Most PAM projects stall not because the product failed, but because nobody could get the accounts into it.

A PAM platform takes the credentials that can change or destroy everything — domain administrators, root, network gear, database owners, cloud consoles, and the service accounts no human ever logs into — out of people’s hands and into a vault that brokers, records and rotates them.

CyberArk sells the human vault and Secrets Manager separately, because an application requesting a credential ten thousand times an hour is not a person checking one out. Most estates buy the first and discover the second two years later.

Already decided — before the demo

What must be vaultedWindows, Unix, network, database, cloud, pipelines
Where it may runyour regulator decides on-prem or SaaS as often as you do
Who owns each accountthe conversation that decides the timeline

Still yours to weigh

The meterper user · per asset · per target
The machine halfsecrets, or only human checkout
Onboardingaccounts per week, honestly
If you’ve never bought one

What privileged access management actually is

A vault, a broker and a recorder. The vault holds the credentials for accounts that can change or destroy your estate, rotating them so nobody memorises one. The broker gives a named person time-limited use of an account without ever showing them the password — ideally just-in-time, so no standing privilege exists between requests. The recorder keeps a replayable record of what was done, which is the part auditors ask for.

The variable nobody prices is the machine half. Service accounts, API keys, pipeline credentials and the tokens AI agents now carry outnumber your administrators many times over, and a vault designed for humans checking credentials out is a poor fit for an application requesting one unattended, constantly. Read the IAM, SSO & MFA guide for who gets in at all, and the identity governance guide for proving the access granted was correct.

The most common mis-purchase

Endpoint privilege management bought as PAM. PEDM removes local administrator rights from laptops and elevates applications — it vaults nothing. If the audit finding was about server, database or network credentials, PEDM does not answer it, and three products on this page are PEDM.

Often confused withIAM, SSO & MFA — who gets in at all, before what they may do·Identity Governance — proving the access granted was correct·Endpoint Protection — identity threat detection sits beside the vault

The three routes of identity and access — and which one is yours

Boundary — the terms this buyer confuses

PAM vs PIM vs PEDM vs secrets management

Four terms sold by the same vendors, often in the same slide. They are adjacent scopes, not tiers — each answers a different question, and buying one for another is the most expensive mistake in this category.

PAM — privileged access management

The umbrella and the vault: store, rotate and broker credentials for accounts that can change or destroy things, record the sessions, prove it to an auditor. Answers: who used the domain admin account at 2am, and what did they do? This is the main purchase, and the one the regulators' language points at.

PIM — privileged identity management

The lifecycle of privileged identities: which accounts are privileged, who is eligible, for how long, with approval and expiry. Microsoft's Entra PIM made the term familiar — eligible rather than permanent roles, activated on request. Overlaps PAM heavily; where PAM vaults the credential, PIM governs the entitlement.

PEDM — privilege elevation and delegation management

No vault at all. An agent on the endpoint removes standing local administrator rights and elevates named applications or commands instead. Answers: how do we take admin away from laptops without breaking the software? A different budget, a different team, and three products on this page.

Secrets management

The machine half: credentials, API keys and certificates requested by applications, pipelines and containers, unattended and at machine speed. No interactive login, no session to record, no human to approve. A vault for people and a vault for code are different products — CyberArk sells both, separately, and that tells you what you need to know.

These are adjacent scopes, not tiers. PAM vaults and records, PIM governs the entitlement, PEDM elevates on the endpoint, secrets management serves machines. Most regulated estates need PAM and secrets management, many need PEDM for a separate audit finding, and PIM is often already sitting in a Microsoft licence you own. A product that handles administrators perfectly can be useless for pipelines — that is the machine-identity problem, and it is this category’s real story.
The decision variables

Six things decide this purchase. The feature grid is none of them.

Seven variables decide this purchase. The instrument tests what documentation establishes (platform coverage, secrets capability, deployment, recording, discovery, agent model, India origin); onboarding time, break-glass and storage are prose because the honest answers come from a project plan, not a datasheet.

