Truth in IT
    • Sign In
    • Register
        • Videos
        • Channels
        • Pages
        • Galleries
        • News
        • Events
        • All
Truth in IT Truth in IT
  • Data Management ▼
    • Converged Infrastructure
    • DevOps
    • Networking
    • Storage
    • Virtualization
  • Cybersecurity ▼
    • Application Security
    • Backup & Recovery
    • Data Security
    • Identity & Access Management (IAM)
    • Zero Trust
    • Compliance & GRC
    • Endpoint Security
  • Cloud ▼
    • Hybrid Cloud
    • Private Cloud
    • Public Cloud
  • Webinar Library
  • TiPs
  • DRAW

Introducing IDIRA Modern Privilege Access Management

Palo Alto Networks
07/24/2026
0 (0%)
Share
  • Comments
  • Download
  • Transcript
Report Like Favorite
  • Share/Embed
  • Email
Link
Embed

Transcript


It simply cannot keep up with pervasive privileges and the sheer velocity of AI growth. This moment requires more than just an update. It requires a fundamental category shift. Hello, Impact. I am so happy to be with you guys today. It's amazing to be here in Austin and to see so many familiar faces. Thank you for spending time with us. Now, I want to start with something that on the surface feels very familiar, but when you really look at it, it has completely changed. And I'm talking about privilege. For a long time, we have thought about privilege in a very specific, very narrow way. In fact, privilege belonged to a small group of people, IT administrators, who held the keys to the kingdom. That was the original problem that Pam was built to solve, and CyberArk solved it better than anyone else. But here is the reality we have to face. That world no longer exists. In every modern enterprise, every single user can become privileged based on the data, the SaaS applications they can access. Privilege has been democratized, but not in a way that makes us safer. Today, your developers are pushing code directly into production. Your cloud operations, well, they are managing infrastructure from a single console. Your data scientists are running models against your company's most sensitive and proprietary customer data. And now, business users, just like me, we are living inside SaaS applications that holds the crown jewels of your information. These are all high-risk identities that can impact entire systems with a single keystroke. Yet, despite this reality, only 22% of organizations attribute privilege to every human identity. This is a massive disconnect. It means that for 78% of organizations, true identity security is only being applied to a tiny subset of users. Human privileges are pervasive. It is uncontrolled, and it is an open door for attackers. This disconnect creates what we call the privilege-exposure gap, where privilege lives today and where security is actually applied. Now, there are three primary reasons why this gap continues to widen. First, we are suffering from fragmented visibility. Traditional tools were built for a static world. They provide limited insight across modern workloads and cloud-native identities. This is what we call identity debt. It's hidden in plain sight, accumulating interest every day you don't address it. Second, we have a problem with persistent risk. We are still relying on static, always-on privileges. In a modern environment, standing privileges should be the exception, yet somehow they've become the default. This creates a permanent attack surface, allowing adversaries to exploit that standing access whenever they choose. And finally, there's complexity in our tools. Traditional systems require heavy, manual deployments that can slow down your teams. This forces business leaders to make an impossible choice between security and velocity. When you combine these factors, overprivileged and dormant access accumulate rapidly. The attacker can use these trusted paths without triggering alerts. Risk and cost compound over time, and this gap is only growing larger. So we have to be honest with ourselves as an industry. The existing model is broken. It simply cannot keep up with pervasive privileges and the sheer velocity of AI growth. This moment requires more than just an update. It requires a fundamental category shift. We have to redefine how we deliver privileged security across the entire enterprise. We cannot just iterate. For too long, the industry has accepted a two-tier system, high-grade security for the few and basic authentication for the many. But attackers don't care about our internal definitions. They care about access. Meeting this moment means moving beyond the silos of the past to build a system that treats every identity as a privileged identity by default. We must be willing to disrupt ourselves to meet the needs of the AI enterprise. And it is with that spirit that I am incredibly proud to introduce our next generation of human identity security, IDERA Modern Privilege Access Management. IDERA sets a new standard for PAM. By eliminating standing privileges and extending dynamic privilege controls to all users, we are democratizing privilege controls. And this will help ensure that all identities are secured, not just managed. We are building this on three core pillars, full discovery to eliminate blind spots, dynamic privilege access to extend controls to every identity and modern target, and radical simplicity to make security a force multiplier. Now, let's take a look at this first pillar of discovery. But this is not discovery as we have known it, not a static inventory, not a one-time scan. This is continuous AI-driven discovery. Understanding where privilege exists across the enterprise, across users, across cloud environments, across SaaS applications, but more importantly, understanding context. How these identities behave, what they access, and where they introduce risk. We are introducing the remediation agent where visibility finally meets automated action. The goal is to replace your blind spots with continuous visibility and AI-driven analytics that surface and remediate identity risk across the entire enterprise. This agent is a true game changer. It analyzes your specific tenant account onboarding patterns to predict and recommend the best controls for every discovered account. This is the find it, fix it capability the industry has been waiting for. The remediation agent acts as a force multiplier for your team. It can reduce your onboarding cycle time by up to 66%. We're talking about moving from a 21-day, manual, fragmented process down to just seven days. And we do this all with a human-in-the-loop philosophy. Every AI recommendation includes a competent score and the specific onboarding reasoning so your team remains in control while moving at light speed. Now to show you exactly how we turn visibility into action, let's look at how Ideara's AI remediation agent tackles the massive scale of unmanaged accounts across your enterprise. Every organization is buried under identity debt. For a security admin, the Ideara Risk Management Dashboard maps that debt, revealing a high-risk baseline of unmanaged admins and exposed secrets that grow faster than we can secure them. We can't fix it all at once, so we prioritize. By identifying our top five hotspots, we see the structural risks that matter most, like orphaned users with privileged access and compromised shared app credentials. But we don't stop at visibility. We use Cora AI to turn these insights into a plan. We simply ask Cora to secure our most privileged accounts, providing instant visibility into the exposure, and remediation is now automated for built-in and service accounts. The AI agent does the heavy lifting, and