By NHI Mgmt Group Editorial TeamBased on StrongDM: “CyberArk Privileged Access Management: 5 Critical Questions to Ask” (October 24, 2025)

TL;DR: Legacy PAM can add complexity, cost, fragmented workflows, and weak JIT adoption in modern hybrid environments, making access harder to govern rather than easier, according to StrongDM. For IAM and NHI teams, the real issue is not feature count but whether access controls can keep pace with cloud-era operational demands.


At a glance

What this is: This is a critique of legacy PAM architecture, arguing that CyberArk-style deployments can add operational complexity, fragment workflows, and slow just-in-time access adoption.

Why it matters: It matters because IAM, PAM, and NHI programmes fail when access controls are harder to operate than the environments they are meant to govern.


Context

Modern privileged access management often breaks down when the control model is heavier than the environment it serves. In hybrid cloud and developer-heavy estates, access governance has to support frequent change, short-lived access, and multiple resource types without turning every request into an operations project.

This article argues that legacy PAM can add tooling friction, licensing overhead, and fragmented workflows that slow adoption of just-in-time access. The identity governance problem is not simply whether privileged access exists, but whether the control plane can keep pace with modern operating rhythms.

The result is a governance gap rather than a feature gap: teams may own more tools, yet secure access less effectively. That makes the article relevant to PAM, IAM, and NHI practitioners who need access control that scales with operational reality.


Key questions

Q: What breaks when legacy PAM adds too much operational friction?

A: When PAM adds too much friction, teams work around it with manual approvals, shared access paths, or persistent permissions. The result is weaker governance, slower delivery, and less reliable audit evidence. A control that people avoid at scale does not remove risk, even if it looks strong in policy documentation.

Q: Why do fragmented PAM workflows increase access risk?

A: Fragmented workflows split entitlement data, session evidence, and approval records across tools, which makes it hard to know who has access and for how long. That fragmentation increases the chance that standing privilege survives unnoticed and that reviews miss critical exceptions.

Q: How do security teams know if just-in-time access is actually working?

A: Look for short-lived sessions, automatic revocation, and complete request-to-access logs. If approvals are still creating durable permissions, or if teardown depends on manual cleanup, then the programme is only partially ephemeral. Effective JIT should leave little or no reusable privilege behind after the task ends.

Q: Should organisations prioritise simplifying PAM before adding more features?

A: Yes, when the current control plane is slowing adoption, driving exceptions, or increasing tool sprawl. A simpler access model is often more effective than a larger feature set because it improves consistent use, which is what turns policy into actual governance.


Technical breakdown

Why legacy PAM creates governance drag

Legacy PAM platforms often assume access is rare, centrally brokered, and tied to a few stable systems. In modern hybrid estates, that model produces more workflow steps, more exceptions, and more administrative overhead than the access path itself should require. When engineers need cloud, SaaS, on-prem, and database access through different controls, the governance layer becomes a bottleneck. The practical issue is not just user frustration. Operational drag encourages workarounds, and workarounds weaken the policy model that PAM is supposed to enforce.

Practical implication: measure whether your PAM workflow increases request friction enough to create unmanaged access paths.

Just-in-time access only reduces risk when it is usable

Just-in-time access is a governance pattern, not a feature toggle. It depends on rapid issuance, reliable revocation, and a consistent request experience across environments. If JIT is fragmented or difficult to operate, teams preserve standing privilege because it is easier than using the control. That leaves the security model intact on paper but ineffective in practice. In identity terms, the control fails when the operating burden pushes people back toward persistent permissions and broad entitlements.

Practical implication: test whether your JIT process actually displaces standing privilege across every target environment.

Why fragmented access stacks widen the attack surface

Fragmented PAM architectures split policy, telemetry, and administration across multiple tools, which makes it harder to see who has what access, where, and for how long. That fragmentation also complicates recertification and exception handling because each system becomes a partial source of truth. For NHI and privileged access programmes, the core problem is lifecycle inconsistency: access is granted and governed in different places, so the audit trail is incomplete. Once governance is fragmented, the attack surface expands through both privilege sprawl and operational blind spots.

Practical implication: consolidate access governance data before you trust any single report on privilege exposure.


Threat narrative

Attacker objective: Exploit overly persistent or poorly governed privileged access to reach systems that should only be available on demand.

  1. Entry occurs through legitimate privileged access pathways that are already too broad or too hard to govern tightly.
  2. Escalation happens when fragmented workflows or weak JIT adoption leave standing access in place longer than intended.
  3. Impact is broader unauthorised access exposure, because the control model cannot keep pace with modern operational demands.
  • BeyondTrust breach 2024: A stolen BeyondTrust Remote Support API key let a China state-sponsored actor reset accounts and reach US Treasury workstations in 2024.

Read and download The State of NHI & AI Agent Breach Report 2026, covering 150+ breaches impacting Non-Human Identities including AI Agents.


NHI Mgmt Group analysis

Legacy PAM becomes a governance tax when the access model no longer matches the estate. CyberArk-style complexity is not just an implementation nuisance. It changes how often teams bypass controls, how consistently they adopt JIT, and how much confidence they can place in recertification outcomes. The practitioner conclusion is straightforward: if access governance slows the business more than it secures it, the programme is already operating below its intended control value.