01

Deployment model

On-premises appliance, self-hosted software, or SaaS — decided by regulator expectations as often as by preference. Indian BFSI deployments are still frequently on-prem; ask your compliance team before your architects.

02

What it can vault

Windows, Unix and Linux, network devices, databases, cloud consoles, Kubernetes, SaaS administrator accounts. Coverage varies enormously and the gap is always the system you cannot replace.

03

Session recording and playback depth

Full searchable video-grade recording, basic activity capture, or none. The audit asks for playback; the storage bill arrives separately.

04

Secrets management for applications and CI/CD

The machine-identity cut. Purpose-built brokering for pipelines and containers, credential storage that applications can call, or nothing. Several products here are genuinely thin — marked, never eliminated on.

05

Just-in-time access vs standing privilege

Whether privilege exists between requests at all. Every vendor here documents just-in-time in some form; how far it extends beyond the flagship platform is the question.

06

Agent vs agentless architecture

Agentless reaches more legacy targets with less deployment friction; agents give deeper control and offline enforcement. Most serious platforms do both.

07

Onboarding and discovery

Can it find the privileged accounts nobody told you about? Discovery is the difference between a vault holding fifty accounts and one holding the estate.

The narrowing instrument · the reasoning is the product

Narrow 17 products to your shortlist

Set what is true for you. A product that misses a constraint fades with its reason printed on it; where documentation cannot settle your case it is flagged, never removed. Every chip is reversible.

The machine half

How it must run

What it must vault

How it works

India

Estate size

Onboarding time, break-glass testing and recording storage are in the notes below, not chips — they are project realities, and no datasheet answers them honestly.

Still in17/ 17
CyberArk logo

per privileged user / year reported — the wide band is the volume curve (small deployments at the top, 1,000+ users near the floor); Self-Hosted and Privilege Cloud are separate SKUs

Large and regulated estates that want the reference vault — the deepest platform coverage, the strongest session controls, and an audit story every regulator already recognises.

The catch: The most expensive licence here and the heaviest to deploy: reported bands run to $12,000 per privileged user per year at small volumes, and the onboarding project is measured in quarters, not weeks. Secrets management for applications is a separate product (Secrets Manager), not this SKU.

Reference platformSession recordingQuarters to deploy
Intel page →
CyberArk logo

per application / per secret-consuming workload on quote; Conjur-derived, built for CI/CD pipelines, containers and application-to-application credentials

Platform and DevOps teams that need the machine half — secrets for pipelines, containers and applications, rotated and brokered without a human in the loop.

The catch: Not a human PAM product: no session recording, no privileged-user workflow. It is the second purchase alongside the vault, and it is priced and deployed as its own project.

Machine identityCI/CD + KubernetesNot human PAM
Intel page →
CyberArk logo

per endpoint / year on quote; removes local admin rights on Windows and macOS and elevates per application (PEDM), not a credential vault

Estates removing local administrator rights from laptops without breaking the applications that need elevation.

The catch: PEDM, not PAM: it elevates on the endpoint and vaults nothing. Buying it expecting a credential vault for servers and network devices is the most common mis-purchase in this category.

PEDM (endpoints)No vaultPer endpoint
Intel page →
CyberArk logo
Quote

per external vendor / year on quote; biometric-verified access for third parties with no VPN and no agent on their machine

Organisations whose auditors ask who from which supplier touched production, and when — without issuing the supplier a VPN account.

The catch: Third-party access only — your own administrators are the main PAM SKU. Priced per vendor, which is cheap at ten suppliers and not at two hundred.

Third-party accessNo VPNPer vendor
Intel page →
BeyondTrust logo
~$157₹13,031

per managed asset / year on the US GSA public-sector schedule (about $1,355 per named user / year on the same list); commercial pricing is a quote — the per-asset meter is the one to model

Estates that want a full vault with discovery and session management, and prefer paying for the machines they manage rather than the people who log in.

The catch: The per-asset meter is cheap for a few administrators over many servers and expensive the other way round; the published figures are a public-sector schedule, not a commercial list. Application secrets are handled, but this is not a CI/CD secrets platform.