provides context and onboarding accounts in bulk. This is Pam at the speed of business. For personal privileged accounts, we remove the risk entirely. We move users from permanent standing access to zero standing privilege, so access only exists when the work is actually happening. The result? We've shifted the needle. Our risk score is trending down because we've neutralized the exposures that matter most. Moving from identity debt to a hardened posture. Finally, we ensure that debt doesn't crawl back. Continuous governance keeps the environment secure long after the initial cleanup. The shift from manual discovery to automated remediation, empowering you to not only find risk, but to fix it. Now, I love hearing from our customers and how the innovation we're driving is helping them every day. So let's take a listen to Brian. Identity is, I really think, the place to be, and you've gotta get that right to enable the business. How do we change that paradigm where we can reliably leverage AI to solve our problems at speed much, much faster? And again, some of the remediation solutions are some of the things I've been looking for. We're sort of at a balancing point. Too fast, and we're not gonna think things through all the way. Too slow, and the whole industry and the whole capability set that we're trying to secure is gonna get away from us. We need reliable, repeatable solutions that are at speed. I think more and more high-quality platform solutions are really important. Palo Alto has a lot of best of breed that they bring to the table. It's the same innovation we've counted on for many years. Going forward, as part of a very, very state-of-the-art Palo Alto network family. Now, from discovery, we move on to controls, and this is where the biggest shift happens. We move away from where identity is static and the idea that access should exist permanently, and towards a model to have access exist only when it's needed. This is dynamic privilege, and it's delivered through a combination of models. Zero standing privilege, just-in-time access, and contextual enforcement. Now, zero standing privilege means exactly what it sounds like. There are no permanent permissions, no standing access. Nothing exists unless it's required. Even if the compromise happens and the credential is taken over by an attacker, there is no entitlement for them to use and leverage laterally, and that changes everything. Because if permanent entitlement does not exist, it cannot be exploited. For scenarios where access is required temporarily, we use just-in-time access. Permissions are granted for a specific task, for a specific duration, and then removed immediately after. And the key here is updating and extending this model so that it's not just for traditional environments, it's for modern environments. That includes zero standing privilege and access for managed Kubernetes, and enter ID groups, helping customers bring dynamic privileges to systems that have become central to modern operations. It also means shifting PAM left with Terraform and CLI-based automations that allow customers to embed privilege controls into deployment workflows instead of layering them in after the fact. And privilege controls are not just for IT administrators anymore. We are extending true security to all human users. Whether it's a developer, a data scientist, a business user, we are providing seamless privilege session management for the web applications where your most sensitive data lives. We are shifting from a workforce state of static standing privilege to a secure dynamic state of just-in-time access. Now, to show you how this transformation impacts the daily experience of an employee, let's walk through a day in the life of a platform engineer operating in a world of zero standing privilege. Alex is a platform engineer, and his day begins from a trusted foundation. His workstation, secured by Cortex, Idera Endpoint Privilege Manager, and Prisma Secure Browser. If Cortex identifies a threat, it triggers EPM to impose a stricter policy posture to neutralize risk. Alex starts with zero standing privilege. Because of his role in the Project Phoenix production deployment, the platform has already paved the path for the infrastructure and applications he needs. This isn't manual policy creation. It's deployed as code via Terraform. Security is baked in the pipeline. This allows him to jump straight into the mission. First, he needs to push an updated Intune policy for devices that are part of the project. Alex gets scoped, just-in-time access to Intune, and his privileges expire at the end of the session. Next, Alex needs to monitor the health of Project Phoenix using ZSP for SaaS applications to access the Chronosphere dashboard. He identifies a latency alert on the production cluster. Alex has the necessary visibility to diagnose the root cause without standing privileges. To resolve the problem, he uses the IDsec CLI to gain native access to the production cluster to remediate it, all with zero standing privilege. Finally, the CISO's view. The command center is the high-definition proof of our zero-trust strategy. We see the full story, not just Alex's ZSP access, but the activity of our machine and AI identities as well. The Phoenix production rollout is a success. The audit trail is complete, and the attack surface has been reduced. By shifting from static permissions to dynamic session-based access, we've empowered Alex to move at the speed of business without leaving an open door for attackers. Now, just as importantly as what we do is how we deliver it. With Idera, we have completely reimagined the user experience through a unified command center. It provides real-time insights from workforce users and vendors to service accounts and AI agents. Now, it doesn't just show you identities. It shows you exactly how they connect to your systems, the privileges that they hold, and the risk they pose. But this is more than just a dashboard. It's an entirely new way of working. By implementing a unified policy model with guided, outcome-driven workflows, we've fundamentally reduced the overhead of operating PAM at scale through self-service deployment. From the command center, your security teams can finally monitor identity posture in real-time, enforce policy, and investigate incidents from a single, unified console. The PAM you know and love is finally ready for the future with Idera. Everything we've discussed today, from discovery, the dynamic access, the radical simplicity, it all leads to a very different outcome for your organization. First and foremost, you eliminate standing access by ensuring that no identity holds access longer than necessary, you remove the permanent attack surface that adversaries rely on. You reduce lateral movement. When sessions are contained, monitored, and bound by just-in-time controls, an attacker who gains a foothold has nowhere to go. But perhaps most importantly, you can extend privileged controls across the entire workforce. We are moving beyond the era where high-grade security was reserved for a small elite. Every single identity has access that matters. Because as we have seen, that is exactly where the risk lives. When you address that risk in a way that is dynamic, contextual, and simple to operate, you do more than just add a new tool. You fundamentally change the security posture of the entire organization. You move from a reactive state of identity debt to a proactive state of active security. Adira, Amon, and Pam enables us to close the exposure gap. This is the end of the always-on era and the beginning of a resilient AI enterprise.

