Historically, privileged access was associated primarily with human administrators responsible for maintaining servers, networks, and enterprise applications. That model no longer reflects how organizations operate today. This webinar draws on a Leadership Compass covering over 35 vendors to examine how PAM adapts to distributed infrastructure, cloud-native systems, and machine-driven activity. It explores how privilege is discovered, governed, and enforced across environments where access is ephemeral, policy-driven, and continuously changing.
Alejandro Leal, Senior Analyst at KuppingerCole Analysts will explore how PAM vendors are addressing NHIs, cloud entitlements, and real-time authorization challenges. They will analyze the convergence of PAM with IGA and CIEM, while highlighting gaps, vendor strategies, and implications for modern security architectures.
Who Should Attend:
This webinar is designed for IT and security professionals responsible for identity, access, and cloud security. It is especially relevant for architects and decision-makers evaluating modern PAM strategies and vendor solutions.
Hello, everyone, and welcome to the webinar, Rethinking Privileged Access. My name is Alejandro Leal. I'm a lead analyst at KuppingerCole. And today we're going to discuss a topic that is, in a way, rapidly moving to the center of enterprise identity security. Privileged Access Management, PAM. For many years, PAM was viewed as, let's say, as a specialized security tool focused on admins, on password vaults, sessions. And I think that view is now incomplete.
Today, privileged actions are increasingly executed not only by humans, but by APIs and workloads, automation pipelines, machine identities, and increasingly AI agents. So organizations are being forced to now rethink not just what, not just who has access, but what can act under what conditions and with which privileges. So I'm trying here to set the stage a little bit, and that's the journey we're going to explore today. Most of the information today was based on the Leadership Compass Report on PAM that I published last month in May. This report covered around 36 vendors in the PAM market.
And we're going to talk a lot about the main findings, the trends, and some of the observations from that report. So I wanted to start with a brief overview I wanted to start with this quote here. I think this single statement, in a way, captures what I believe is the most important shift happening in identity security today. Historically, identity and access management focused on authenticating people.
PAM, in a way, focused on controlling privileged people. But enterprises are becoming machine-driven organizations. So a single human admin today might now oversee thousands of automated processes, cloud services, containers, APIs. So we can then understand that the attack surface is no longer primarily human, but it's autonomous. And with all the noise around AI agents, when an AI agent executes a workflow or accesses sensitive data, triggers infrastructure changes, then this AI agent is effectively exercising privilege, right? So the question becomes, who governs those privileges?
Who monitors them? Who revokes them? And how do we enforce least privilege when decisions occur at machine speed? These are no longer future questions, but they're today's questions. And that's sort of the angle that I'd like to explore today. But before I go deep into the report, I'd like to do some housekeeping, just some reminders for some of you to know that all of you are centrally muted. So you don't need to mute or unmute yourself. We're also going to be conducting two poll questions. So I would like to encourage you to participate on those.
And if you have any questions throughout the webinar, you can enter questions in the panel, and I will answer those at the end. And the recording of the webinar, together with the slides, will be available in the coming days. By looking at the agenda, we're going to first examine why privilege access is expanding beyond traditional PAM. Then we will look at how PAM is evolving by looking at some trends, some market changes. And we'll also be discussing the findings of the leadership compass. I will show you the results, the overall leadership.
And then we'll also try to identify some of the common challenges organizations face. And finally, some practical recommendations for moving forward. So now let's take a look at the poll question. So how mature would you say is your organization's PAM program? I'm going to move forward, but take your time. And I'd be really happy if you could answer those whenever you can. So one of the strongest findings from our leadership compass research is that privilege access is expanding well beyond the traditional boundaries of PAM.
As I said earlier, historically, PAM focused on a relatively narrow problem, which is controlling admin accounts, securing credentials, monitoring privilege sessions. But today, the scope of privileges is larger. Machine identities, APIs, service accounts are all performing actions that can affect critical systems and sensitive data. So in other words, privilege is no longer attached solely to people, but it's attached to actions.
And that's maybe one of the most important takeaways here, because when I started to work on my leadership compass, I had the challenge to define privilege in a way that could encompass all these different vendors. You know, they all have a different background, different approach to doing privilege. So the way I defined it was privilege is defined less by who holds a specific account, and it's defined more by what an identity is capable of doing within an environment. So in a way, from the identity of the identity to more the actions that that identity is allowed to do.
Another thing that we observe is that PAM is also converging with adjacent markets. So we increasingly see overlaps with IGA, with KIM, with ITDR, with secrets management.
