Skip to content

PAM Evaluation — Keeper Enterprise PAM vs CyberArk vs Azure PIM

Story: PAM-003 — Evaluate Keeper PAM vs alternatives Owner: Rory (security) / Kobe (documentation) Status: Completed 2026-04-16 Related: Keeper License Audit, PAM Scope

Purpose

Compare the three realistic PAM options for Cirius Group's scope (defined in PAM-002) and make a recommendation. The candidates are:

  1. KeeperPAM (Keeper Enterprise tier + PAM add-on)
  2. CyberArk Privilege Cloud (industry-standard enterprise PAM)
  3. Azure PIM (already in use for Entra role elevation)

These three span the realistic option space: the vendor we already use, the enterprise gold standard, and the cloud-native tool we already pay for. Every other PAM vendor (Delinea/Thycotic, BeyondTrust, Teleport, HashiCorp Boundary) is a variation on one of these three patterns and would not change the recommendation.

Evaluation Criteria

Scored 1–5 against a 5-admin shop with HIPAA obligations and an Entra-primary identity stack.

CriterionWeightWhy it matters at Cirius
Session recording (video + keystroke)HighRequired by PAM scope tiers 1–4
Credential brokering + rotationHighRequired by scope tiers 1, 2, 4
Entra / MFA integrationHighWe are an Entra-primary shop; friction here kills adoption
Cost for 5 adminsHighCirius is a 15-person shop, not a bank
Deployment complexityMediumSmall team — hours matter
Ongoing operational overheadMediumRory is the sole security engineer
Integration with existing Keeper password vaultLow–MediumSingle pane of glass for admins
Auditor credibilityMediumWe will face a HIPAA audit — "never heard of it" answers cost us

Option 1: KeeperPAM (Keeper Enterprise + PAM add-on)

AspectAssessment
Session recordingYes — full video + keystroke, 90-day default retention, tamper-evident storage. 4/5
Credential brokeringYes — Connection Manager injects credentials into RDP/SSH, rotates after use. 4/5
Entra MFA integrationSAML SSO to Entra already in place for password vault. KeeperPAM admin activation also enforces the same Conditional Access policy. 5/5
Cost (5 admins)Enterprise tier for 15 users ~$1,125/yr + KeeperPAM add-on for 5 admins ~$625/yr = ~$1,750/yr. 5/5
Deployment complexityConnection Manager is a lightweight broker; deployment is estimated at 2 days for in-scope targets. 4/5
Operational overheadShares admin console with the existing password vault Rory already runs. 5/5
Integration with existing KeeperNative — same tenant, same vault, same SSO. 5/5
Auditor credibilityKnown vendor, SOC 2 Type II, FedRAMP In Process. 3/5 — mid-market recognition, not CyberArk-tier.

Total weighted: strong across the board, only soft spot is auditor brand recognition.

Option 2: CyberArk Privilege Cloud

AspectAssessment
Session recordingYes — gold standard, multi-factor playback review, forensic-grade. 5/5
Credential brokeringYes — original inventor of the pattern. 5/5
Entra MFA integrationSupported via SAML; fully works but requires CyberArk-specific Entra application registration and ongoing attribute-mapping maintenance. 4/5
Cost (5 admins)Privilege Cloud base list is ~$12k–$18k/yr minimum entry, plus per-admin licensing ~$500–$800/admin/yr. ~$15k–$20k/yr for our size — order of magnitude more than Keeper. 1/5
Deployment complexityMulti-week deployment; typical 20–40 engineering hours for initial config, plus SaaS onboarding sessions. 2/5
Operational overheadDedicated admin console, its own patching cadence for components like PSM/CPM, quarterly policy reviews as part of best practice. Not a solo-engineer tool. 2/5
Integration with existing KeeperNone — two separate password/secret stores. 2/5
Auditor credibilityMaximum — the reference implementation auditors expect at enterprise scale. 5/5

Total weighted: functionally ideal, operationally and financially disproportionate for a 15-person shop.