TL;DR

  • Privilege has been democratized across modern enterprises — developers, cloud operators, data scientists, and business users all hold high-risk access — yet 78% of organizations only apply true identity security to a tiny subset of users, creating a massive privilege-exposure gap.
  • Palo Alto Networks introduces IDERA Modern PAM, built on three pillars: continuous AI-driven discovery with automated remediation (reducing onboarding cycles by 66%), dynamic privilege controls that eliminate standing access through zero standing privilege and just-in-time models, and radical simplicity via a unified command center.
  • The AI remediation agent analyzes tenant-specific patterns to predict optimal controls and automate bulk onboarding, shifting organizations from manual 21-day processes to seven-day cycles while maintaining human-in-the-loop oversight with confidence scores and reasoning transparency.
  • Zero standing privilege extends beyond traditional IT admins to modern environments including managed Kubernetes, Entra ID groups, Terraform workflows, and web applications where sensitive data lives, ensuring no permanent entitlements exist that attackers can exploit.
  • The unified command center provides real-time visibility across all identity types (workforce, vendors, service accounts, AI agents), showing how they connect to systems, privileges held, and risk posed, enabling organizations to move from reactive identity debt to proactive active security posture.

The Privilege-Exposure Gap in Modern Enterprises

This keynote addresses a fundamental shift in how privilege operates across modern organizations. Traditional Privileged Access Management (PAM) was designed for a small group of IT administrators, but today every user can become privileged based on their access to data and SaaS applications. Developers push code to production, cloud operations manage infrastructure from single consoles, and business users work in applications containing crown jewel data. Despite this reality, only 22% of organizations attribute privilege to every human identity, creating what Palo Alto Networks calls the privilege-exposure gap. This disconnect stems from three core problems: fragmented visibility across modern workloads, persistent risk from static always-on privileges, and complexity in traditional deployment models that force impossible choices between security and velocity.