Just-in-time access fails as a policy when it is treated as a separate product capability instead of an operating pattern. JIT only works when issuance, approval, session start, and revocation feel natural across environments. If the path is inconsistent, standing privilege survives by default. The practical conclusion is that JIT effectiveness should be judged by whether it displaces persistent entitlement at scale, not by whether the feature exists in the stack.

Access fragmentation is an identity governance failure, not merely an architecture inconvenience. When cloud, SaaS, on-prem, and hybrid access are governed through different workflows, the organisation loses a coherent view of privilege lifecycle and exception management. That weakens PAM, IGA, and audit readiness at the same time. The practitioner conclusion is to treat fragmentation as a control defect because it breaks the chain from entitlement to accountability.

Privileged access maturity now depends on control usability as much as control design. A mature PAM programme must reduce the cost of doing the right thing for admins, engineers, and security teams. If the control plane creates license pressure, operational drag, or poor adoption, the organisation ends up preserving risk to avoid friction. The practitioner conclusion is that modern access governance should be evaluated on adoption, consistency, and revocation reliability, not on feature count.

From our research library:

What this signals

Control usability is now an access-governance requirement, not a nice-to-have. If privileged access is difficult to request, approve, or revoke, engineers and admins will route around it. That turns PAM into documentation for the control rather than the control itself.

JIT adoption is the clearest test of whether PAM fits the operating model. Organisations should watch whether just-in-time access displaces standing privilege in cloud, SaaS, and on-prem systems, or whether it remains a narrow feature used only in low-friction cases. The latter is a sign that governance and practice are misaligned.


For practitioners

  • Assess PAM workflow friction Map every privileged access request path from request to revocation and identify where users switch to manual or persistent access because the control is too cumbersome.
  • Validate JIT displacement of standing access Sample cloud, SaaS, on-prem, and database access to confirm that just-in-time permissions are actually replacing persistent privilege rather than sitting beside it.
  • Consolidate privilege inventory and governance data Unify entitlement records, approval history, and session evidence so recertification and exception handling are based on one coherent view of access.
  • Recheck access coverage across hybrid estates Compare the systems protected by your PAM programme against the systems engineers actually touch, including databases, clusters, and developer-facing platforms.
  • Review licence and adoption trade-offs Identify features that are paid for but underused, then determine whether the operational model or the user experience is the reason adoption stalls.

Key takeaways

  • Legacy PAM can become a governance burden when the access model no longer matches how modern environments are actually run.
  • The key risk is not only cost or complexity, but the persistence of standing access and fragmented lifecycle control.
  • Teams should evaluate PAM by adoption, revocation reliability, and workflow consistency rather than by feature count.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

OWASP Non-Human Identity Top 10 addresses the attack and risk surface, while NIST SP 800-53 Rev 5, NIST CSF 2.0 and CIS Controls v8 set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
OWASP Non-Human Identity Top 10NHI-05 — Overprivileged NHIThe article centers on excessive privilege and access paths that are broader than needed.
NHI-07 — Long-Lived SecretsStanding access and delayed JIT adoption keep privilege alive longer than governance intends.
Recommendation — Reduce overprivileged access by aligning entitlement scope with actual operational need. Shorten the lifetime of privileged credentials and replace persistent access with time-limited issuance.
NIST SP 800-53 Rev 5AC-6 — Least PrivilegeThe article argues that access should be narrower and less persistent than legacy PAM allows.
Recommendation — Enforce least privilege by limiting privileged entitlements to the minimum operational scope.
NIST CSF 2.0PR.AA-05 — Access Permissions, Entitlements and AuthorizationsThe core issue is whether permissions and authorisations can be governed coherently across modern estates.
Recommendation — Review access permissions continuously so entitlement drift does not outpace governance.
CIS Controls v8CIS-5 — Account ManagementThe article is fundamentally about managing privileged accounts, licences, and operational access paths.
Recommendation — Centralise account management so privileged access remains visible, limited, and revocable.

Key terms

  • Just-in-Time Access Request: Just-in-Time Access Request is a pattern that grants access only when it is needed and only for the duration required. It reduces standing privilege by making access temporary, policy driven, and task scoped. This approach is especially useful for contractors, sensitive systems, and short-lived operational work.
  • Standing Privilege: Standing privilege is access that remains active even when no immediate task requires it. For NHI programmes, it is a common failure mode because long-lived credentials and persistent roles create unnecessary exposure. Reducing standing privilege usually means tighter expiry, on-demand access, and clearer review of who or what still needs access.
  • Privilege Narrative Fragmentation: The condition where no single system can explain privileged access across an enterprise. In multi-cloud estates, approvals, activations, session actions, and expiry live in separate tools, so auditors and defenders must reconstruct the story instead of reading it from one control plane.
  • PAM Governance: PAM governance is the set of rules, operating models, and review processes used to control privileged access across systems and teams. It is effective only when the control experience is usable enough that administrators and engineers actually follow it in day-to-day operations.

Deepen your knowledge

NHI governance, agentic AI identity, and machine identity lifecycle are core topics in our NHI Foundation Level course, the industry's only accredited NHI security programme. If you are building or maturing an IAM programme, it is worth exploring.
NHIMG Editorial Note
Published by the NHIMG editorial team on June 7, 2026.
Updated on October 7, 2026.
NHI Mgmt Group, the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org