- Just-in-time admin roles with Microsoft Entra Privileged Identity Management: requested, approved, time-limited, with two-step sign-in on activation
- Separate admin accounts, so daily email and browsing never run with admin rights
- A password vault for shared, service and break-glass accounts, with rotation (CyberArk, Delinea, Keeper, Bitwarden or BeyondTrust)
- Unique, rotating local administrator passwords on every Windows device with Windows LAPS
- Tiered administration for Active Directory, so a workstation compromise cannot reach the domain controllers
- Emergency break-glass accounts, set up and monitored
- Recording of privileged sessions where the platform supports it, and alerts on unusual admin activity
- Regular access reviews, with leavers' and movers' rights removed
What you get
- No standing admin rights for a stolen password to use
- Every privileged action tied to a person, a reason and a time
- Evidence for auditors, insurers and POPIA section 19
One engineer handles it from start to finish, so a change requested today can be in production the next day, once change-control documentation and testing are complete.
Related services
IT Security
Harden what you already have, close the gaps attackers use, and know where you stand.
Hardening & Vulnerability Management
Hardened to CIS benchmarks, scanned for vulnerabilities, and proven with reports.
Automated Patch Management
Windows, Linux and third-party applications patched on schedule, with a report that proves it.
Talk to us about privileged access management
Tell us what you need. You will hear back from the person who will do the work.