Appearance
PAM Evaluation — Keeper Enterprise PAM vs CyberArk vs Azure PIM
Story: PAM-003 — Evaluate Keeper PAM vs alternatives Owner: Rory (security) / Kobe (documentation) Status: Completed 2026-04-16 Related: Keeper License Audit, PAM Scope
Purpose
Compare the three realistic PAM options for Cirius Group's scope (defined in PAM-002) and make a recommendation. The candidates are:
- KeeperPAM (Keeper Enterprise tier + PAM add-on)
- CyberArk Privilege Cloud (industry-standard enterprise PAM)
- Azure PIM (already in use for Entra role elevation)
These three span the realistic option space: the vendor we already use, the enterprise gold standard, and the cloud-native tool we already pay for. Every other PAM vendor (Delinea/Thycotic, BeyondTrust, Teleport, HashiCorp Boundary) is a variation on one of these three patterns and would not change the recommendation.
Evaluation Criteria
Scored 1–5 against a 5-admin shop with HIPAA obligations and an Entra-primary identity stack.
| Criterion | Weight | Why it matters at Cirius |
|---|---|---|
| Session recording (video + keystroke) | High | Required by PAM scope tiers 1–4 |
| Credential brokering + rotation | High | Required by scope tiers 1, 2, 4 |
| Entra / MFA integration | High | We are an Entra-primary shop; friction here kills adoption |
| Cost for 5 admins | High | Cirius is a 15-person shop, not a bank |
| Deployment complexity | Medium | Small team — hours matter |
| Ongoing operational overhead | Medium | Rory is the sole security engineer |
| Integration with existing Keeper password vault | Low–Medium | Single pane of glass for admins |
| Auditor credibility | Medium | We will face a HIPAA audit — "never heard of it" answers cost us |
Option 1: KeeperPAM (Keeper Enterprise + PAM add-on)
| Aspect | Assessment |
|---|---|
| Session recording | Yes — full video + keystroke, 90-day default retention, tamper-evident storage. 4/5 |
| Credential brokering | Yes — Connection Manager injects credentials into RDP/SSH, rotates after use. 4/5 |
| Entra MFA integration | SAML SSO to Entra already in place for password vault. KeeperPAM admin activation also enforces the same Conditional Access policy. 5/5 |
| Cost (5 admins) | Enterprise tier for 15 users ~$1,125/yr + KeeperPAM add-on for 5 admins ~$625/yr = ~$1,750/yr. 5/5 |
| Deployment complexity | Connection Manager is a lightweight broker; deployment is estimated at 2 days for in-scope targets. 4/5 |
| Operational overhead | Shares admin console with the existing password vault Rory already runs. 5/5 |
| Integration with existing Keeper | Native — same tenant, same vault, same SSO. 5/5 |
| Auditor credibility | Known vendor, SOC 2 Type II, FedRAMP In Process. 3/5 — mid-market recognition, not CyberArk-tier. |
Total weighted: strong across the board, only soft spot is auditor brand recognition.
Option 2: CyberArk Privilege Cloud
| Aspect | Assessment |
|---|---|
| Session recording | Yes — gold standard, multi-factor playback review, forensic-grade. 5/5 |
| Credential brokering | Yes — original inventor of the pattern. 5/5 |
| Entra MFA integration | Supported via SAML; fully works but requires CyberArk-specific Entra application registration and ongoing attribute-mapping maintenance. 4/5 |
| Cost (5 admins) | Privilege Cloud base list is ~$12k–$18k/yr minimum entry, plus per-admin licensing ~$500–$800/admin/yr. ~$15k–$20k/yr for our size — order of magnitude more than Keeper. 1/5 |
| Deployment complexity | Multi-week deployment; typical 20–40 engineering hours for initial config, plus SaaS onboarding sessions. 2/5 |
| Operational overhead | Dedicated admin console, its own patching cadence for components like PSM/CPM, quarterly policy reviews as part of best practice. Not a solo-engineer tool. 2/5 |
| Integration with existing Keeper | None — two separate password/secret stores. 2/5 |
| Auditor credibility | Maximum — the reference implementation auditors expect at enterprise scale. 5/5 |
Total weighted: functionally ideal, operationally and financially disproportionate for a 15-person shop.