Per managed assetDiscoveryGSA-listed price
Intel page →
BeyondTrust logo

per endpoint / year on quote; least privilege and application control for Windows, macOS, Linux and Unix servers (PEDM)

Estates taking local admin away across a mixed Windows, macOS and Unix fleet with application-level rules rather than blanket elevation.

The catch: PEDM again — it removes standing local admin, it does not vault credentials for network devices, databases or cloud consoles. The Unix server coverage is the differentiator against endpoint-only rivals.

PEDMUnix servers tooNo vault
Intel page →
BeyondTrust logo

per concurrent or named user / year on quote; brokered privileged sessions for insiders and vendors with full recording, no VPN

Teams whose real problem is how administrators and suppliers reach production at all — a brokered, recorded path instead of VPN plus jump box.

The catch: Access brokering with credential injection rather than a full enterprise vault: password rotation depth and discovery live in Password Safe, which is the companion purchase.

Session brokeringVendors + insidersCompanion to the vault
Intel page →
ARCON logo

per privileged user and per managed target, quoted in INR; Mumbai-built and Mumbai-supported, with reporting shaped for RBI and SEBI CSCRF audits; on-prem is the common BFSI deployment

Indian BFSI and regulated estates that want the vault, the auditor's report format and the support engineer in the same country, time zone and currency.

The catch: Deepest where its market is: platform coverage and the ecosystem of integrations are narrower than CyberArk's, and Kubernetes-native secrets for CI/CD are not its strength. Quote-only, with no public list to anchor a negotiation.

India-built (Mumbai)INR + local supportBFSI reporting
Intel page →
ARCON logo

per endpoint, quoted in INR; least privilege, application allow-listing and elevation on Windows endpoints

Indian estates extending least privilege to laptops and desktops from the same vendor that runs their server vault.

The catch: Endpoint elevation only, Windows-centric, and documented scale is smaller than the server-side product's. Not a credential vault.

PEDMWindowsINR
Intel page →
ARCON logo
Quote (INR)

per user, quoted in INR; a personal and team credential vault for business users — passwords, cards, documents — not privileged infrastructure sessions

Organisations that want employees' shared and personal business credentials in a managed vault rather than a spreadsheet.

The catch: A password manager, not PAM: no session recording, no just-in-time elevation, no discovery of privileged infrastructure accounts. It sits beside the PAM purchase, never instead of it.

Business password vaultNot infrastructure PAMINR
Intel page →
Securden logo

priced purely on the number of users — no per-target or per-connector add-ons, which is the whole pitch; quote-based, with a free Password Vault starter for up to five users

Mid-market and lean enterprise teams that want vault, session recording, discovery and remote access in one all-inclusive per-user number instead of six line items.

The catch: No public list price despite the simple meter, and documented deployments are smaller than CyberArk's or BeyondTrust's — flagged rather than ruled out above 1,000 privileged accounts. Application secrets are stored and served, but this is not a CI/CD-native secrets platform.

All-inclusive per userIndia-builtYounger at scale
Intel page →
Securden logo

per endpoint on quote; removes local admin rights and elevates named applications on Windows and macOS

Teams removing local admin from laptops on the same all-inclusive commercial model as the Securden vault.

The catch: Endpoint elevation only; no infrastructure vault. Documented scale is mid-market.

PEDMPer endpointMid-market
Intel page →
One Identity logo
Quote

per user or per asset on quote; a hardened appliance heritage with session analytics, and the tightest coupling to Identity Manager for governance-plus-PAM estates

Estates that want the vault and the governance platform from one vendor, with behavioural session analytics on privileged sessions.

The catch: Sold as an appliance-first platform with a heavier deployment than the SaaS-native options, and quote-only. Its strength is the Identity Manager pairing — standalone, it competes without that advantage.

Appliance heritageSession analyticsPairs with IGA
Intel page →
One Identity logo

per user / month on quote; SaaS-delivered session-based privileged access with recording — no appliance to rack

Mid-market teams that want brokered, recorded privileged sessions quickly, without an appliance project.

