Join our Newsletter — 33% off our NHI Course

Zero standing privileges and vaulting: are your controls keeping up?

 

(@nhi-mgmt-group)
Member Moderator
Joined: 1 year ago
Posts: 20739
Topic starter  

TL;DR: Teleport’s analysis finds that credential vaults still preserve stored, reusable secrets, so they can reduce risk without eliminating standing privilege, according to cited CISA findings. Zero standing privileges depends on ephemeral, identity-bound access, not rotated credentials hidden behind a vault.

Editorial analysis by NHI Mgmt Group, based on content published by Teleport: “Zero Standing Privileges vs Credential Vaulting”.

By the numbers:

  • Valid privileged accounts were responsible for 41% of successful attacks, according to CISA’s FY23 Risk & Vulnerability Assessments report cited by Teleport.

Key questions

Q: What breaks when privileged access is controlled only by a vault?

A: A vault controls where the credential sits, but not what happens after the credential is released.

Q: Why do password vaults create more risk than PAM in organisations with sensitive infrastructure?

A: Password vaults reduce storage friction, but they do not provide the fine grained authorization, discovery, or oversight needed for privileged access.

Q: How do teams know whether zero standing privilege is actually working?

A: Teams should look for evidence that privileged access is time-bound, fully revoked, and impossible to reuse outside the approved session.

Practitioner guidance

  • Reclassify vaults as secret stores, not ZSP controls Document which privileged paths still depend on check-out, reuse, or delayed revocation.
  • Replace checkout-based admin access with JIT issuance Issue short-lived credentials tied to the requesting identity and task, then let them expire automatically.
  • Map privileged service accounts behind the vault Inventory the accounts, policies, and automation paths that make the vault work.

Bottom line: Credential vaulting can reduce exposure, but it does not by itself remove standing privilege from PAM.

What's in the full article

Teleport's full blog post covers the operational detail this post intentionally leaves for the source:

  • The comparison table that contrasts vault-based PAM with vault-free just-in-time access
  • The discussion of how vault workflows can preserve standing privilege even when secrets are rotated
  • The implementation notes on short-lived certificates, task-bound access, and auditability
  • The article’s discussion of AI and MCP workflows, where identity traceability becomes harder to recover from a vault model

👉 Read Teleport's analysis of zero standing privileges vs credential vaulting →

Explore further

View Full Forum →  |  NHI Foundation Course →  |  Our Services →  |  Read the full analysis →


This topic was modified 16 hours ago by NHI Mgmt Group

   
Quote
(@mr-nhi)
Member Moderator
Joined: 5 months ago
Posts: 20967
 

Vaulting controls secrets, not standing privilege: A credential vault can reduce exposure, but it still assumes a durable secret exists and can be checked out, reused, or rotated. That assumption is sufficient for legacy PAM, but it does not satisfy zero standing privilege, which requires that privilege not persist between tasks. The practical conclusion is that vaulting and ZSP solve related but different governance problems.

A few things that frame the scale:

  • 91% of organisations say at least half of their privileged access is always-on, and only 1% have fully implemented just-in-time privileged access, according to a CyberArk study.

A question worth separating out:

Q: What is the difference between vaulting privileged credentials and using just-in-time access?

A: Vaulting protects privileged credentials by storing them securely and rotating them on a schedule or after use. Just-in-time access goes further by granting elevation only for a specific task and time window, then revoking it automatically. Vaulting reduces exposure, while just-in-time access removes standing privilege and narrows the attack window.

👉 Read our full editorial: Zero standing privileges vs credential vaulting in modern PAM


This post was modified 16 hours ago by NHI Mgmt Group

   
ReplyQuote
Share:

Free weekly newsletter

Subscribe to the NHI & AI Identity Journal

The latest on NHI and Agentic AI security – articles, research, breaches, news and events every week.

Bonus 33% off our NHI Course when you subscribe.