Privileged Access Security (PAS) Cloud Infrastructure
Imprivata Privileged Access Security (PAS) is a secure privileged access platform that enables organizations and enterprises to securely manage privileged access for internal administrators, internal users, vendors, contractors, and third-party support teams.
Available as an Imprivata-hosted SaaS offering or as a customer-managed deployment, PAS is built on a security-first architecture, PAS combines identity verification, privileged session management, credential protection, and comprehensive audit capabilities with a globally distributed cloud infrastructure designed for resiliency, availability, and regional deployment flexibility.
Whether supporting routine vendor maintenance, emergency access, or highly regulated environments, PAS provides secure remote access without exposing internal networks or privileged credentials.
Global Cloud Infrastructure
For Imprivata-hosted deployments, PAS is hosted in a single-tenant Amazon Web Services (AWS) environment.
Customer-managed deployments can be installed on supported virtual infrastructure, including private data centers or cloud-hosted virtual machines. In both deployment models, customer resources remain protected behind outbound-only connections established by Gateways or Gatekeepers.
Imprivata PAS is deployed across multiple geographic regions to support customer requirements for performance, availability, and data residency.
Each deployment is designed around regional resiliency principles, including:
-
Regional deployment options
-
High Availability architecture
-
Disaster Recovery capabilities
-
Encrypted communications
-
Continuous monitoring
Cloud Availability
Imprivata PAS Cloud is currently hosted on Amazon Web Services (AWS). Customers may select an appropriate deployment region based on proximity, organizational requirements, and service availability.
Use AWS Regions and Availability Zones to discover where the Imprivata PAS Cloud can be deployed.
Organizations deploying PAS outside of Imprivata-hosted AWS Cloud are responsible for selecting and managing the infrastructure that hosts their deployment. PAS supports customer-managed deployments on supported virtual infrastructure, including private data centers and cloud-hosted virtual machines. Customers are responsible for ensuring that their deployment satisfies PAS system requirements and that connectivity between PAS components is permitted.
Platform Availability and Resiliency
PAS is designed to provide resilient privileged access for business-critical environments.
For Imprivata-hosted PAS Cloud deployments, infrastructure resiliency is managed by Imprivata.
For customer-managed deployments, organizations may implement High Availability (HA) and Disaster Recovery (DR) architectures to meet business continuity objectives.
-
High Availability (HA) is an optional PAS deployment architecture designed for customer-managed environments. It provides automatic failover within a local clustered deployment to minimize service interruption caused by localized hardware or software failures. In PAS, High Availability refers to a specific clustered architecture and should not be confused with the general use of the term "high availability" to describe cloud services.
-
Disaster Recovery (DR) is designed to protect customer-managed deployments from site-level failures by maintaining a replicated standby environment. While High Availability minimizes downtime caused by localized infrastructure failures, Disaster Recovery enables service restoration following a catastrophic outage affecting an entire location. Many organizations deploy both capabilities together to support comprehensive business continuity objectives.
Although each capability addresses different operational risks, they are complementary and are commonly deployed together in customer-managed environments requiring maximum service continuity.
Depending on the deployment model, PAS supports:
-
Gateway redundancy
-
Failover-capable Gateway instances
-
Disaster Recovery architectures
-
Continuous health monitoring
-
Secure encrypted communications
-
Backup and recovery processes
Contact Imprivata to get help on High Availability and Disaster Recovery deployments.
Security Architecture
Gateways and Gatekeepers are deployed and managed within customer-controlled environments. These components establish secure outbound connections to PAS and broker access to protected resources without requiring inbound connectivity to the customer network. Their deployment, sizing, redundancy, and lifecycle management remain under the customer's control.
Rather than relying on traditional VPN access, PAS brokers secure, policy-driven connections between authorized users and protected resources.
Key architectural principles include:
-
Zero standing privileged access
-
Least privilege
-
Encrypted communications
-
Session isolation
-
Identity federation
-
Continuous auditing
-
Centralized policy enforcement
The PAS architecture separates authentication, authorization, session brokering, and target system connectivity to reduce attack surface while maintaining operational flexibility.