IDERA Modern PAM: Zero Standing Privilege at Scale

Palo Alto Networks introduces IDERA Modern Privilege Access Management as a fundamental category shift built on three pillars. First, continuous AI-driven discovery provides visibility across users, cloud environments, and SaaS applications with contextual understanding of behavior and risk. The remediation agent analyzes tenant-specific patterns to predict optimal controls, reducing onboarding cycles by up to 66% from 21 days to seven days. Second, dynamic privilege controls eliminate standing access through zero standing privilege (ZSP) and just-in-time access models, extending to modern environments including managed Kubernetes, Entra ID groups, and Terraform-based workflows. Third, radical simplicity is delivered through a unified command center with real-time insights, guided workflows, and self-service deployment that reduces operational overhead while extending privileged controls to the entire workforce, not just IT administrators.

From Identity Debt to Active Security Posture

The solution transforms how organizations manage identity risk by shifting from reactive identity debt to proactive security. The AI remediation agent identifies structural risks like orphaned users with privileged access and compromised shared credentials, then automates bulk onboarding with human-in-the-loop oversight. For personal privileged accounts, the platform moves users from permanent standing access to zero standing privilege, ensuring access only exists when work is actively happening. Continuous governance prevents identity debt from accumulating after initial cleanup. The unified command center provides visibility across workforce users, vendors, service accounts, and AI agents, showing not just identities but how they connect to systems, the privileges they hold, and the risk they pose. This approach eliminates the permanent attack surface adversaries rely on and contains lateral movement by binding sessions with just-in-time controls.

Chapters

0:00 - The Broken Model of Privilege
1:17 - The Privilege-Exposure Gap
2:55 - Three Reasons the Gap Widens
4:38 - The Need for Category Shift
5:43 - Introducing IDERA Modern PAM
6:30 - Pillar One: AI-Driven Discovery
8:24 - Remediation Agent Demo
11:26 - Pillar Two: Dynamic Privilege Controls
14:03 - Day in the Life: Platform Engineer
16:05 - Pillar Three: Radical Simplicity
17:11 - Outcomes and Impact

Key Quotes

0:00 "... the existing model is broken. It simply cannot keep up with pervasive privileges and the sheer velocity of AI growth. This moment requires more than just an update. It requires a fundamental category shift."
1:27 "Privilege has been democratized, but not in a way that makes us safer."
2:14 "... only 22% of organizations attribute privilege to every human identity. This is a massive disconnect. It means that for 78% of organizations, true identity security is only being applied to a tiny subset of users."
5:43 "IDERA Modern Privilege Access Management. IDERA sets a new standard for PAM. By eliminating standing privileges and extending dynamic privilege controls to all users, we are democratizing privilege controls."
7:47 "This is the find it, fix it capability the industry has been waiting for. The remediation agent acts as a force multiplier for your team. It can reduce your onboarding cycle time by up to 66%."
12:24 "... if permanent entitlement does not exist, it cannot be exploited."

FAQ

How does IDERA's AI remediation agent reduce onboarding time while maintaining security controls?

The remediation agent analyzes your specific tenant account onboarding patterns to predict and recommend the best controls for every discovered account. It automates bulk onboarding for built-in and service accounts while maintaining a human-in-the-loop philosophy — every AI recommendation includes a confidence score and specific onboarding reasoning so security teams remain in control. This reduces onboarding cycles by up to 66%, from 21 days down to seven days, while ensuring appropriate controls are applied based on learned organizational patterns.

What is zero standing privilege and how does it prevent lateral movement after a credential compromise?

Zero standing privilege means there are no permanent permissions or standing access — nothing exists unless it's required for a specific task. Even if an attacker compromises credentials and takes over an account, there are no entitlements for them to use and leverage laterally. Permissions are granted just-in-time for specific tasks and specific durations, then removed immediately after. When sessions are contained, monitored, and bound by just-in-time controls, an attacker who gains a foothold has nowhere to go because the permanent attack surface has been eliminated.

How does IDERA extend privileged access management beyond traditional IT administrators?

IDERA extends true security controls to all human users including developers, data scientists, and business users through seamless privilege session management for web applications where sensitive data lives. It brings dynamic privileges to modern environments like managed Kubernetes and Entra ID groups, and shifts PAM left with Terraform and CLI-based automations that embed privilege controls into deployment workflows instead of layering them in after the fact. This democratizes privilege controls across the entire workforce rather than reserving high-grade security for a small elite group.