In a way, the traditional market boundaries are becoming less relevant as customers seek integrated approaches to identity security. And this is also reshaping the vendor landscape. Over the past couple years, we've seen some acquisitions, platform strategies, market consolidation. They're all transforming PAM from a standalone product category into a more broad security control plane. Many vendors are expanding horizontally, while others are incorporating PAM capabilities into larger identity security platforms. So when we look at PAM today, we're really looking at a market in transition.
And that brings us to the key takeaway here. Organizations should stop viewing PAM as simply an admin security tool. It should be treated as a strategic business control layer. And you ask why? Because privileged actions are ultimately the actions that can change systems, move data, alter configurations, approve transactions, or impact business operations. So whether those actions are performed by a human admin, or by a machine, or an AI agent, whatever you want to call it, that's becoming less important than ensuring that those actions are properly governed.
So the future of PAM is therefore not about managing privileged accounts, but about managing privileged actions across the enterprise. And this evolution can be understood as, let's say, four distinct eras when we look at how PAM has changed. First came traditional PAM, focused more on the human admin experience, right? In the next slide, I will show you some of the capabilities that were expected from the past, capabilities that are expected today, and those that are shaping tomorrow. But on this slide, we see the transition moving to cloud and automation.
So organizations began creating service accounts and APIs at scale. Next came the machine identity era. So now workloads, containers, cloud services, and automation systems, they vastly outnumber human users in many organizations.
And today, we're in a sort of like entering a new era. And this era is sort of the autonomous era, where AI agents increasingly receive delegated authority. They will request information, execute workflows, trigger business processes, and potentially even make decisions. So the challenge is that governance models designed for human users do not scale to this reality. So PAM must evolve. And that's why this picture, this slide here, is trying to emphasize that evolution based on the needs and requirements that, let's say, privilege entails, right?
And if we look at the next slide, then we can understand this by looking at those capabilities that historically were in demand. So organizations back then expected vaulting, password rotation, session recording, share account management. Those features still matter. They're still important. Organizations still ask for them. But the reality is that things are a little bit more complicated now. Because organizations increasingly expect just-in-time access, secrets management, Kim, machine identity security, discovery and visibility.
And when we look ahead, the features that are expected in the future, these are some of the trends that we observed when talking to vendors. And it doesn't mean that these are already operating and vendors are already providing these. But they were part of the conversation, part of the roadmap, or also based on some of the smaller, highly innovative companies that we cover in the report. You will see the vendor list in a few slides. But there are some vendors that are very, very niche, focusing on NHIs and focusing on agentic AI.
So in a way, some of these new, innovative PAM vendors, they may not do vaulting. They may not do session management and recording. But they're now focusing on governing AI agents, for example. So what we see in the market is still vendors that focus on the traditional PAM. And they're still evolving and they're still incorporating new solutions for the modern use cases. But we also see new vendors, new entrants that are just aiming to address the modern PAM use cases, rather than also offering some of the traditional PAM features.
If you look at the future, the future of PAM is continuous, is contextual, and dynamic. And we'll talk more about that later. This evolution of PAM also explains why we are discussing PAM within the context of the Identity Fabric. The Identity Fabric is, as some of you may know already, it's not a product. It's not based on just one technology, but it's an architectural model. Its purpose is to bring together identity services, governance, authentication, authorization, analytics, into a unified framework. And if you pay attention here, notice something important. PAM is no longer isolated.
Here on the right side, it sits alongside IGA, Access Management, KIM, ITDR, and the rest. And why?
Well, because privileged decisions increasingly depend on information from across the entire identity ecosystem. So effective privileged governance requires context. And context comes from integration. So that's why when we talk about PAM, we always want to keep it with this Identity Fabric approach. Because many organizations out there, they operate in silos. They have different tools for different issues, but they do not communicate with each other. They don't work together. They don't have a unified view of identity. Now we can talk about the leadership purpose.
And just very briefly, I'll tell you a little bit about how we conduct research here. But first, we identify a market segment, in this case, PAM. So we engage vendors directly. We send them a questionnaire and an invitation to participate. And if their solution aligns with what we are looking for, then they decide to participate. We have briefings with the vendors. And after some time, then we analyze the capabilities independently. We write the analysis. And then we perform fact check. And then we publish the report. That's in a nutshell, very quickly.
