This session is for members.

Subscribe or log in to watch every GoSec session.

Subscribe Log in

This recording is not available yet.

Managing Passwords is Obsolete, Manage Privilege Instead!

Download resources

About this session

Maurice Côté, VP of Products at Devolutions, argues that both password managers and standard MFA, as designed a decade ago, are now obsolete and that organizations should shift from managing passwords to managing privilege. He traces how attackers defeated MFA push notifications and stole session tokens, and describes how legacy password managers create single points of failure and account-centric rather than asset-centric workflows. He situates privileged access management (PAM) within NIST's zero trust framework, covering its core components: discovering accounts across identity providers, vaulting and rotating credentials, brokering and logging access, and launching sessions without ever revealing passwords to technicians. He contrasts shared, dual (dash-admin) and passwordless account models with ephemeral, just-in-time privileged accounts that exist only for the duration of a task, arguing these best limit lateral movement and token replay risk. He closes on the productivity-versus-security tradeoff, recommending organizations adopt PAM incrementally against their own risk posture and compliance needs (ISO 27001, SOC 2, HIPAA), and takes an audience question on handling MFA-less service account credentials through automated password rotation, propagation and application-to-application password management.

Key takeaways

  • Move from account-centric password vaulting toward asset-centric privileged access management so IT staff never have to view or handle plaintext passwords at all.
  • Replace standing dash-admin (dual) accounts with ephemeral, just-in-time privileged accounts that are granted only for the duration of a task and disappear afterward, cutting lateral movement and token replay risk.
  • For MFA-less service accounts, automate password rotation and propagation into the systems that consume them (application pools, service control manager) rather than leaving static long-lived credentials embedded in scripts.
  • Choose a PAM platform based on breadth of identity provider support (Active Directory, Azure AD, Okta, SSH boxes, network equipment) since your asset mix will keep changing.
  • Treat PAM adoption as incremental: map your current security posture, your compliance targets (ISO 27001, SOC 2, HIPAA), and choose the next achievable step rather than aiming for a maximal setup immediately.

Speakers

Maurice Côté
Maurice Côté
Vice-President of Products · Devolutions
I lead the Privileged Access Management Solution at Devolutions, . Having evolved in startups for the greater part of my career, although I am a developer by trade, I've had to learn infrastructure management and operational security since, well… Read moreRead less

I lead the Privileged Access Management Solution at Devolutions, . Having evolved in startups for the greater part of my career, although I am a developer by trade, I've had to learn infrastructure management and operational security since, well... there was no one else to do it! I work with analysts, customers, and partners alike and have acquired a deep knowledge of the PAM space.

Resources

Tags

More from GoSec 2023

Also from Maurice Côté

On the same topic

This site is registered on wpml.org as a development site. Switch to a production site key to remove this banner.