Talk to us Risks to Watch

Webinar – Harshavardhan Lale and Geoff Cairns on Protecting the Crown Jewels with Modern PAM

ARCON hosted a webinar featuring Forrester to discuss best security practices around privileged identities. On June 5th, 2024, Harshavardhan Lale, VP – Business Development, ARCON and guest speaker Geoff Cairns, Principal Analyst, Forrester turned their attention to the role of modern Privileged Access Management (PAM) in protecting the crown jewels of an enterprise. It includes privileged identities, administrative identities, cloud consoles, AI models, credentials of interactive/ non-interactive accounts and more.

Moderated by Dushyant Arora, Marketing Lead, ARCON, both the speakers in this webinar discussed implementation of best practices in privileged access environments with the help of a robust PAM solution to combat risks around privileged identities. Moreover, there were insights about ARCON | Privileged Access Management (PAM) solution that offer capabilities to navigate through most complex PAM use cases and help to maintain strong security posture.

During the first half of the webinar, Geoff Cairns from Forrester highlighted the trends shaping the next generation of Identity and Access Management. Below are the key takeaways from the first half of the session:

  • Based on data from Forrester’s 2023 Security Survey, it has been observed that the customers are struggling with the complexity of their IT environment. The challenge is more around centralized visibility that can lead to identity sprawl such as orphan accounts over privileged users and over-permissioned accounts (or over-entitlements).
  • Geoff added that the evolving threat landscape is both internal and external. The hackers are capitalizing on identity-based attacks where legacy systems often are in tech silos leading to gaps in IT processes. This is further evidenced by organizations that have recently been in the news. United healthcare had acquired Change Healthcare a couple of years ago. During the process unfortunately, the organization failed to put MFA on some externally facing servers, and that resulted in identity abuse by phishing the credentials with the help of social engineering techniques.
  • Referring to the Forrester Security Survey once again, Geoff presented some primary drivers that resulted in purchasing of IAM solutions in the last 12 months. 26% of respondents (security decision makers responsible for IAM security) indicated that a top driver was replacing an existing IAM solution that was ineffective or too costly. 25% responded that cloud migration requires new IAM solutions to meet the necessary security and compliance requirements in the organization.
  • Continuing with the legacy IAM technology, it is a fact that with the passage of time, any IAM solution becomes less secure, inadequate robustness of the features, difficult to upgrade and costly to operate. Interestingly, it is increasing every year. The technology replacement trends that are seen in 2022, have turned more challenging in 2023 and onwards.
  • Coming to the essence of Privileged Access Management (PAM), Geoff drew the reference of a newly released Forrester report on IM trends for 2024. It included ten different trends among which three different areas are relevant in this context. While talking about Privileged Access Management (PAM), he narrowed down to identity threat intelligence, cloud entitlements and visibility and management of machine identities.
  • Identity Threat Detection and Response (ITDR) has been discussed a lot in the IT security community in recent times and ITDR capabilities have increasingly been incorporated into broader IAM and security platforms. Identity Threat Intelligence in this respect is interpreted as critical insights on threats to IAM systems and digital identities. It uses AI/ML algorithms to evaluate real-time risks and produces intelligence feeds for timely and relevant security measures. It enables swift action to reduce the impact and cost associated with data breaches.
  • In terms of cloud entitlements, it is all about visibility and governance of cloud identities. Referring to cloud infrastructure, entitlement management is quite often used interchangeably with cloud governance. Centralized visibility and governance support multi-cloud environments like Azure, AWS, GCP. It ensures safer IaaS console configuration and data access management with CIEM (Cloud Infrastructure and Entitlement Management) practices. It is increasingly added to IAM platforms globally.
  • While talking about machine identity management, Geoff highlighted the importance of operational aspects, especially when the objective is to mitigate the risks of data breaches. The growth of machine identity is going to surpass human identities to improve operational resilience. By increasing the number of machine identities, organizations can reduce risks associated with the expanded threat surface.
  • Geoff put an end to his session by providing several strong PAM recommendations to protect enterprise data assets. There must be continuous supervision and improvement of preventive and reactive identity security measures through robust PAM integrations. Strong governance for privileged identities must be ensured and machine identities must be brought under a unified IAM program strategy.

