Home/Identity & Access

Every identity system you own was built for humans. Most of what signs in now isn’t one.

Service accounts, API keys, CI/CD credentials and now AI agents acting on a user’s behalf. Non-human identities outnumber human ones in most estates — and almost none of them are governed by the systems that govern employees.

CyberArk sells the human vault and Secrets Manager as separate products, because an application requesting a credential ten thousand times an hour is not a person checking one out. Three routes below; each answers a different question about who — or what — is signing in.

Privileged Access Management

Some accounts can change or destroy everything. You need to control who uses them, and prove it.

17 productsOpen the guide →
Often confused with IAM, SSO & MFA. The difference: IAM decides who gets in; PAM controls what the most dangerous accounts can do once inside. IAM, SSO & MFA

IAM, SSO & MFA

People and services need to sign in. You need to know it's really them.

17 productsOpen the guide →
Often confused with Identity Governance. The difference: one grants access, the other proves the access granted was correct. Identity Governance

Identity Governance

Someone has access they shouldn't. You need to find it, remove it, and show an auditor.

10 productsOpen the guide →
Often confused with IAM, SSO & MFA. The difference: IAM is live in weeks and run by administrators; governance takes months and needs the business. IAM, SSO & MFA
Second entry axis

Something just happened?

Events and audits send people here more often than job descriptions do. If one of these is your week, it already names your route.

An RBI or SEBI CSCRF audit asked how privileged access is controlled

Privileged Access Management

Administrators share a root password nobody has rotated in years

Privileged Access Management

A push-fatigue attack got someone to tap approve at midnight

IAM, SSO & MFA

A legacy application still can't do single sign-on

IAM, SSO & MFA

A leaver kept access for three weeks and nobody noticed

Identity Governance

The auditor wants evidence of periodic access reviews

Identity Governance

The overlaps

Why people pick the wrong door

Nobody confuses the definitions. They confuse the pairs. Four overlaps, and the one question that settles each:

PAMvsIAM

Are you controlling who gets in, or what they can do once inside?

Buy IAM when you needed PAM and every administrator still shares a root password nobody rotates, with no recording when the auditor asks who did what. Buy PAM when you needed IAM and you have a vault for fifty accounts while ten thousand people sign in with a password and a push prompt.

IAMvsIdentity Governance

Do you need access granted, or proven?

Buy IAM expecting governance and the auditor asks for evidence of periodic access reviews that your identity provider never ran. Buy governance when the real gap was joiner-mover-leaver and you have a months-long certification programme for a problem that needed an HR trigger.

PAMvsSecrets management

Is the thing signing in a person, or a process?

Buy a human vault for a machine problem and your pipelines keep credentials in CI/CD variables while the vault holds fifty administrator accounts. Buy a secrets platform expecting session recording and the auditor's question about who used the domain admin account at 2am has no answer at all.

PAMvsIdentity Governance

Is the account controlled, or is the entitlement justified?

Buy PAM and the domain admin credential is vaulted and recorded — while nobody has asked in three years whether those fourteen people should still be administrators at all. Buy governance and the certification campaign approves a list of privileged roles it cannot see being used, with the credentials themselves still shared and unrotated. The vault controls the account; the campaign justifies the entitlement, and an auditor asks for both.

Compare any two terms

vs
PAMPrivileged Access Management

The vault and broker for accounts that can change or destroy things, with session recording.

The Privileged Access Management boundary section →
Secrets managementPrivileged Access Management

The machine half — credentials requested by applications, pipelines and containers, unattended.

The Privileged Access Management boundary section →

The difference

A vault for humans and a vault for code. PAM brokers a credential a named person checks out, with a session to record and an approval to log. Secrets management serves an application, pipeline or container requesting a credential unattended, thousands of times an hour, with no session and no human. CyberArk sells both as separate products — that is the clearest statement of the difference you will find.

The vocabulary — one line each

Sixteen terms, one line each. The depth lives in each route’s guide.

These are adjacent scopes, not tiers. IGA is not IAM done better — it answers a different question, needs different people, and takes far longer to implement than buyers expect. Each route’s guide resolves only the four its buyer confuses.