Option 3: Azure PIM

AspectAssessment
Session recordingNo — PIM is activation/approval/audit, not session capture. Azure activity log records what resources were touched but not keystroke-level intent. 2/5
Credential brokeringN/A — PIM elevates the user's existing Entra identity; there is no injected shared credential. This is fine for Entra roles, irrelevant for DC/Panorama/firewall targets that don't use Entra identities for admin. 3/5
Entra MFA integrationNative. Activation triggers Conditional Access and MFA. 5/5
Cost (5 admins)Included in existing Entra ID P2 licensing we already pay for. 5/5
Deployment complexityAlready deployed. 5/5
Operational overheadMinimal — access reviews are automatable, approvals flow into existing M365 approvals UX. 5/5
Integration with existing KeeperN/A (different problem domain).
Auditor credibilityHigh for the Entra scope. Does not cover non-Entra targets at all. 4/5 for Entra-only scope, 1/5 as a full PAM solution.

Total weighted: excellent for Entra role elevation, does nothing for Panorama / DC / firewall scope. This is not an "either/or" with the other options — it's a base layer.

Cost Comparison Summary

OptionYear-1Year-2+Covers PAM scope tiers
KeeperPAM (Enterprise + PAM)~$2,500 incl. setup~$1,750/yrTiers 1, 2, 4 (plus native Keeper for tier 3 recording)
CyberArk Privilege Cloud~$22k–$28k incl. setup~$15k–$20k/yrTiers 1, 2, 3, 4
Azure PIM only$0 (sunk cost)$0Tier 3 only

Recommendation: Azure PIM + KeeperPAM (layered)

Azure PIM remains the control for privileged Entra role activation (scope tier 3). KeeperPAM is added on top for the non-Entra targets — Panorama, DCs, firewall CLI (scope tiers 1, 2, 4).

Reasoning:

  1. Azure PIM already works for tier 3 and costs us nothing additional. Ripping it out to consolidate under CyberArk or Keeper would duplicate what Entra already does well. Keep it.
  2. CyberArk is the functionally ideal tool but is 10x the annual cost of Keeper for our scope. At 15 people and 5 admins, the incremental control value of CyberArk over KeeperPAM is not worth the ~$15k/year premium. Revisit CyberArk only if Cirius scales past ~75 people, handles a significantly larger PHI dataset, or an auditor explicitly requires it.
  3. KeeperPAM is the lowest-friction path for the non-Entra scope. Rory already runs the Keeper tenant. One admin console, one SSO path, one support contract. Deployment is measured in days, not weeks. Session recording, credential injection, and rotation are all present in the PAM add-on.
  4. Layering is HIPAA-defensible. We document the split: "Entra-identity privileged access is protected by Entra PIM. Non-Entra privileged access (on-prem infrastructure, network management plane) is protected by KeeperPAM." Auditors accept layered controls when the boundary is documented and coherent, which it is.
  5. Exit ramp exists. If we outgrow KeeperPAM, migration to CyberArk is non-trivial but feasible — the PAM-scoped targets are few (Panorama, 2 DCs, 2 firewalls) and session-recording evidence retention from Keeper can be exported.

Rejected Alternatives

  • KeeperPAM only, drop Azure PIM: would require moving Entra role activation workflows into Keeper. Entra PIM is native to the identity plane and tracks role assignment changes with Entra audit telemetry that Keeper cannot fully replicate. No benefit to switching.
  • CyberArk only: covered above — overkill for our size.
  • Teleport / HashiCorp Boundary: excellent for engineering-heavy orgs doing lots of Kubernetes / database access. Cirius's PAM scope is network/identity-weighted, not database/Kube-weighted. Poor fit.
  • Delinea / BeyondTrust: Keeper-tier alternatives; no differentiation justifies a switch given we already run Keeper.

Next Steps

  • [ ] Greg reviews PAM scope and this recommendation
  • [ ] PAM-004: Rory presents recommendation to Greg with quote
  • [ ] On Greg approval, PAM-005/006/007 deploy session recording per scope tier
  • [ ] PAM-008: wire session logs to LAW
  • [ ] PAM-009/010: fold PAM review into monthly security review and SecOps evidence mapping

References

  • Keeper License Audit
  • PAM Scope
  • HIPAA Controls
  • CyberArk Privilege Cloud product page — cyberark.com/products/privileged-access-manager
  • Azure PIM documentation — learn.microsoft.com/entra/id-governance/privileged-identity-management
  • KeeperPAM overview — keepersecurity.com/privileged-access-management.html

Internal use only — Cirius Group