But the whole process takes between three to four months. It really depends on the topic. So these are the companies that participated in this leadership compass. 36 in total. And you can see a diverse group of vendors here. And I think that diversity tells an interesting story. We see the usual suspects, the traditional PAM leaders. But we also see some cloud-native innovators. We see identity-centric vendors. Some other vendors that have a secret management background.
But we also see some new entrants, the ones that I was mentioning, that are focusing on machine identities and modern architectures. So in a way, the PAM market is no longer homogeneous. Different vendors increasingly emphasize different visions of privilege access. Some remain, again, as I mentioned in the previous slide, remain centered on admin accounts, on the traditional set of capabilities. But others are moving more aggressively toward identity security platforms. Other position their solution around machine identity and agentic AI readiness and governance.
So I've done so far in my five years at Coupangracle more than 10 leadership compasses. But this was the most diverse in terms of geographical presence of the vendors. We had vendors from South America, from China, from Southeast Asia, from Europe, from North America, from the Middle East. So it's quite interesting. And I think that organizations interested in PAM, they need to evaluate solutions that really meet their criteria and their own requirements. But yeah. So these are the results of the leadership compass on PAM.
As I said, the report was published in May of last year. So here on the right side, we see the product leaders. On the left side, the innovation leaders. And then here on the top right corner, we see the overall leaders. The size of the bubble indicates that they're a market leader. So we see the big players with big bubbles. But we also see some well-known vendors in the identity space that, let's say, are not leaders, but they are making strategic movements. They've made recent acquisitions in the PAM space. And they're also looking at incorporating more features on the roadmap.
We see some vendors that just focus on the SMB market, something that I talked about at my EIC session in Berlin last month. I talked about how for many small-medium enterprises, especially here in Europe, the European economy largely depends on small-medium enterprises. And for many of them, they don't really need all this noise around agentic AI and machine identities, etc. Many of them just need the basics. They need password rotation. They need session recording. Many of them have small teams, and they just need the basics. They need a foundation.
So that's why in the report, I really tried to highlight that it's important to have that balance. They are the old, traditional PAM vendors, but have made acquisitions. They have incorporated new features that are more aimed to addressing modern use cases. But there are still some vendors that just focus on the modern use cases, as I said. So it's an interesting mix of players.
Here, some of you may be familiar with our research, with our leadership compasses. And if you had the chance to look at one of them, you see that each chapter, each vendor has a spatter graph that illustrates how we evaluate the capabilities, the capabilities in this case for PAM listed here on the left side. So rather than focusing on a single score, we examine multiple dimensions, for example, security, deployment, interoperability, stability, just-in-time access, etc., etc.
And having this spatter graph is important because, as I mentioned, again, PAM success depends on balance, a solution that may excel in bolting but struggles with cloud-native environments. Another solution may excel in machine identities but lacks governance depth and visibility. So the shape of the spatter often tells a richer story than the score itself. Here's just a list of the percentage of vendors, percentage of solutions that support each of these capabilities. Several capabilities have become almost universal. So just-in-time access is now expected.
Credential management remains foundational. Identity discovery has become increasingly important, as well as machine identity support. At the same time, some advanced capabilities remain unevenly implemented, like support for OT, ICS, and KIEM, Cloud Infrastructure Entitlement Management. Some of the vendors, not all of them, address this.
So, yeah, there's still some gaps in certain areas. Another observation from our research is the increasing dualization of the PAM market. So strong vendor presence across North America, Europe, APAC, and Latin America. Deployment models are equally diverse. Organizations can choose traditional on-prem deployments, SaaS offerings, managed services, hybrid architectures. And the important point is that deployment flexibility has become a competitive requirement.
A lot of European organizations are now looking at hybrid deployments, traditional on-prem deployments, if they belong to highly regulated industries, for example. So I think customers increasingly expect solutions that fit their architecture, but they also provide some flexibility.
So, challenges. So when talking to vendors, one of my main goals was to understand how they're trying to solve their customers' challenges.
Because, you know, a lot of people are talking about AI, you go to an identity conference, there's a lot of hype around it, there's a lot of marketing around it. So when I talk to vendors, I really want to understand the real needs that their customers are facing. What are they asking? What do they demand? And what are you doing to help them? So despite significant progress, and despite the trends and innovation that we see, a lot of end-user organizations still struggle in several areas. The first is reliance on static credentials.
It's not a new problem, but many environments still depend heavily on long-lived privileges. So many organizations don't know their privileges, they don't know what's going on, right? That's why visibility and discovery are important aspects that were mentioned before. Second is machine identity governance. Organizations often know how to manage people, but they frequently lack the visibility into workloads, APIs, and automated systems. The third is contextual enforcement. So most access decisions remain binary and static.