In the latter half of the webinar, Harshavardhan Lale from ARCON discussed how modern privilege access management solution mitigates the challenges of protecting enterprise data assets by focusing on the real crux of the crown jewel i.e. identity. The key takeaways from his session are as follows.

  • PAM helps you mitigate human errors by trying to eliminate unwanted access from people. IT security leaders always ensure that people only have access to the resources which they are entitled to automatically diminish the attack service, because instead of a user having access to 100 servers, he/ she only has access to only 10 servers/ devices. It obviously increases productivity, efficiency, and compliance.
  • The array of multiple identities that we see in an enterprise are human identities, machine identities, API identities, privilege identities and BOT identities. Now all these
  • identities are increasing in every industry and opening gateways for “crown jewels” in an organization.
  • Harsh provided several examples of “crown jewels” in an enterprise. These are AI models, cloud management consoles, Containers, CI/ CD pipeline, users of SaaS on AWS, Azure, GCP, credentials of interactive/ non-interactive accounts, administrative identities, active directory domain controllers, infra components, IaaS/ PaaS/ SaaS, and certificate servers.
  • Now the question is how do you manage these complexities using PAM solution? As there exist different crown jewels, these crown jewels are managed with the help of these identities, and these identities can be managed by deploying PAM. The basic formula is to verify, approve, authorize, allow, and monitor these identities to maintain security.
  • The other way to manage the complexities is by seamless integration of MFA (Multi-Factor Authentication) both for logging to PAM and accessing critical systems/ assets.
  • Just-In-Time (JIT) access is another aspect to manage and control privileged identity access only during requirements. It ensures that the right person is getting the right access to the right device at the right time for the right reasons. ARCON JIT privilege helps organizations to follow the principle of “Least Privilege”.
  • PAM offers continuous monitoring and threat detection of every identity in an IT infrastructure. It helps to build identity governance and implement security practices regularly.
  • The other aspect or the other way of dealing with this situation is to set up ephemeral access for all the users. With this IT administrators can ensure that identities are not trying to access (or allowed access) and authorized to your crown jewels. But they are allowed on a ‘need-to-know and ‘need-to-do’ basis only required. Hence ephemeral access will be given to create an active directory. With the help of PAM, the users are granted access and once the session is disconnected, the ephemeral account is again deleted from the system.
  • If we talk about access and authorization, then granular level access control is highly imperative, especially based on end-user roles and responsibilities that exist within the organization. It builds a layer of access control for restricting unauthorized access to critical IT infrastructure.
  • Auto onboarding on the other hand allows administrators to seamlessly add new server groups, user accounts with associated privileges to map new users onboarded on PAM solution. It auto-on-board users and assets and maps them to appropriate rules (based on roles).
  • In continuation of Geoff’s discussion about proliferation of identities, Harsh added that identities are the weakest link to compromise enterprise information assets. It includes human (business) identities, machine identities, privileged identities, BOT identities, APIs etc. Eventually, all the identities are converged into digital identities that are provisioned/ deprovisioned/ re-provisioned to manage and control the activities.
  • Discussion of modern PAM is incomplete without cloud platform/ cloud infrastructure. Enterprises can secure their cloud environment by deploying PAM through which they can onboard cloud infrastructure end users, make them access-ready, monitor the access and rotate credentials/ keys. This way, they can meet compliance requirements.
  • ARCON has made onboarding quite simple through different directories for AWS, Azure, or GCP through Auto-onboarding feature. With this, IAM users can auto onboard in SaaS environment, Windows, Linux and RDS (database) users can auto onboard in IaaS and PaaS environments. This automated task can happen in every cloud platform like AWS, Azure or GCP with any requirement of an IT administrator.
  • Lastly, Harsh discussed ARCON’s profile as a risk control solution provider and esteemed global PAM vendor. ARCON | PAM strengthens the security fabric in an enterprise and the IT administrators can define the policies and permissions for distinct entities wanting to access files, workloads, databases, management consoles, services, servers, containers, and many other cloud resources. It can even control misuse of over entitlements in the cloud environment that could invite unprecedented IT threats.

