Privileged Access Management (PAM) Implementation
Administrator accounts are what attackers want most: one stolen domain or global admin password can open every system you have. Privileged access management takes away standing admin rights, so they are granted for a task, approved, time-limited and recorded, and keeps the passwords that remain in a vault instead of in people's heads and spreadsheets.
What is included
- A review of who holds admin rights today, and which of them are needed
- Just-in-time admin roles with Microsoft Entra Privileged Identity Management: requested, approved, time-limited, with two-step sign-in on activation
- Separate admin accounts, so daily email and browsing never run with admin rights
- A password vault for shared, service and break-glass accounts, with rotation (CyberArk, Delinea, Keeper, Bitwarden or BeyondTrust)
- Unique, rotating local administrator passwords on every Windows device with Windows LAPS
- Tiered administration for Active Directory, so a workstation compromise cannot reach the domain controllers
- Emergency break-glass accounts, set up and monitored
- Recording of privileged sessions where the platform supports it, and alerts on unusual admin activity
- Regular access reviews, with leavers' and movers' rights removed
What you get
- No standing admin rights for a stolen password to use
- Every privileged action tied to a person, a reason and a time
- Evidence for auditors, insurers and POPIA section 19
One engineer handles it from start to finish, so a change requested today can be in production the next day, once change-control documentation and testing are complete.
Related services
IT Security
Harden what you already have, close the gaps attackers use, and know where you stand.
Hardening & Vulnerability Management
Hardened to CIS benchmarks, scanned for vulnerabilities, and proven with reports.
Cybersecurity Training & Awareness
Your people are the first line of defence. We train them, test them, and measure it.
Talk to us about privileged access management
Tell us what you need. You will hear back from the person who will do the work.