What you are evaluating
This profile covers privileged access in the CyberArk portfolio under Palo Alto Networks. Machine and agent identity products require separate scoping; do not assume one console or subscription covers the entire portfolio.
A useful evaluation context
A hybrid estate can evaluate vaulting, time-limited privileged access and session evidence for administrators and vendors.
Documented capabilities
The vendor describes these capabilities in the linked sources. Availability depends on the product edition and supported environment.
- Credential vaulting and just-in-time access reduce standing administrator passwords on hybrid and operational-technology-adjacent targets.
- Session isolation and recording broker privileged human and vendor access instead of shared remote-desktop logins.
- Adjacent machine and agent identity offerings should be mapped separately to the modules and integrations included in a proposal.
Where it fits in the work
- Inventory privileged humans, vendors, and secrets in a lab, including one jump host that represents operational-technology or server administration.
- Onboard a synthetic administrator into the vault, check out a password or just-in-time role, and open a recorded session to the lab target.
- Rotate the test credential, test configured session termination, and export the audit evidence; record any residual access rather than assuming revocation is universal.
APPLY THE IDEA / ILLUSTRATIVE EXERCISE
Make the outcome observable.
Vault a synthetic administrator credential for a lab target, perform a recorded session, then rotate the credential and test the configured access-revocation controls.
Evidence to look for
The old credential fails after verified rotation, new access follows the revoked policy, and the operator records whether an existing session ends or retains access.
Use synthetic data and an authorized test environment. Agree the scope and recovery steps before enabling enforcement.
Questions for your evaluation
- Which Idira or CyberArk product, console and subscription provide each requested capability?
- Which targets in your lab actually support session isolation and recording, versus password checkout only?
- How are machine and agent secrets onboarded without assuming every CyberArk and Palo Alto Networks product already shares a directory?
Names you may encounter: CyberArk Privileged Access Management · CyberArk PAM. Historical names do not establish current availability or feature equivalence.