The catch: Session access rather than a full enterprise vault: no discovery, no application secrets, and documented deployments are smaller. The fuller product is Safeguard.

SaaS-onlySessions, not a full vaultFast to stand up
Intel page →
Okta logo
Bundled ~$17₹1,411

per user / month inside Okta's Essentials workforce bundle (list) rather than as a standalone vault; ties privileged server and cloud access to the Okta identity you already carry

Okta estates that want just-in-time server and cloud access governed by the same identity, policy and lifecycle as everything else.

The catch: Built for cloud and Linux/Windows server access from an Okta-centric estate: network devices, mainframes and the long tail of legacy targets that classic vaults cover are not its ground. It assumes you are already an Okta customer.

Okta-nativeJIT server accessNot for legacy targets
Intel page →
miniOrange logo
miniOrange PAMminiOrange
From ~$2.16₹179

per user / month — miniOrange publishes workforce identity from ₹180 per user per month; PAM is quoted on top and remains the cheapest entry point of the vendors here, in INR, from an India-built vendor

Cost-sensitive Indian estates that want a vault, session recording and web-application privileged access without an enterprise-scale licence or an enterprise-scale project.

The catch: The value option, and priced like one: documented deployments are smaller than the enterprise vaults', deep platform coverage (mainframe, exotic network gear) is thinner, and it is not a CI/CD secrets platform.

Lowest entry priceIndia-builtMid-market scale
Intel page →
ARCON logo

per user, quoted in INR; brokered and recorded remote privileged sessions for distributed teams and third parties, without a VPN into the network

Indian estates whose administrators and suppliers work remotely and need a recorded, controlled path into production rather than a VPN account.

The catch: Session brokering rather than a full credential vault — rotation, discovery and the enterprise workflow live in ARCON PAM, which is the companion purchase. Documented scale is smaller than the flagship.

Remote sessionsNo VPNCompanion to ARCON PAM
Intel page →
Why each constraint rules out what it doesShow the reasoning ↓

Application and pipeline secretsRules out CyberArk Endpoint Privilege Manager, CyberArk Vendor PAM, BeyondTrust Endpoint Privilege Management, BeyondTrust Privileged Remote Access, ARCON Endpoint Privilege Management, ARCON My Vault, Securden Endpoint Privilege Manager, One Identity Cloud PAM Essentials and ARCON Global Remote Access — no application or pipeline secrets capability; it vaults credentials for people. That leaves CyberArk Privileged Access Manager (Self-Hosted · Privilege Cloud), CyberArk Secrets Manager (SaaS · Self-Hosted, formerly Conjur), BeyondTrust Password Safe, ARCON Privileged Access Management, Securden Unified PAM, One Identity Safeguard, Okta Privileged Access and miniOrange PAM. It flags CyberArk Privileged Access Manager (Self-Hosted · Privilege Cloud) — Stores and serves application credentials, but is not a CI/CD-native secrets platform, BeyondTrust Password Safe — Stores and serves application credentials, but is not a CI/CD-native secrets platform, ARCON Privileged Access Management — Stores and serves application credentials, but is not a CI/CD-native secrets platform, Securden Unified PAM — Stores and serves application credentials, but is not a CI/CD-native secrets platform, One Identity Safeguard — Stores and serves application credentials, but is not a CI/CD-native secrets platform, Okta Privileged Access — Stores and serves application credentials, but is not a CI/CD-native secrets platform and miniOrange PAM — Stores and serves application credentials, but is not a CI/CD-native secrets platform — marked on the cards, not removed.

Kubernetes workloadsRules out CyberArk Privileged Access Manager (Self-Hosted · Privilege Cloud), CyberArk Endpoint Privilege Manager, CyberArk Vendor PAM, BeyondTrust Password Safe, BeyondTrust Endpoint Privilege Management, BeyondTrust Privileged Remote Access, ARCON Privileged Access Management, ARCON Endpoint Privilege Management, ARCON My Vault, Securden Unified PAM, Securden Endpoint Privilege Manager, One Identity Safeguard, One Identity Cloud PAM Essentials, Okta Privileged Access, miniOrange PAM and ARCON Global Remote Access — Kubernetes-native secrets brokering not documented. That leaves CyberArk Secrets Manager (SaaS · Self-Hosted, formerly Conjur).

