Bitara

Privileged Access Management (PAM) Implementation

Administrator accounts are what attackers want most: one stolen domain or global admin password can open every system you have. Privileged access management takes away standing admin rights, so they are granted for a task, approved, time-limited and recorded, and keeps the passwords that remain in a vault instead of in people's heads and spreadsheets.

What is included

  • A review of who holds admin rights today, and which of them are needed
  • Just-in-time admin roles with Microsoft Entra Privileged Identity Management: requested, approved, time-limited, with two-step sign-in on activation
  • Separate admin accounts, so daily email and browsing never run with admin rights
  • A password vault for shared, service and break-glass accounts, with rotation (CyberArk, Delinea, Keeper, Bitwarden or BeyondTrust)
  • Unique, rotating local administrator passwords on every Windows device with Windows LAPS
  • Tiered administration for Active Directory, so a workstation compromise cannot reach the domain controllers
  • Emergency break-glass accounts, set up and monitored
  • Recording of privileged sessions where the platform supports it, and alerts on unusual admin activity
  • Regular access reviews, with leavers' and movers' rights removed

What you get

  • No standing admin rights for a stolen password to use
  • Every privileged action tied to a person, a reason and a time
  • Evidence for auditors, insurers and POPIA section 19

One engineer handles it from start to finish, so a change requested today can be in production the next day, once change-control documentation and testing are complete.

Talk to us about privileged access management

Tell us what you need. You will hear back from the person who will do the work.

Contact us