  • PAMthe vault and broker for accounts that can change or destroy things, with session recording
  • PIMthe lifecycle and eligibility of privileged identities — eligible rather than permanent roles
  • PEDMno vault: an agent removes standing local admin and elevates named applications instead
  • Secrets managementthe machine half — credentials requested by applications, pipelines and containers, unattended
  • IAMthe umbrella: directory, sign-on, factors, policy and lifecycle for who may get in
  • SSOone authenticated session opening many applications through SAML, OIDC or OAuth
  • MFAproof beyond the password — and push is phishable where a FIDO2 key is not
  • Directorythe list of who exists and what they belong to; everything else authenticates against it
  • CIAMcustomer identity at consumer volume, priced per monthly active user — a different product
  • Phishing-resistant MFAFIDO2 security keys and passkeys, which an attacker cannot relay or fatigue you into approving
  • IGAthe platform around requests, approvals, reviews and the evidence they happened
  • Provisioningcreating, changing and removing access from an HR or directory event rather than a ticket
  • Access reviewthe recurring look at who has what — rubber-stamping at scale without context
  • Certificationthe evidenced version: scope, deadlines, decisions, revocations, an audit trail
  • SoDsegregation of duties — detecting the person who can both create and approve a payment
  • ITDRidentity threat detection and response: the session after sign-in, not the sign-in itself
Ground truths

What holds whichever route you take

Most of what signs in is not a person

Service accounts, API consumers, pipeline credentials, workload identities and now AI agents authenticate constantly, unattended, and outnumber human identities in most estates by a wide margin. No manager owns them, no HR event ends them, and no certification campaign reviews them. Every route on this page was designed for people first — ask each vendor what it does for the other population, and expect a thinner answer than the brochure implies.

You already own an identity provider

Microsoft Entra ID P1 (roughly $6–7 per user per month, already inside Microsoft 365 E3) gives SSO and full conditional access; P2 (about $9–10, inside E5) adds Privileged Identity Management. Google’s Cloud Identity Premium is around $6. The useful question is never “which identity provider” but “where does the one on my invoice stop” — usually at legacy protocols, non-Microsoft depth, or governance evidence.

The factor matters more than the acronym

“Supports MFA” covers both a push notification a tired person taps at midnight under a fatigue attack and a FIDO2 security key an attacker cannot phish at all. Push fatigue is a live technique, not a theoretical one. Every guide here records documented FIDO2 and passkey support per product — and marks it unknown where vendor documentation does not establish it, rather than assuming.

India names the control, not the product

The RBI Master Direction on Information Technology Governance, Risk, Controls and Assurance Practices (7 November 2023, in force 1 April 2024) requires need-based access and multi-factor authentication for privileged users; SEBI’s CSCRF (August 2024) sets least-privilege and privileged-access requirements; the IRDAI Information and Cyber Security Guidelines, 2023 (24 April 2023) require privileged access management and periodic access reviews. Each names a control and an evidence expectation — not a product category. Read the circular before the brochure.

The licence is the small number. Onboarding, implementation and the population nobody governs are the purchase.
TechBag
Where it's heading

The seams are moving

Identity vendors are absorbing privileged access — Okta, One Identity and miniOrange all sell a vault beside the sign-in, and Palo Alto Networks announced its acquisition of CyberArk in July 2025. Endpoint vendors are adding identity threat detection from the other side (CrowdStrike Falcon Identity Protection, SentinelOne Singularity Identity). And ITDR is emerging in the gap between identity and security operations: continuously scoring the session after sign-in, which neither an identity provider nor an endpoint agent was originally built to do. Buying two of these today often means buying one thing twice.

What you used to buyWhat you buy now
Privileged access
vault · sessions · secrets
IAM, SSO & MFA
who gets in
Identity governance
who should have
One direction
Identity vendors absorbing PAM
the IdP sells the vault beside the sign-in
OktaCyberArkOne IdentityminiOrange
One direction
Endpoint vendors adding identity threat detection
the agent watches the directory too
CrowdStrikeSentinelOneBeyondTrust
One direction
ITDR between identity and SecOps
the session after sign-in, continuously scored
OktaCrowdStrikeSentinelOneRubrik

Buy for the seam that is moving, not last year’s org chart — and buy the scope, not the brand.

Check what you already own

Almost every buyer in this category already holds part of what they are about to purchase — usually the sign-in half, occasionally the governance half, almost never the machine half.

  • Microsoft Entra ID P1 SSO, full conditional access and hybrid identity at roughly $6–7 per user per month — and already inside Microsoft 365 E3. Stops at governance evidence and non-Microsoft depth.
  • Microsoft Entra ID P2 adds Privileged Identity Management (eligible rather than permanent roles, with approval and expiry) and risk-based sign-in, about $9–10 per user per month, inside E5. It governs Microsoft's own roles; it vaults no server or network credential.
  • Entra ID Governance add-on access reviews, entitlement management and lifecycle workflows for roughly $4–7 per user per month on top of P1 or P2. Real governance for the Microsoft estate; thin for third-party applications.
  • Google Cloud Identity Premium around $6 per user per month for SSO, device management and security controls in a Google-centric estate. Thin for legacy protocols and non-Google SaaS.
  • On-premises Active Directory Kerberos, LDAP and group policy for the domain — and nothing for SaaS. It is what most estates federate from, not to.
  • MFA inside a product you already run your VPN, firewall, UEM or endpoint vendor may already include multi-factor authentication. Check which factors — if it is push and one-time codes only, the phishing-resistant gap is still open.