Categories:
  • » Cybersecurity » Identity & Access Management (IAM)
  • » Cybersecurity » Zero Trust
  • » Cybersecurity » Cloud Security
  • » Data Protection
Channels:
News:
Events:
Tags:
  • Identity & Access
  • Zero Trust
  • Cloud Security
  • AI & Machine Learning
  • Technical Deep Dive
  • Privileged Access Management
  • Zero Standing Privilege
  • Identity Security
  • AI-Driven Remediation
  • Just-in-Time Access
  • Identity Debt
  • Attack Surface Reduction
Show more Show less

Browse videos

  • Related
  • Featured
  • By date
  • Most viewed
  • Top rated
  •  

              Video's comments: Introducing IDIRA Modern Privilege Access Management

              XStreaminars (watch here)

              • Jul
                28

                Illumio + Netskope: Zero Trust in the Age of AI Autonomy

                07/28/202601:00 PM ET
                • Jul
                  29

                  Ask Your Cloud Anything: Unlocking Governance Silos in your Environments

                  07/29/202601:00 PM ET
                  More events

                  Industry Events (watch there)

                  • Aug
                    06

                    Mitigating Risks of Sensitive Data Exposure in AI Platforms

                    08/06/202604:00 AM ET
                    • Aug
                      06

                      Same Tactics, Enhanced Velocity: The Impact of AI Agents on Identity Attacks

                      08/06/202602:00 PM ET
                      • Aug
                        07

                        Discover DLP Memories: The Evolving Triage Agent That Learns Each Shift

                        08/07/202611:00 AM ET
                        More events

                        Upcoming Webinar Calendar

                        • 07/28/2026
                          01:00 PM
                          07/28/2026
                          Illumio + Netskope: Zero Trust in the Age of AI Autonomy
                          https://www.truthinit.com/index.php/channel/2031/illumio-netskope-zero-trust-in-the-age-of-ai-autonomy/
                        • 07/29/2026
                          04:00 AM
                          07/29/2026
                          Real-Time Strategies for Safeguarding Against Prompt Injections
                          https://www.truthinit.com/index.php/channel/1968/real-time-strategies-for-safeguarding-against-prompt-injections/
                        • 07/29/2026
                          01:00 PM
                          07/29/2026
                          Ask Your Cloud Anything: Unlocking Governance Silos in your Environments
                          https://www.truthinit.com/index.php/channel/2048/ask-your-cloud-anything-unlocking-governance-silos-in-your-environments/
                        • 08/06/2026
                          04:00 AM
                          08/06/2026
                          Mitigating Risks of Sensitive Data Exposure in AI Platforms
                          https://www.truthinit.com/index.php/channel/2058/mitigating-risks-of-sensitive-data-exposure-in-ai-platforms/
                        • 08/06/2026
                          02:00 PM
                          08/06/2026
                          Same Tactics, Enhanced Velocity: The Impact of AI Agents on Identity Attacks
                          https://www.truthinit.com/index.php/channel/2064/same-tactics-enhanced-velocity-the-impact-of-ai-agents-on-identity-attacks/
                        • 08/07/2026
                          11:00 AM
                          08/07/2026
                          Discover DLP Memories: The Evolving Triage Agent That Learns Each Shift
                          https://www.truthinit.com/index.php/channel/2062/discover-dlp-memories-the-evolving-triage-agent-that-learns-each-shift/
                        • 08/07/2026
                          11:30 AM
                          08/07/2026
                          Refreshing Beverages and Essential Cybersecurity Insights for the Season
                          https://www.truthinit.com/index.php/channel/2063/refreshing-beverages-and-essential-cybersecurity-insights-for-the-season/
                        • 08/13/2026
                          12:00 PM
                          08/13/2026
                          Harnessing AI for Secure Innovation in the Enterprise with Netskope & Omada
                          https://www.truthinit.com/index.php/channel/2065/harnessing-ai-for-secure-innovation-in-the-enterprise-with-netskope-omada/
                        • 08/19/2026
                          12:00 PM
                          08/19/2026
                          Becoming Agent Ready: Insights and Strategies with Cyera
                          https://www.truthinit.com/index.php/channel/2036/becoming-agent-ready-insights-and-strategies-with-cyera/
                        • 09/02/2026
                          12:00 PM
                          09/02/2026
                          Unified Data Security in Action: Uncover, Analyze, and Resolve Threats
                          https://www.truthinit.com/index.php/channel/2045/unified-data-security-in-action-uncover-analyze-and-resolve-threats/
                        • 09/30/2026
                          04:00 AM
                          09/30/2026
                          AI Command Center: Optimizing Visibility and Control in Your Operations
                          https://www.truthinit.com/index.php/channel/2024/ai-command-center-optimizing-visibility-and-control-in-your-operations/
                        Truth in IT
                        • Sponsor
                        • About Us
                        • Terms of Service
                        • Privacy Policy
                        • Contact Us
                        • Preference Management
                        Desktop version
                        Standard version