Privileged Access Management (PAM) is critical because many successful cyberattacks misuse privileged accounts—through shared credential abuse, unauthorized elevation, theft of privileged credentials, and third-party privilege misuse—often enabled by weak PAM tooling, policies, or processes. Risk rises when organizations over-privilege users, fail to enforce policy, or allow standing privilege. Privileged access has expanded from a small admin group managing mostly on-premises systems to organization-wide, workflow- and task-based access across legacy systems, multi-cloud infrastructure, and SaaS, alongside traditional admin tasks. As least privilege and Zero Trust adoption grows, modern PAM platforms are expected to support cloud and SaaS and to fit into highly dynamic “ultra-hybrid” environments. This direction aligns with KuppingerCole’s DREAM paradigm, emphasizing controlled, rapid access to dynamic and ephemeral resources across cloud, on-prem, partner networks, and even mainframes.
Indeed Identity (Lithuanian, founded 2011) has moved from IAM into PAM, reflecting convergence between the two markets. Indeed Privileged Access Manager is currently on-premises only and consists of seven components (Access Server, SSH Proxy, PAM Server, IdP, Connectors, Management Console, User Console). It delivers core PAM features such as vaulting, session recording, and shared account management, with a notably modern UX. Standout features include built-in SSO and 2FA, configurable out-of-the-box policies (SSH command allow/deny, approvals, password reset after sessions, exclusive mode, session duration limits), service desk integration via API/CLI, and improved forensic search for session text/commands. It adds controls like routine discovery of new privileged accounts, credential/SSH key checks, warnings for unmanaged SSH keys, and emergency encrypted “password dump” access, though key admin tasks still require CLI. A new Desktop Console Client enables endpoint users to initiate and manage recorded privileged sessions conveniently. Despite missing capabilities (SaaS, EPM, PUBA, privilege elevation, JIT, DevOps support), it is positioned as a lean, easy-to-deploy option with an adaptive roadmap driven by customer demand.
See All Locations
See All Locations