On-premises deploymentRules out CyberArk Endpoint Privilege Manager, CyberArk Vendor PAM, One Identity Cloud PAM Essentials and Okta Privileged Access — SaaS only; there is no self-hosted deployment. That leaves CyberArk Privileged Access Manager (Self-Hosted · Privilege Cloud), CyberArk Secrets Manager (SaaS · Self-Hosted, formerly Conjur), BeyondTrust Password Safe, BeyondTrust Endpoint Privilege Management, BeyondTrust Privileged Remote Access, ARCON Privileged Access Management, ARCON Endpoint Privilege Management, ARCON My Vault, Securden Unified PAM, Securden Endpoint Privilege Manager, One Identity Safeguard, miniOrange PAM and ARCON Global Remote Access.

Pure SaaS deliveryRules out CyberArk Privileged Access Manager (Self-Hosted · Privilege Cloud), CyberArk Secrets Manager (SaaS · Self-Hosted, formerly Conjur), BeyondTrust Password Safe, BeyondTrust Endpoint Privilege Management, BeyondTrust Privileged Remote Access, ARCON Privileged Access Management, ARCON Endpoint Privilege Management, ARCON My Vault, Securden Unified PAM, Securden Endpoint Privilege Manager, One Identity Safeguard, miniOrange PAM and ARCON Global Remote Access — the deployment includes a self-hosted or on-premises component you run. That leaves CyberArk Endpoint Privilege Manager, CyberArk Vendor PAM, One Identity Cloud PAM Essentials and Okta Privileged Access.

Windows serversRules out CyberArk Secrets Manager (SaaS · Self-Hosted, formerly Conjur) — does not vault Windows servers or domain accounts. That leaves CyberArk Privileged Access Manager (Self-Hosted · Privilege Cloud), CyberArk Endpoint Privilege Manager, CyberArk Vendor PAM, BeyondTrust Password Safe, BeyondTrust Endpoint Privilege Management, BeyondTrust Privileged Remote Access, ARCON Privileged Access Management, ARCON Endpoint Privilege Management, ARCON My Vault, Securden Unified PAM, Securden Endpoint Privilege Manager, One Identity Safeguard, One Identity Cloud PAM Essentials, Okta Privileged Access, miniOrange PAM and ARCON Global Remote Access.

Unix and LinuxRules out CyberArk Secrets Manager (SaaS · Self-Hosted, formerly Conjur), CyberArk Endpoint Privilege Manager, ARCON Endpoint Privilege Management, ARCON My Vault and Securden Endpoint Privilege Manager — does not vault Unix / Linux accounts. That leaves CyberArk Privileged Access Manager (Self-Hosted · Privilege Cloud), CyberArk Vendor PAM, BeyondTrust Password Safe, BeyondTrust Endpoint Privilege Management, BeyondTrust Privileged Remote Access, ARCON Privileged Access Management, Securden Unified PAM, One Identity Safeguard, One Identity Cloud PAM Essentials, Okta Privileged Access, miniOrange PAM and ARCON Global Remote Access.

Network devicesRules out CyberArk Secrets Manager (SaaS · Self-Hosted, formerly Conjur), CyberArk Endpoint Privilege Manager, BeyondTrust Endpoint Privilege Management, ARCON Endpoint Privilege Management, ARCON My Vault, Securden Endpoint Privilege Manager, One Identity Cloud PAM Essentials, Okta Privileged Access and miniOrange PAM — does not vault network device credentials. That leaves CyberArk Privileged Access Manager (Self-Hosted · Privilege Cloud), CyberArk Vendor PAM, BeyondTrust Password Safe, BeyondTrust Privileged Remote Access, ARCON Privileged Access Management, Securden Unified PAM, One Identity Safeguard and ARCON Global Remote Access.

