Privileged Access Management: Vaults, Secrets and Machine Identities
Most PAM programmes secure human administrators and ignore the service accounts, which outnumber them heavily and never change their passwords.
GuardsArm Team
Security Experts
PAM programmes usually begin and end with human administrators — vault the domain admin passwords, enforce check-out, record sessions. That work matters, and it addresses a minority of the privileged credentials in the estate.
The majority are machine identities: service accounts running applications, integration credentials, API keys, certificates, database connection strings. They typically have high privilege, passwords that have never changed, and no owner. The human side is covered in privileged access for clinicians; this is the other half.
Find them first
Service accounts hide because they were created outside normal process:
| Where to look | What you find |
|---|---|
| Directory accounts with non-expiring passwords | The classic service account signature |
| Accounts with a service principal name | Kerberos-authenticated services |
| Scheduled tasks and service definitions | The account each runs as |
| Application configuration files | Connection strings and embedded credentials |
| Source repositories | Committed secrets, including in history |
| CI/CD pipeline variables | Deployment credentials, often highly privileged |
| Certificate stores | Expiry dates nobody tracks |
Repository history is worth emphasising. A secret removed in a later commit is still in the history and still valid unless it was rotated. Scanning only the current tree misses most of them.
The target state
Workload identity is the endpoint worth aiming at. Cloud platforms and Kubernetes can issue short-lived, automatically rotated credentials to a workload based on what it is rather than a stored secret. That removes the category rather than managing it.
Certificates deserve their own tracking
Certificate expiry causes more outages than certificate compromise causes breaches, and in healthcare the outage lands on a clinical integration at an inconvenient hour.
- Inventory every certificate, including internal ones
- Alert well ahead of expiry — 30 days minimum, with escalation
- Automate renewal where possible
- Know who to contact for each externally issued certificate
- Track the ones embedded in appliances and devices, which nobody owns
What to measure
- Privileged credentials under management, as a proportion of those discovered
- Service accounts with a named owner
- Credentials older than the rotation policy
- Secrets found in repositories, trending to zero
- Standing privilege eliminated in favour of just-in-time
- Certificate expiries causing incidents, which should be zero
Emergency access to the vault
A credential vault becomes a single point of failure the moment you depend on it. If the vault is unavailable during an incident — or is itself part of the incident — administrators cannot reach the systems they need to recover.
Plan for it explicitly:
- A break-glass credential set stored outside the vault, physically secured, with tamper-evident packaging
- Two-person control on retrieval, logged
- Tested annually, because a sealed envelope containing an expired password is worse than useless
- Rotated after every use, without exception
- Not dependent on the directory, since the directory may be what failed
This is the same principle as recovery credentials for backups — see immutable backups. The credential you need most is the one you cannot retrieve from the environment that is down.
Where to start
Scan your source repositories — including history — for committed secrets. It takes an afternoon with open tooling, it almost always finds something, and every credential it surfaces is one an attacker could find just as easily.
GuardsArm assesses privileged and machine identity across healthcare estates, including secret sprawl and service account ownership. Book a scoping call.
Written by GuardsArm Team
Our team of cybersecurity experts brings decades of combined experience in penetration testing, compliance auditing, and incident response. We're dedicated to helping organizations strengthen their security posture.
Take the next step on this topic
Talk to the GuardsArm team about how these services apply to your environment.