How To Achieve Better Endpoint Management with the Proper Remote Connection Tool
Download resourcesAbout this session
Recorded as a two-hander between a Devolutions host and Maurice Côté, this session is not the Remote Desktop Manager endpoint demo announced on the site but a talk titled 'The gap between identity management and non-federated systems'. Côté defines identity and access management as a framework covering authentication, authorisation, auditing, group and role assignment and provisioning, with the ideal of one corporate identity (Devolutions itself uses Azure AD). The gap is everything that cannot federate: COBOL-era banking systems, network switches, VPNs and firewalls, virtualisation hosts, printers and CNC machines, legacy CRMs and the organisation's shared social media accounts. Those go into a privileged access management vault. He lists privileged account types, notes that Gartner and KuppingerCole count six to nine PAM modules while Devolutions targets small businesses and MSPs with two, and details vault features: gated access, account discovery, rotation, credential brokering that never reveals the password, break-glass access, plus session management through a bastion. Bridging the gap means the PAM authenticates with the IAM identity, derives RBAC from its groups and ships logs to the SIEM.
Endpoint management without a specialized tool can be error-prone and become quite costly due to lost productivity. With the right tool, you can quickly discover endpoints and easily import them from multiple sources. It will also provide you with a rich credential mangement layer to obtain credentials "just-in-time" while automatically injecting them upon launching your chosen remote access protocol. This session will showcase Remote Desktop Manager's versatilitu while also demonstrating the increased gain in productivity without compromising the highest standards in security.
Key takeaways
- Inventory the systems that cannot use your identity provider (network gear, VPN and firewall consoles, hypervisors, legacy apps, shared social accounts); they are the keys to the kingdom.
- Put shared privileged accounts in a PAM vault with gated access, discovery and rotation, and broker sessions so users never see the password.
- Authenticate the PAM with the corporate identity and derive its role-based permissions from IAM group membership rather than assigning rights per user.
- Forward PAM events to the SIEM so the IAM administrator sees who did what, when and how on non-federated systems.
- Route contractors and external consultants through a privileged session management bastion to prevent lateral movement into the subnet.
Speakers

I lead the Privileged Access Management Solution at Devolutions, . Having evolved in startups for the greater part of my career, although I am a developer by trade, I've had to learn infrastructure management and operational security since, well… Read moreRead less
I lead the Privileged Access Management Solution at Devolutions, . Having evolved in startups for the greater part of my career, although I am a developer by trade, I've had to learn infrastructure management and operational security since, well... there was no one else to do it! I work with analysts, customers, and partners alike and have acquired a deep knowledge of the PAM space.

