Privileged Access Management
High-Assurance Access
System administrators, C-suite and high-value targets need authentication that passwords and basic MFA can't protect. PKI smart cards, HSM-backed secrets and dual-control policies, all from MyID®.

Step-by-step deployment
Identify Privileged Users
Enumerate all elevated accounts, domain admins, DBAs, executives and service accounts.
Issue High-Assurance Credentials
MyID CMS issues PKI smart cards or FIDO2 keys with privileged-specific certificate policies.
Enforce Dual Control
High-risk operations require dual approval. MyID SecureVault enforces this at the secrets layer.
Audit Every Session
Every privileged authentication event logged, user, credential, device, timestamp. Immutable.
What you need to deploy
PKI Infrastructure
CA connection for privileged certificate profiles, separate OID from standard user certs.
HSM Hardware
FIPS 140-2 Level 3 HSM for privileged key material. Entrust nShield or Thales Luna.
PAM Integration
CyberArk, BeyondTrust or Delinea for session recording alongside MyID credential management.
Products that deliver this solution
Regulations this solution addresses
| Regulation / Standard | Requirement | Status with MyID |
|---|---|---|
| NIST SP 800-53 AC-2 | Account management, privileged account controls | Privileged certificate policies enforced |
| ISO 27001 A.9 | Access control, privileged access management | Full lifecycle with dual-control support |
| PCI-DSS v4.0 Req 8.7 | MFA for all admin access to CDE systems | Hardware MFA for all privileged sessions |
| CIS Control 5 | Account management, admin account hardening | Hardware-bound credentials eliminate password risk |
| SOC 2 CC6.1 | Logical access security, privileged access controls | Immutable audit trail for SOC 2 evidence |