Future environments will require dynamic, real-time, risk-aware decisions. And finally, many organizations still operate fragmented architectures. Privilege controls remain disconnected from broader identity security initiatives, and that's why I mentioned the Identity Fabric approach. So what are some of the recommendations? If you're starting your PAM journey, or you're just trying to learn more about the latest developments, well, here are five recommendations.
First, adopt an Identity Fabric mindset. Privilege management should not operate in isolation.
Second, it's important to move from static privilege toward dynamic privilege. Just-in-time access should become the default model, and as it was shown in one of the slides, almost all vendors provide that.
Third, treat machine identities and AI agents as first-class citizens. You need to govern them with the same rigor applied to human users, but it's also important to remember that it doesn't matter if we're talking about human or non-human identities. What truly matters in the end is what are the actions that these identities are allowed to do.
Fourth, enforce least privilege continuously, not annually, not quarterly, but continuously. And finally, design for the future. Things are moving fast, things are changing. That means hybrid environments, cloud environments, machine-driven environments, and increasingly autonomous environments. So the key takeaway is simple. The future of PAM is not account management. The future of PAM is governing privilege actions across all identities, human, machine, autonomous, all identities.
Organizations that make this transition early will be better positioned for the next decades of identity security. And with that, thank you so much for joining. I'm going to go to some other slides.
Oh, okay. Here's our second poll question. What is your organization's biggest challenge in managing privilege access today? Here we have some related research where you can also take a look at all of our topics. I see that we have already some questions, so I will go through those in a second. Just be aware that we're going to be having some Impact Day events this year. The next one is in Cologne, Germany, where we're going to talk more about the identity fabric. I'll probably attend this event in Munich in October, non-human identity.
We're going to talk about the latest developments there and how you can start your journey there when it comes to non-human identity management. And that's my contacts. If you have any questions or any comments or anything like that, feel free to reach out to me. I know we have some questions here.
Okay, so the first question, how do you see PAM adoption evolving in the SMB and mid-market segment? That's something I talked about in one of the slides. I was surprised to some extent at how many vendors do not really focus on the SMB market. What I realized is that some vendors are only targeting the SMB market. And these vendors are trying to facilitate the deployment for these companies, but also give them a lean IT, you could say. So not very complex environments, not very complex tooling, but an easy way for them to start from scratch and to scale as they grow.
So I still expect PAM to be important for SMBs, of course, but I think ultimately depends on which PAM solution is going to be better for you. That also ties with some of the trends that we see here in Europe around digital sovereignty. So a lot of European organizations are trying to see if there are any European alternatives to PAM that can match some of the leading PAM vendors in terms of execution, interoperability, and the amount of capabilities and use cases it can cover. So there are a lot of things in the SMB and slash European market that are, I think, interesting to keep exploring.
Which market trend do you believe will have the greatest impact on PAM over the next five years? Well, nobody will be surprised to hear that I think AI, I think AI is really having an impact. We saw today that a large vendor acquired one of the vendors that appear here, Apono. So he has been acquired by a large vendor. So I still expect to see movement in the market, to see vendors making strategic acquisitions. And as I mentioned in the first slide, there's some convergence happening with IGA, with secrets management, with ITDR.
So it's going to be interesting to see how things are going to look like in the coming years. And right on time, I'm just going to take a look at the poll questions just to see if there's anything interesting, and then we can wrap it up.
Okay, so the first question was, how mature is your PAMS program? And according to the results, around sort of splitting in two camps, around half of the attendants are just starting to define their PAMS strategy, and some of them have basic vaulting and password rotation in place, while the other half already has just-in-time access, and they've integrated PAMS with IGA and endpoint control. So it's sort of like half and half, which is not surprising.
Okay, what is your organization's biggest challenge in managing privilege access today? According to the polls, for most people, it's securing human and non-human privilege. Which is a fair, fair statement, because in many organizations, there are more non-human identities than human ones. The second one is lack of visibility. So those two problems are in a way related, right? If you don't have visibility into privilege accounts, then, well, that's a problem.
Well, I think that's all from my side. I really appreciate you attending today, and if you have any questions, or would like to talk more about the PAMS market, feel free to check out our latest research. The report is published, it's online, and if you have any questions, just reach out to me. Thank you very much, and goodbye.
See All Locations
See All Locations