Digital transformation is expanding organizational attack surfaces through initiatives such as digital workplaces, DevOps, security automation, and IoT, creating new security risks that must be managed without disrupting business operations. Privileged Access Management (PAM) is positioned as a critical control set for reducing risks tied to privileged access, which commonly undermines least-privilege principles and weakens accountability due to broad, often unmonitored permissions. Two primary privileged user groups are emphasized: privileged business users who access sensitive information assets through application accounts, and privileged IT users who administer infrastructure through system, software, or operational accounts. Core PAM capabilities span shared account password management, privileged session management, application-to-application credential management, session recording/monitoring, controlled privilege elevation/delegation, privileged user behavior analytics, endpoint privilege management, and privileged access governance, with an industry trend toward integrated suites and advanced analytics.
Xton Technologies is presented as a newer PAM entrant focused on a lean, efficient implementation of core PAM capabilities via Xton Access Manager (XTAM). XTAM groups functionality into privileged account management (vaulting of passwords/secrets/keys), privileged session management (browser-based access, monitoring, recording, remote control), and privileged job/task automation (recurring admin tasks like password resets and health checks). Its fully agentless design leverages target system APIs, simplifying deployment and transparency, but limits deep privilege elevation controls on Unix/Linux; baseline CPEDM is addressed through command allow/deny controls.
XTAM organizes target systems and credentials into folders and “records,” supports granular role/user access and approval workflows, logs all access, and integrates with SIEM via syslog. Session features include SSH tooling support, proxy/tunnel options, SSH tunneling for running protocols like SQL with statement recording, and efficient HD RDP/SSH recording. It also proxies HTTP(S) to web portals with credential substitution and records traffic to searchable HAR files. Security includes AD/LDAP integration, MFA, SAML SSO, AES-256 encryption with separate master key storage, and standard database backends; a SaaS option is not yet available.
See All Locations
See All Locations