<link rel="stylesheet" href="https://fonts.googleapis.com/css2?family=Plus+Jakarta+Sans:wght@500;600;700;800&family=Inter:wght@400;500;600&display=swap">

ARCON | PAM Suite

Seamlessly navigating complex privileged access use cases

A full-blown solution with a scalable architecture, covering the core capabilities an organisation needs to reach a PAM maturity model.

Cybersecurity solutions
  • MFA & SSO
  • Credential vaulting
  • Session recording
Privileged access brokered through the PAM core Users and devices on the left authenticate through multi-factor authentication, single sign-on and Active Directory. The verified identity reaches the PAM core, where the credential vault, session manager, access-request workflow and policy engine broker privileged sessions out to Windows and Linux servers, databases, network devices, applications and cloud platforms on the right, while every action drains down into the SIEM, audit-log and alerting tier. USERS & DEVICESIT adminThird-party vendorInternal usersDevicesMulti-factorauth (MFA)Single sign-on(SSO)ActiveDirectoryPAM CORECredential VaultSession Manager?Access RequestsPolicy Engine LOGGING & MONITORING SIEM integrationAudit logsAlerts & reportsTARGET SYSTEMSWindows ServerLinux ServerDatabaseNetwork DevicesApplicationsCloud PlatformAuthenticationPrivileged sessionAudit trail

Privileged identity security

Impregnable privileged identity security, built to scale

Everything a PAM maturity model asks for

ARCON | PAM offers the range of core features and functionality required to attain a PAM maturity model. A full-blown solution with scalable architecture ensures impregnable privileged identity security.

Banking organisations, government agencies and healthcare chains, among many other vertical markets, trust ARCON | PAM for building a robust IAM and compliance framework.

  • Every privileged ID discovered across a heterogeneous estate
  • Least privilege granted by role, responsibility and task
  • Recorded, auditable privileged sessions
Visit arconnet.com

Core capabilities

Six controls that cover the privileged access lifecycle

Discovery and onboarding

Onboard users from Microsoft AD, AWS, Azure and GCP, and add new server groups and privileged accounts to a single PAM instance. Auto discovery finds every privileged ID and device, so orphaned accounts spread across a heterogeneous IT environment stop being a blind spot.

Multifactor authentication

Reinforce security and enforce zero-trust principles with MFA. Built-in dual-factor authentication is joined by integration with Google Authenticator, Microsoft Authenticator, ARCON Authentication, hardware tokens, facial recognition, biometrics and traditional SMS or email OTP.

Single sign-on

One-time secure administrative access to web, on-premise legacy and cloud applications without managing multiple sets of credentials. ARCON SSO supports the standard protocols: OAuth 2.0, OpenID Connect (OIDC) and SAML.

Access control

Grant access on a need-to-know and need-to-do basis. Privileged users are managed by role, responsibility and task, enforcing least privilege and reducing the risk of unauthorised access to sensitive systems and data.

Credential management

Manage and protect the credentials, SSH keys and secrets used to reach privileged accounts, with vaulting, randomisation and controlled retrieval for interactive access to target systems.

Session management

Monitor, terminate and record privileged sessions. Real-time threat detection and response protect critical sessions, with audit trails for every command fired and file accessed.

PAM maturity model

Six moves towards controlled privileged access

  1. Discover

    Find every privileged ID

    Auto discovery locates privileged IDs and devices across AD, AWS, Azure and GCP, so nothing is left orphaned.

  2. Onboard

    Bring accounts into one instance

    Server groups and user accounts with privileges are onboarded into a single PAM instance.

  3. Authenticate

    Enforce MFA at the gate

    Dual-factor authentication and third-party MFA tools apply zero-trust principles before a session opens.

  4. Authorise

    Grant least privilege only

    Access is granted by role, responsibility and task on a need-to-know and need-to-do basis.

  5. Vault

    Protect credentials and keys

    Credentials, SSH keys and secrets are vaulted, randomised and retrieved under control.

  6. Audit

    Record and review sessions

    Sessions are monitored, recorded and terminated where needed, with audit trails of commands and files.

Implementation detail

What auditors and admins ask about PAM

PAM solution

Find out how many privileged accounts you really have

We will run a discovery exercise across your directories, servers and cloud accounts and show you what is unmanaged today.

Cybersecurity solutions