Platform Capabilities
The following sections contain high-level descriptions of the key core security capabilities in PAS.
PAS integrates with enterprise identity providers including:
-
Active Directory (AD)
-
LDAP
-
SAML 2.0 providers such as Microsoft Entra ID, Okta, Ping Identity, and ADFS.
-
RADIUS
Organizations can enable Single Sign-On (SSO), Multi-Factor Authentication (MFA), group synchronization, and role synchronization through supported identity providers.
Securely manage third-party access through:
-
Third-Party onboarding
-
Third-Party approval workflows
-
Application-specific authorization
-
Departmental access controls
-
Time-based access
PAS enables organizations to define vendor organizations, representatives, authorized applications, approval policies, and access schedules from a centralized interface.
PAS protects privileged credentials through:
-
Secure credential vault
-
Credential injection
-
API-managed credentials
-
Credential rotation
-
Optional External vault integrations
HTTP/HTTPS Credential Mapping enables secure credential injection into internal web applications without exposing credentials to end users. Randomized session tokens are substituted for stored credentials during authenticated sessions.
Organizations can provide secure remote access through desktop clients and browser-based sessions while providing centralized session management, credential protection, and continuous visibility. PAS has the following capabilities:
-
Desktop and browser-based remote sessions
-
Secure access to all FTP/UCP protocols
-
File transfer for authorized sessions
-
Remote desktop sharing and support
-
Session approval and policy enforcement
-
Session recording and audit logging
-
Secure credential injection during supported connections
PAS provides comprehensive visibility into privileged activity with:
-
Session monitoring and recording
-
Audit logs and connection history
-
User and privileged activity tracking
-
Centralized audit reporting
-
Syslog and SIEM integration
-
Support for security investigations and compliance reporting
PAS supports enterprise automation through:
-
REST API
-
Java SDK
-
Python SDK
-
C# SDK
-
API Keys
-
Automation workflows
API access enables organizations to automate administrative operations while maintaining secure authentication through rotating API keys and role-based authorization.
PAS includes capabilities that support security programs aligned with common regulatory and operational requirements.
For example:
-
Audit logging
-
Session recording
-
Multi-Factor Authentication
-
SAML SSO
-
Least privilege
-
Time-bound access
-
Approval workflows
-
Credential protection
-
Role-Based Access Control (RBAC)
-
Secure encrypted communications
Frequently Asked Questions (FAQs)
Imprivata PAS Cloud is hosted by Imprivata on Amazon Web Services (AWS) in a single-tenant deployment model.
Contact our Imprivata Customer Support for more information.
Customers deploying PAS in their own environments may host supported PAS virtual appliances on infrastructure of their choosing, including private data centers or supported cloud-hosted virtual machines. Customers are responsible for managing the hosting environment and ensuring that connectivity and system requirements are met.
Contact our Imprivata Customer Support for more information.
PAS supports any cloud deployment.
Contact our Imprivata Customer Support for more information.
Yes. Customer-managed deployments can implement the PAS High Availability architecture to provide automatic local failover within a clustered deployment. PAS High Availability is a deployment architecture specific to customer-managed environments and is distinct from the resiliency provided by the cloud infrastructure.
Yes. Disaster Recovery architectures protect against site-level failures through replicated standby environments and complement High Availability deployments.
Read the PAS Disaster Recovery guide for more information.
PAS appliances are hardened Linux servers with a strictly controlled security stack that includes multiple layers and continuous monitoring for both hosted and on-premise environments. Additionally, the PAS team is constantly testing and developing safety features and enhancements.
Read the Cloud Auto Upgrade and Manual Upgrades documents to ensure your server is up to date!
Yes. PAS protects customer data using industry-standard encryption.
Yes. PAS supports Active Directory (AD), LDAP, and other SAML-compatible identity providers for SSO and MFA.