Conclusion

Before the final wrap, the webinar concluded by discussing several questions raised by the participants and moderated by Dushyant. Both Geoff and Harsh shared their valuable insights while answering the questions.

Privileged Identity Management: Securing Elevated Access with Confidence

Overview

In today’s complex IT environments, securing privileged access is critical for preventing unauthorized access to sensitive data and resources. This is where Privileged Identity Management (PIM) comes into play. It’s a key solution that provides organizations with granular control over who can access critical systems, how they can perform privileged tasks, and for how long.

In this blog, we’ll explore what PIM is, how it works, its key features, and why it’s essential for any organization. We’ll also dive into the best practices for configuring PIM, the role it plays in modern cloud environments, and how it integrates with privileged access management solutions to enhance security.

Request a Demo

What is Privileged Identity Management (PIM)/ Privileged Access Management ?

Privileged Identity Management displayed on a computer screen with a security lock icon, emphasizing secure access control and digital protection measures

Privileged Identity Management (PIM) is a specialized subset of Identity and Access Management (IAM) that focuses on managing and monitoring user accounts that have privileged access within an organization. It is important to differentiate PIM from Privileged Access Management (PAM), which also enhances security by controlling user access to critical systems, but specifically manages and secures access for privileged accounts to sensitive resources.

PIM works by enforcing controls over privileged identities, ensuring that privileged credentials are granted temporarily and only when absolutely necessary. Once the task requiring privileged access is completed, access privileges are automatically revoked. This principle of least privilege ensures that no one has ongoing access to critical systems unless required. It ensures that systems and data are accessed on “need-to-know” and “need-to-basis”.  

Key Features of Privileged Identity Management

Organizations leveraging PIM and privilege management can secure their environments using several critical features:

1. Role-Based Access Control (RBAC)

RBAC allows IT administrators to define and manage roles that determine what level of access privileges each user has within the system. With PIM, roles are highly customizable, ensuring that users only receive the privileges they need, reducing unnecessary risk.

2. Just-In-Time Access

PIM grants temporary privileged access based on predefined policies. This ensures that users don’t have continuous privileged credentials, minimizing potential security risks and ensuring only necessary access is granted,using temporary credentials such as tokens, keys and passwords.  

3. Approval Workflows

Many PIM systems, including those used in privileged access management, require an approval process before granting privileged access. This oversight ensures accountability and reduces the chances of misuse, particularly in organizations with global administrators who manage sensitive systems.

4. Session Monitoring & Audit Trails

All activities carried out under privileged accounts are monitored and logged, focusing on privileged account activity. This includes detailed audit trails, session recording, and alerting, which helps in identifying suspicious behavior during the execution of privileged tasks.

5. Automatic Revocation of Access

Once a user completes a task requiring privileged access, PIM automatically revokes the access privileges. This reduces the attack surface by ensuring no user has lingering privileges they don’t need.

Why You Should Implement Privileged Identity Management Solutions?

What is Privileged Identity Management concept illustrated with a login form and a security lock icon, emphasizing secure access control on mobile devices.

Enhanced Security for Privileged Accounts

Privileged accounts are often the target of cyberattacks. By implementing PIM alongside privileged access management, organizations can safeguard these accounts, reducing the risk of insider threats and external breaches. This is especially important for global administrators who manage sensitive infrastructure.

