This video introduces an alternative approach to privileged access management that focuses on controlling identity and authentication rather than credential vaulting. The model emphasizes three key pillars: governing privilege identities (who gets admin access, how requests are made, and duration), controlling authentication through MFA and conditional access policies, and restricting the operating environment to approved devices and hardened workstations. This approach reduces credential exposure, provides visibility into privilege activity, and aligns with Essential Eight security requirements by controlling access at the entry point rather than waiting until sessions begin.
Deep Dive
Prerequisite Knowledge
- No data available.
Where to go next
- No data available.
Deep Dive
Talking Identity: A Simpler Way to Control Privileged Access (Part III)Added:
Hello everyone. I'm Hector from Assertive and welcome to the third installment of our video series privileged access without the pain. In our last video, we look at how traditional PAMP tools work. We also had a look at the complexity in of rolling out these type of tools. So, let's take a step back and ask a different question. What if you didn't start with a credential at all? What if you control how identities are used instead?
Interested? Join me for the conversation.
So, most modern attacks today don't break into a vault. They don't really need to. Attackers really use compromised user accounts, token theft, lateral movement, privilege escalations.
In other words, they abuse identity and authentication. So if that's where the attacks happens, doesn't it make sense that that's where the controls need to happen? Instead of focusing on stoing and rotating credentials, this model focuses on three things. One, govern privilege identities. Who can get admin access? How is requested? How long does it last? No more standing privileges sitting around. Number two, control authentication. This is the critical piece here. You enforce MFA conditional access where login can happen and what devices can be used. So even if an account exist, it can be used it cannot be used freely. And number three, restricting the operating environment.
Administrative actions only happen from approved devices, hardened controls, hardened workstations, control environments. So you're not just controlling who, you are controlling how and when privilege access is used.
Now if you put those three things together, what do you get? Understanding privilege, control elevation when needed, restricted authentication paths, reduce credential exposure, visibility of privilege activity. If this all sounds familiar, it's because it's exactly what essential aid is trying to achieve.
So this is the shift. Traditional PAM says protect credentials then control the session. This model says control the identity and the authentication and you reduce the risk before the session even starts. You are not waiting until access happens. You're controlling it at the entry point.
Now we are not saying never use spam.
We're not saying that. There is a still still cases where you know credential vaulting makes sense. Session recording is required. Share accounts need type controls. But instead of starting there, you start with identity and authentication as your control plane and add those capabilities where they are actually needed.
So you've got two models, one that controls credentials and sessions and one that controls identity and authentication. In the final video, we are going to put these models side by side and look at how to choose the right approach for your environment. If you're trying to meet essential aid without over complicating things, without overengineering, this model is worth understanding. Thank you so much for your time and we look forward to seeing you in our next installment.
Related Videos
Agentforce NOW AMA: Build with React and Salesforce Multi-Framework
SalesforceDevs
490 views•2026-05-28
How agent o11y differs from traditional o11y — Phil Hetzel, Braintrust
aiDotEngineer
450 views•2026-05-28
WEB TECHNOLOGIES UNIT-2 | Degree 4th sem BCOM Computers web technologies unit-2 full explanation💯✅
LearnwithSahera
1K views•2026-05-29
More tests are always better? How to use AI to identify tests that bring little value
Alliance4Qualification
335 views•2026-05-29
Search Algorithms Explained in 60 Seconds! 🤖💨
samarthtuliofficial
218 views•2026-06-01
People of Game of Thrones using JavaScript DOM
AltCampus
296 views•2026-05-30
Introduction to Problem Solving Part - 1 | Lecture 1 | Intermediate DSA
ascensionix
107 views•2026-05-29
🚀 BCS613C Compiler Design | Module 1 to 5 Schema Evaluation 🔥 | VTU 6th Sem 💯 #VTU #bcs613c #exam
Pranavaa-y4y
104 views•2026-06-02