DatabasesRules out CyberArk Secrets Manager (SaaS · Self-Hosted, formerly Conjur), CyberArk Endpoint Privilege Manager, CyberArk Vendor PAM, BeyondTrust Endpoint Privilege Management, BeyondTrust Privileged Remote Access, ARCON Endpoint Privilege Management, ARCON My Vault, Securden Endpoint Privilege Manager, One Identity Cloud PAM Essentials, Okta Privileged Access and ARCON Global Remote Access — does not vault database accounts. That leaves CyberArk Privileged Access Manager (Self-Hosted · Privilege Cloud), BeyondTrust Password Safe, ARCON Privileged Access Management, Securden Unified PAM, One Identity Safeguard and miniOrange PAM.

Cloud consolesRules out CyberArk Endpoint Privilege Manager, BeyondTrust Endpoint Privilege Management, ARCON Endpoint Privilege Management, ARCON My Vault and Securden Endpoint Privilege Manager — does not vault cloud console access. That leaves CyberArk Privileged Access Manager (Self-Hosted · Privilege Cloud), CyberArk Secrets Manager (SaaS · Self-Hosted, formerly Conjur), CyberArk Vendor PAM, BeyondTrust Password Safe, BeyondTrust Privileged Remote Access, ARCON Privileged Access Management, Securden Unified PAM, One Identity Safeguard, One Identity Cloud PAM Essentials, Okta Privileged Access, miniOrange PAM and ARCON Global Remote Access.

SaaS admin accountsRules out CyberArk Secrets Manager (SaaS · Self-Hosted, formerly Conjur), CyberArk Endpoint Privilege Manager, CyberArk Vendor PAM, BeyondTrust Endpoint Privilege Management, BeyondTrust Privileged Remote Access, ARCON Privileged Access Management, ARCON Endpoint Privilege Management, Securden Endpoint Privilege Manager, One Identity Safeguard and ARCON Global Remote Access — does not vault SaaS admin accounts. That leaves CyberArk Privileged Access Manager (Self-Hosted · Privilege Cloud), BeyondTrust Password Safe, ARCON My Vault, Securden Unified PAM, One Identity Cloud PAM Essentials, Okta Privileged Access and miniOrange PAM.

Full session recordingRules out CyberArk Secrets Manager (SaaS · Self-Hosted, formerly Conjur) and ARCON My Vault — no session recording; CyberArk Endpoint Privilege Manager, BeyondTrust Endpoint Privilege Management, ARCON Endpoint Privilege Management and Securden Endpoint Privilege Manager — basic activity capture, not full session recording with playback. That leaves CyberArk Privileged Access Manager (Self-Hosted · Privilege Cloud), CyberArk Vendor PAM, BeyondTrust Password Safe, BeyondTrust Privileged Remote Access, ARCON Privileged Access Management, Securden Unified PAM, One Identity Safeguard, One Identity Cloud PAM Essentials, Okta Privileged Access, miniOrange PAM and ARCON Global Remote Access.

Account discoveryRules out CyberArk Secrets Manager (SaaS · Self-Hosted, formerly Conjur), CyberArk Endpoint Privilege Manager, CyberArk Vendor PAM, BeyondTrust Endpoint Privilege Management, BeyondTrust Privileged Remote Access, ARCON Endpoint Privilege Management, ARCON My Vault, One Identity Cloud PAM Essentials, Okta Privileged Access and ARCON Global Remote Access — no automated discovery of unknown privileged accounts. That leaves CyberArk Privileged Access Manager (Self-Hosted · Privilege Cloud), BeyondTrust Password Safe, ARCON Privileged Access Management, Securden Unified PAM, Securden Endpoint Privilege Manager, One Identity Safeguard and miniOrange PAM.

Agentless targetsRules out CyberArk Endpoint Privilege Manager, BeyondTrust Endpoint Privilege Management, ARCON Endpoint Privilege Management, Securden Endpoint Privilege Manager and Okta Privileged Access — requires an agent on the managed system. That leaves CyberArk Privileged Access Manager (Self-Hosted · Privilege Cloud), CyberArk Secrets Manager (SaaS · Self-Hosted, formerly Conjur), CyberArk Vendor PAM, BeyondTrust Password Safe, BeyondTrust Privileged Remote Access, ARCON Privileged Access Management, ARCON My Vault, Securden Unified PAM, One Identity Safeguard, One Identity Cloud PAM Essentials, miniOrange PAM and ARCON Global Remote Access.

