TL;DR: Forrester’s Q3 2025 PIM evaluation highlights privilege governance, credential and secrets management, and session controls as the criteria shaping modern identity security decisions, according to Delinea’s summary of the report. The broader lesson is that privilege management is now a lifecycle and detection problem, not just an elevation-control problem.
Editorial analysis by NHI Mgmt Group, based on content published by Delinea: “Delinea Named a Leader in Q3 2025 Privileged Identity Management Solutions Report by Independent Research Firm”.
Practitioner guidance
- Map privileged identities across humans and machines Build a single inventory of privileged human users, service accounts, developer access, and machine identities so entitlement ownership is not split across teams.
- Tie secrets management to privilege lifecycle Require every reusable secret to have an owner, expiry expectation, and revocation path that aligns with the access it enables.
- Add session recording to privileged workflows Capture and review privileged sessions where the action itself matters, especially for administrative changes, cloud entitlement edits, and machine-assisted access.
Bottom line: Privilege governance is no longer just about who can elevate into an account. It now spans credentials, sessions, cloud entitlements, and runtime detection.
Explore further
View Full Forum → | NHI Foundation Course → | Our Services → | Read the full analysis →
Privilege identity management is converging with NHI governance, not remaining a human-admin discipline. The evaluation criteria highlighted in the article, especially credential and secrets management, cloud entitlements, and identity threat detection, show that privileged access is now a cross-actor control problem. Human administrators and machine identities increasingly share the same privilege patterns, so governance has to cover both in one model. The practitioners who still separate PAM from machine identity governance will miss the real attack surface.
A few things that frame the scale:
- 61% of organisations still define privileged users as humans only, overlooking the role of non-human identities in privileged access, according to KPMG.
👉 Read our full editorial: Forrester PIM leader signals a broader shift in privilege governance