Managing Passwords is Obsolete, Manage Privilege Instead!
Download resourcesAbout this session
Maurice Côté, VP of Products at Devolutions, argues that both password managers and standard MFA, as designed a decade ago, are now obsolete and that organizations should shift from managing passwords to managing privilege. He traces how attackers defeated MFA push notifications and stole session tokens, and describes how legacy password managers create single points of failure and account-centric rather than asset-centric workflows. He situates privileged access management (PAM) within NIST's zero trust framework, covering its core components: discovering accounts across identity providers, vaulting and rotating credentials, brokering and logging access, and launching sessions without ever revealing passwords to technicians. He contrasts shared, dual (dash-admin) and passwordless account models with ephemeral, just-in-time privileged accounts that exist only for the duration of a task, arguing these best limit lateral movement and token replay risk. He closes on the productivity-versus-security tradeoff, recommending organizations adopt PAM incrementally against their own risk posture and compliance needs (ISO 27001, SOC 2, HIPAA), and takes an audience question on handling MFA-less service account credentials through automated password rotation, propagation and application-to-application password management.
Key takeaways
- Move from account-centric password vaulting toward asset-centric privileged access management so IT staff never have to view or handle plaintext passwords at all.
- Replace standing dash-admin (dual) accounts with ephemeral, just-in-time privileged accounts that are granted only for the duration of a task and disappear afterward, cutting lateral movement and token replay risk.
- For MFA-less service accounts, automate password rotation and propagation into the systems that consume them (application pools, service control manager) rather than leaving static long-lived credentials embedded in scripts.
- Choose a PAM platform based on breadth of identity provider support (Active Directory, Azure AD, Okta, SSH boxes, network equipment) since your asset mix will keep changing.
- Treat PAM adoption as incremental: map your current security posture, your compliance targets (ISO 27001, SOC 2, HIPAA), and choose the next achievable step rather than aiming for a maximal setup immediately.
Speakers

I lead the Privileged Access Management Solution at Devolutions, . Having evolved in startups for the greater part of my career, although I am a developer by trade, I've had to learn infrastructure management and operational security since, well… Read moreRead less
I lead the Privileged Access Management Solution at Devolutions, . Having evolved in startups for the greater part of my career, although I am a developer by trade, I've had to learn infrastructure management and operational security since, well... there was no one else to do it! I work with analysts, customers, and partners alike and have acquired a deep knowledge of the PAM space.