Option 3: Azure PIM
| Aspect | Assessment |
|---|---|
| Session recording | No — PIM is activation/approval/audit, not session capture. Azure activity log records what resources were touched but not keystroke-level intent. 2/5 |
| Credential brokering | N/A — PIM elevates the user's existing Entra identity; there is no injected shared credential. This is fine for Entra roles, irrelevant for DC/Panorama/firewall targets that don't use Entra identities for admin. 3/5 |
| Entra MFA integration | Native. Activation triggers Conditional Access and MFA. 5/5 |
| Cost (5 admins) | Included in existing Entra ID P2 licensing we already pay for. 5/5 |
| Deployment complexity | Already deployed. 5/5 |
| Operational overhead | Minimal — access reviews are automatable, approvals flow into existing M365 approvals UX. 5/5 |
| Integration with existing Keeper | N/A (different problem domain). |
| Auditor credibility | High for the Entra scope. Does not cover non-Entra targets at all. 4/5 for Entra-only scope, 1/5 as a full PAM solution. |
Total weighted: excellent for Entra role elevation, does nothing for Panorama / DC / firewall scope. This is not an "either/or" with the other options — it's a base layer.
Cost Comparison Summary
| Option | Year-1 | Year-2+ | Covers PAM scope tiers |
|---|---|---|---|
| KeeperPAM (Enterprise + PAM) | ~$2,500 incl. setup | ~$1,750/yr | Tiers 1, 2, 4 (plus native Keeper for tier 3 recording) |
| CyberArk Privilege Cloud | ~$22k–$28k incl. setup | ~$15k–$20k/yr | Tiers 1, 2, 3, 4 |
| Azure PIM only | $0 (sunk cost) | $0 | Tier 3 only |
Recommendation: Azure PIM + KeeperPAM (layered)
Azure PIM remains the control for privileged Entra role activation (scope tier 3). KeeperPAM is added on top for the non-Entra targets — Panorama, DCs, firewall CLI (scope tiers 1, 2, 4).
Reasoning:
- Azure PIM already works for tier 3 and costs us nothing additional. Ripping it out to consolidate under CyberArk or Keeper would duplicate what Entra already does well. Keep it.
- CyberArk is the functionally ideal tool but is 10x the annual cost of Keeper for our scope. At 15 people and 5 admins, the incremental control value of CyberArk over KeeperPAM is not worth the ~$15k/year premium. Revisit CyberArk only if Cirius scales past ~75 people, handles a significantly larger PHI dataset, or an auditor explicitly requires it.
- KeeperPAM is the lowest-friction path for the non-Entra scope. Rory already runs the Keeper tenant. One admin console, one SSO path, one support contract. Deployment is measured in days, not weeks. Session recording, credential injection, and rotation are all present in the PAM add-on.
- Layering is HIPAA-defensible. We document the split: "Entra-identity privileged access is protected by Entra PIM. Non-Entra privileged access (on-prem infrastructure, network management plane) is protected by KeeperPAM." Auditors accept layered controls when the boundary is documented and coherent, which it is.
- Exit ramp exists. If we outgrow KeeperPAM, migration to CyberArk is non-trivial but feasible — the PAM-scoped targets are few (Panorama, 2 DCs, 2 firewalls) and session-recording evidence retention from Keeper can be exported.
Rejected Alternatives
- KeeperPAM only, drop Azure PIM: would require moving Entra role activation workflows into Keeper. Entra PIM is native to the identity plane and tracks role assignment changes with Entra audit telemetry that Keeper cannot fully replicate. No benefit to switching.
- CyberArk only: covered above — overkill for our size.
- Teleport / HashiCorp Boundary: excellent for engineering-heavy orgs doing lots of Kubernetes / database access. Cirius's PAM scope is network/identity-weighted, not database/Kube-weighted. Poor fit.
- Delinea / BeyondTrust: Keeper-tier alternatives; no differentiation justifies a switch given we already run Keeper.
Next Steps
- [ ] Greg reviews PAM scope and this recommendation
- [ ] PAM-004: Rory presents recommendation to Greg with quote
- [ ] On Greg approval, PAM-005/006/007 deploy session recording per scope tier
- [ ] PAM-008: wire session logs to LAW
- [ ] PAM-009/010: fold PAM review into monthly security review and SecOps evidence mapping
References
- Keeper License Audit
- PAM Scope
- HIPAA Controls
- CyberArk Privilege Cloud product page — cyberark.com/products/privileged-access-manager
- Azure PIM documentation — learn.microsoft.com/entra/id-governance/privileged-identity-management
- KeeperPAM overview — keepersecurity.com/privileged-access-management.html