India-built, INRRules out CyberArk Privileged Access Manager (Self-Hosted · Privilege Cloud), CyberArk Secrets Manager (SaaS · Self-Hosted, formerly Conjur), CyberArk Endpoint Privilege Manager, CyberArk Vendor PAM, BeyondTrust Password Safe, BeyondTrust Endpoint Privilege Management, BeyondTrust Privileged Remote Access, One Identity Safeguard, One Identity Cloud PAM Essentials and Okta Privileged Access — a global vendor; INR quoting is via the channel, not the vendor's own price list. That leaves ARCON Privileged Access Management, ARCON Endpoint Privilege Management, ARCON My Vault, Securden Unified PAM, Securden Endpoint Privilege Manager, miniOrange PAM and ARCON Global Remote Access.

Above 1,000 privileged accountsRules nothing out on published terms. It flags ARCON Endpoint Privilege Management — Unverified above 1,000 privileged accounts, ARCON My Vault — Unverified above 1,000 privileged accounts, Securden Unified PAM — Unverified above 1,000 privileged accounts, Securden Endpoint Privilege Manager — Unverified above 1,000 privileged accounts, One Identity Cloud PAM Essentials — Unverified above 1,000 privileged accounts, miniOrange PAM — Unverified above 1,000 privileged accounts and ARCON Global Remote Access — Unverified above 1,000 privileged accounts — marked on the cards, not removed.

Onboarding is the project, not the productEvery vendor here can vault a Windows administrator account in an afternoon. What separates them is account 1,000: the service account nobody owns, the appliance whose password is in a runbook, the application that breaks when its credential rotates. Discovery (CyberArk, BeyondTrust, ARCON, Securden, One Identity Safeguard, miniOrange) finds the accounts; agreeing who owns each one is a governance conversation with your own teams, and it is where PAM projects stall. TechBag's delivery figures for accounts onboarded per week by platform are [TechBag to confirm].

Secrets management is a different productVaulting a credential a human checks out is not the same as brokering a secret an application requests ten thousand times an hour, unattended, with no interactive login. Only CyberArk Secrets Manager on this page is a purpose-built machine-identity platform; the full vaults (CyberArk PAM, BeyondTrust, ARCON, Securden, One Identity, miniOrange, Okta) store and serve application credentials but are not CI/CD-native — marked partial, flagged, never eliminated. If your pipelines and containers are the gap, price the second product now rather than discovering it in year two.

Break-glass and the day the vault is downEvery deployment needs an emergency path when the vault, the directory or the network is unavailable — sealed credentials, an offline copy, a documented two-person procedure. Every vendor supports one; almost nobody tests it. Put the break-glass rehearsal in the implementation plan, not the runbook.

Session-recording storageFull recording produces video-scale data. Retention is a policy decision with a storage bill attached, and it is not in the licence — see the cost section. Ask for gigabytes per recorded hour and set retention before go-live, not after the first audit.

Under 50 privileged accountsRules nothing out on published terms: Securden, miniOrange, One Identity Cloud PAM Essentials and Okta Privileged Access are sold to small estates; CyberArk and BeyondTrust publish no floor but are enterprise-positioned. Where a small estate should stop at a vault and skip the full platform is delivery judgement: [TechBag to confirm].

Narrow to your situation

Eight situations, eight shortlists — with the onboarding named

Each shortlist names what the first ninety days look like, not only which product wins a feature grid. If a regulator is driving this, start from the first row.

Indian bank or NBFC — the auditor arrives and the report format matters

Why: ARCON is Mumbai-built with reporting shaped for RBI and SEBI CSCRF audits and support in the same time zone; CyberArk is the platform every regulator already recognises; Securden gives the same controls on an all-inclusive per-user number.

