Privileged Access Security Offering
Imprivata Privileged Access Security (PAS) Solutions provide a shared platform for managing privileged access across internal and third-party use cases. Privileged Access Management (PAM) and Vendor Privileged Access Management (VPAM) can operate together by sharing core technologies, components, functionality, and an administrative experience. When licensed together, PAM VPAM extend the same environment to address privileged access for both internal users and external vendors.
Deploying PAM and VPAM together combines their shared privileged access capabilities with features designed for each user population. PAM extends the platform with capabilities for internal account and credential management and administrative workflows, while VPAMadds third-party identity management, vendor access workflows, and Nexus connectivity. Together, they provide administrators with a broader approach to governing privileged access while maintaining workflows and controls appropriate to internal users and third parties.
Features and Capabilities
PAM and VPAM provide the following features and capabilities:
| Capability | PAM | VPAM | When licensed together |
|---|---|---|---|
| Vault and credential management | Yes | Yes | Centrally manage privileged credentials for internal and third-party access workflows. |
| Credential rotation | Yes | Yes | Manage the lifecycle of privileged credentials across both access use cases. |
| Credential injection | Yes | Yes | Provide credentials to supported connections without exposing them to users. |
| Approval and access controls | Yes | Yes | Apply controlled access workflows to protected resources. |
| Session management and auditing | Yes | Yes | Govern and audit privileged sessions across internal and third-party access. |
| Service and credential discovery | Yes | Yes | Discover services and credentials from the shared environment. |
| Internal workforce privileged access | Yes | Yes | Extend the platform to employees, administrators, and other internal privileged users. |
| Account Discovery | Yes | — | Extend Discovery to endpoints and accounts. |
| Just-In-Time Privilege Elevation | Yes | — | Provide temporary privilege elevation for eligible internal users. |
| Break-Glass | Yes | — | Provide authorized administrators with offline emergency access to eligible Vault secrets. |
| Personal Vault | Yes | — | Provide private secret storage for internal users. |
|
Custom Script Task |
Yes | — | Upload a custom script that the system runs as a scheduled or on demand task. |
| Vendor and third-party privileged access | — | Yes | Extend privileged access governance to external vendors and Vendor Reps. |
| Third-party identity management | — | Yes | Manage Vendor organizations and Vendor Rep identities, authentication, approvals, and access. |
| Nexus | — | Yes | Extend third-party access through supported VPAM and CPAM connections. |
PAM provides privileged access management for internal users, such as employees, administrators, and other members of your workforce who require elevated access to organizational systems. Additionally, PAM provides additional capabilities specifically designed for enhanced administrative privileged access:
-
Account Discovery discovers accounts associated with endpoints in your environment. Service and credential discovery can be used with either product, but endpoint and account discovery require PAM.
-
Just-In-Time (JIT) Privilege Elevation allows internal users to temporarily elevate privileges for eligible accounts when required. Elevation can require approval and is removed when the applicable access condition ends. JIT is not available to Vendor Reps.
-
Break-Glass provides authorized administrators with last-resort, offline access to Vault secrets when the primary server cannot be reached because of an outage or network failure. A PAM license is required to obtain the Break-Glass client.
-
Personal Vault provides private secret storage for internal users. Personal Vault is available only with PAM.
-
Custom Script Task runs a scheduled or on demand custom script on a target host, service, or secret.
VPAM provides privileged access management for external vendors and third parties that require access to systems within your environment.
Vendor Reps connect to authorized assets through Gatekeeper or Gateway applications configured for controlled access. Their activity within those assets is monitored so administrators have detailed records of vendor access.
VPAM shares core privileged-access capabilities with PAM, including Vault functionality, credential management, credential rotation, session access and governance, and applicable discovery capabilities.
For example, Discovery can identify services and credentials for both PAM and VPAM environments, while the additional ability to discover endpoints and accounts requires PAM.
Using PAM and VPAM Together
While PAM and VPAM can be deployed independently, licensing and deploying our Privileged Access Security together provides the best experience for users and administrators.
For example, an organization using VPAM to manage third-party access can add PAM when it also needs to govern employee privileged access and provide a personal vault to internal users. The existing environment then gains the PAM capabilities available to internal users, including Account Discovery, JIT Privilege Elevation, Break-Glass, and Personal Vault.
Similarly, an organization using PAM for its workforce and credential management can add VPAM when it needs to extend privileged access governance to vendors and other third parties.
This approach allows System Administrators to manage privileged-access users through a common architecture while applying controls appropriate to each population.