Privileged Access and Credential Management
Credential Vaulting
Protect privileged credentials. Rotate them with their dependencies in view.
Discover accounts, control their secrets, and carry each credential change through to the services and applications that use it.
Available nowCredential Control Across Your Environment
Privileged Identity Management (PIM) brings credential discovery, custody, rotation, and propagation into one managed lifecycle.
Explore Privileged Identity Management →- Find Accounts and Their Dependencies
- Discover privileged and service accounts, password age, and last sign-in. Identify the services, tasks, and application pools that depend on a credential.
- Reduce Shared-Credential Exposure
- See the hosts and services a shared credential reaches. Rotate and propagate it, or split it into one managed service account per host, with a preview first.
- Keep an Operational Record
- Verify sign-in after the change and retain each step in the audit trail.
Screenshots
A Credential Change, End to End
Preview the change plan before applying it. The workflow accounts for the systems that rely on the credential.
Discover and Map
Identify the account and where its credential is used.
Preview the Plan
Review the target change and dependency updates before execution.
Rotate and Propagate
Stop dependent services, change the credential, update dependencies, and restart in order.
Verify and Record
Test the new credential and retain the results of every step.
Choose Where Encryption Keys Live
Stored secrets are encrypted. Key custody can follow your deployment and security requirements.
Explore Key Management →- Software keys in the platform secret store.
- A hardware security module (HSM) through PKCS#11.
- A customer-owned key in AWS KMS, Azure Key Vault Managed HSM, or Google Cloud KMS.
- Separate key sets for different system groups, with rotation and re-encryption.
Frequently Asked Questions
How Is Credential Vaulting Different from Session Management?
Credential vaulting is part of Privileged Identity Management: discovering, protecting, rotating, and propagating credentials. Privileged Access Management controls the sessions opened with those credentials, including Connect, Jump, and recording.
Can Passwords Rotate on Air-Gapped Systems?
Yes. The AIC Agent can derive and apply scheduled passwords locally from a protected shared seed without reaching AIC Server. It propagates the change to local services and applications and records the action. An authorized administrator can derive the current password when needed.
Can We Manage a Device Without a Built-In Connector?
Yes. Use browser automation for a device with a web management page, a Secure Shell (SSH) or Telnet script for a command-line interface, or the REST API for an application that can call it. Ready-made browser automations are included, and organizations can create their own.