If the half you need is already on your invoice, we say so. It costs us a sale and saves you one.

Budget shape

What it costs, roughly

Three meters live in this category, and a fourth number under all of them: the project. Which meter you are quoted tells you which route you are in — order of magnitude here, the tier- and term-matched USD + INR number is each guide’s job.

Privileged Access Management
Per privileged user · per managed asset
CyberArk reported $1,800–12,000 per privileged user / yr on a steep volume curve; BeyondTrust about $157 per managed asset / yr on the US GSA schedule; ARCON, Securden and miniOrange quote in INR. The meters differ by up to 5× on the same estate.
IAM, SSO & MFA
Per user per month
Okta from ~$6 (starter) to ~$17 (Essentials bundle); Cisco Duo ~$3–9; miniOrange published from ₹180; ManageEngine AD360 from ~$595 per module — which does not scale with headcount at all.
Identity Governance
Per identity — plus the implementation
Okta IGA reported ~$9–11 per user / month; Microsoft's Entra ID Governance add-on ~$4–7; the enterprise platforms quote per identity. At the deep end the services line commonly rivals the licence.
Appendix — every vendor in the category, tagged by route
  • CyberArkThe reference vault — PAM Self-Hosted and Privilege Cloud, Secrets Manager (Conjur) for machine identity, EPM, Vendor PAM, Workforce Identity, IGA; being acquired by Palo Alto Networks (announced July 2025)PAMIAMIGA
  • BeyondTrustPassword Safe (about $157 per managed asset / yr on the US GSA schedule), Endpoint Privilege Management, Privileged Remote Access, Identity Security InsightsPAM
  • ARCONIndia-built (Mumbai): PAM, EPM, My Vault, Global Remote Access, Converged Identity, Security Compliance Management — INR pricing, on-prem first, BFSI-shaped audit reportingPAMIGA
  • SecurdenIndia-built, all-inclusive per-user pricing: Unified PAM, Password Vault, Endpoint Privilege Manager, IGA, CIEM, Vendor PAM, AI Identity ManagerPAMIGA
  • One IdentitySafeguard (PAM), Cloud PAM Essentials, Identity Manager (deep enterprise IGA with SAP and mainframe), Active Roles, OneLogin, Password ManagerPAMIAMIGA
  • OktaWorkforce Identity (SSO from ~$6, Essentials ~$17 per user / mo), Adaptive MFA, Universal Directory, Customer Identity (Auth0), Privileged Access, Identity Governance, Identity Threat Protection; India tenants from 2026PAMIAMIGA
  • miniOrangeIndia-built, published from ₹180 per user / month: SSO, MFA, PAM, CIAM, Directory, Access Gateway — the widest legacy protocol support herePAMIAM
  • ManageEngineAD360 (Zoho, India-built) — SSO, MFA, self-service, provisioning and AD auditing, licensed per module from about $595 rather than per userIAMIGA
  • CiscoDuo — MFA and device trust in front of VPN, RDP and legacy applications; Essentials to Premier, roughly $3–9 per user / monthIAM
  • eMudhraIndia-built licensed certifying authority: SecurePass identity, CertiNext PKI, emSigner, DSC — certificate-based passwordless and machine identityIAM
  • InstaSafeIndia-built: MFA, Authenticator, ZTNA and zero-trust application access, quoted in INRIAM
  • FortinetFortiAuthenticator — RADIUS, SAML, certificate authority and FortiToken inside the Fortinet fabric, on an applianceIAM
  • Scalefusion · HexnodeOneIdP and Hexnode IdP — identity and conditional access bound to device trust from the UEM agent, priced inside UEM plansIAM
  • CrowdStrike · SentinelOneFalcon Identity Protection and Singularity Identity — identity threat detection and response beside the endpoint agent, not an identity providerIAM
  • RubrikIdentity Resilience — backup, comparison and object-level restore for Entra ID, Active Directory and Okta, including forest recoveryIGA
  • MicrosoftEntra ID P1 (~$6–7 per user / mo, in Microsoft 365 E3) and P2 (~$9–10, in E5, with Privileged Identity Management); Entra ID Governance add-on roughly $4–7 moreIAMIGAPAM

Five vendors span all three routes; every product on the guides is mapped by SKU, not by vendor. SailPoint, Saviynt, Ping Identity, Delinea and JumpCloud are named in the guides where relevant but have no TechBag intel pages yet, so they are not ranked. Microsoft appears in the index and in every “already own” section, but its identity SKUs are not carded on the guides.

Know your route and want it narrowed to a shortlist? That’s the next page’s job — or ours.

Talk to an advisor

Vendor-neutral · no gated content