2. Regulatory Compliance

PIM helps organizations comply with various regulatory frameworks such as GDPR,NIS 2, DORA HIPAA, PCI-DSS, and SOX, all of which require strong access management controls to protect sensitive data.

3. Reduced Insider Threats

By limiting the number of users with privileged access and enforcing monitoring, PIM reduces the risk of malicious insiders exploiting their privileges for unauthorized activities. Privileged credentials are closely managed, further reducing security risks.

4. Streamlined Identity and Access Governance

Privileged identity management solutions enable organizations to efficiently manage privileged access and user accounts, reducing administrative overhead and improving overall identity governance. This enhances both security and compliance. 

5. Vault Credentials 

It allows IT security teams to store, encrypt and randomize privileged credentials in a secure manner. Vaulting credentials not only strengthens the security for a privileged identity but also ensures adherence to several regulations and IT standards.  

 

Use Cases of Privileged Identity Management

1. Securing Admin Access in Cloud Environments

In cloud-based environments, administrator accounts are highly privileged, providing access to vital infrastructure and Microsoft Entra resources. PIM ensures that these accounts are tightly controlled and monitored, especially when performing privileged tasks that impact critical systems.

2. Managing Third-Party Vendor Access

Third-party vendors often require access to internal systems for maintenance or support. PIM ensures that these external users receive temporary and controlled access, limiting the potential for security breaches while performing privileged tasks.

3. Elevated Access for System Maintenance

During regular system maintenance, IT staff may require temporary access to high-privilege accounts. PIM, integrated with privileged access management, allows this access to be granted and revoked automatically, minimizing risks associated with excessive access privileges.

Best Practices for Configuring Privileged Identity Management

1. Implement the Principle of Least Privilege

Assign users the minimum privileges they need to perform their duties. This ensures that users don’t have unnecessary access privileges to sensitive systems or data, reducing potential security risks.

2. Utilize Role-Based Access Control (RBAC)

Define roles carefully and involve security administrators in managing roles to avoid assigning permanent administrative rights. Temporary roles with just-in-time privileged access reduce the attack surface and ensure better access management.

3. Enforce Multi-Factor Authentication (MFA)

Implement MFA for users requesting privileged access. This adds an extra layer of security, ensuring that even if credentials are compromised, attackers cannot easily gain access to critical systems.

4. Set Up Approval Workflows

Requiring approvals for privileged access requests adds accountability. Ensure that all requests are reviewed by authorized personnel before granting access, especially for sensitive tasks involving privileged credentials.

Challenges in Implementing PIM

While PIM and privileged access management are powerful tools, they come with challenges:

1. Complexity in Large Organizations

Configuring PIM for large enterprises with thousands of privileged accounts can be complex. Organizations must ensure that they have a clear strategy for role assignment, access management, and approval workflows.

2. Managing Hybrid Environments

Many organizations operate in both on-premise and cloud environments. Managing access privileges and privileged accounts across these hybrid environments requires careful planning and coordination.

3. User Resistance to Change

Users who are accustomed to having ongoing privileged access may resist the transition to just-in-time models. Educating users on the benefits of PIM and privilege management is critical for smooth adoption.

Future of Privileged Identity Management

The future of PIM lies in the integration of artificial intelligence (AI) and machine learning (ML). These technologies will enable predictive analytics to identify potential threats and automatically adjust access management controls based on user behavior. Additionally, PIM will continue to evolve as organizations move towards fully automated identity management solutions, particularly in the realm of privileged access management.

Conclusion: Securing Your Organization with PIM

As organizations increasingly rely on digital infrastructures, securing privileged access is more important than ever. Privileged Identity Management offers a robust solution to prevent unauthorized access to critical systems while ensuring compliance with regulatory standards. By implementing PIM alongside privileged access management, organizations can minimize their attack surface, reduce insider threats, and streamline their identity governance processes.

To stay ahead of evolving threats, investing in a PIM and privilege management solution is no longer optional—it’s a necessity.

 


Request a Demo