The trade-off: ARCON's platform breadth and CI/CD secrets are thinner than CyberArk's; CyberArk's licence and implementation are several times the cost. The regulator cares that privileged access is controlled and evidenced — not whose logo is on it.

The pipelines are the problem — credentials live in CI/CD variables and container images

Why: CyberArk Secrets Manager is the only purpose-built machine-identity platform here — pipelines, containers and application-to-application credentials brokered without a human. The full vaults store application credentials but are not CI/CD-native.

The trade-off: It is a second product with its own project and its own quote. Buying only the human vault and hoping it covers pipelines is how the machine half stays unsolved for two more years.

Few administrators, many servers

Why: BeyondTrust's per-managed-asset meter (about $157 per asset per year on the US GSA schedule) suits a small team over a large estate; Securden's per-user-only model suits the same shape from the other direction; ARCON quotes both dimensions in INR.

The trade-off: The two meters invert: per-asset is cheap for five admins over 500 servers and expensive for 200 admins over 50; per-user is the reverse. Model both on your real numbers before reading a quote.

Third parties and vendors need into production

Why: CyberArk Vendor PAM gives biometric-verified, VPN-less access priced per supplier; BeyondTrust Privileged Remote Access brokers and records the session for insiders and vendors alike.

The trade-off: Per-vendor pricing is cheap at ten suppliers and painful at two hundred; the brokered-session products price per user instead. Both beat issuing the supplier a VPN account nobody reviews.

Remove local admin rights from laptops — the audit finding everyone gets

Why: All three are PEDM: they take standing local administrator rights away and elevate named applications instead. BeyondTrust extends the same model to Unix and Linux servers.

The trade-off: None of these vaults anything. If the finding was about server, database or network credentials, PEDM does not answer it — that is the vault, and it is a separate purchase.

Already on Okta, and privileged server access is the remaining gap

Why: Okta Privileged Access puts just-in-time server and cloud access under the identity, policy and lifecycle you already run; One Identity Cloud PAM Essentials is the vendor-neutral SaaS equivalent.

The trade-off: Okta's version assumes an Okta-centric estate and does not reach network devices, mainframes or the legacy long tail. If those matter, you are buying a classic vault regardless of who runs your SSO.

Mid-market, no dedicated identity team, needs it running this quarter

Why: Securden's all-inclusive per-user pricing and miniOrange's low INR entry point (workforce identity published from ₹180 per user per month, PAM quoted on top) are the two fastest routes to a working vault; Cloud PAM Essentials needs no appliance.

The trade-off: All three are flagged unverified above 1,000 privileged accounts — not ruled out, but ask for a reference at your size before signing a three-year term.

Governance and PAM bought together, one vendor, one roadmap

Why: One Identity pairs Safeguard with Identity Manager more tightly than anyone here; CyberArk and Okta each sell governance beside the vault on one platform.

The trade-off: One platform means one negotiation and one throat to choke — and one vendor's roadmap for two disciplines that are usually run by different teams on different timelines.

The spine of the decision

Two vaults, four meters, and the accounts nobody owns

Every product here secures privilege. They differ in whose privilege — a person’s or a process’s — and in what you are billed for. Place each on both before comparing quotes.

Scope 1

The human vault

Credentials a named person checks out, brokered and recorded: domain admins, root, network gear, database owners, cloud consoles. The classic purchase, and what the regulators' language describes.

Scope 2

The machine vault

Secrets requested by applications, pipelines and containers — unattended, constantly, with no session to record. Purpose-built at CyberArk Secrets Manager; served but not CI/CD-native at the full vaults.

Scope 3

The endpoint (PEDM)

No vault: an agent removes standing local admin and elevates named applications. A separate audit finding, a separate budget, and frequently mistaken for the vault.

Scope 4

The access path

How administrators and suppliers reach production at all — brokered, recorded sessions instead of VPN and a jump box. Sold alongside the vault, sometimes instead of it.

The onboarding test

Ask these before the feature demo, in this order.

  • Show me discovery against a messy estate. Not a clean lab — how many privileged accounts does it find, and what does the list look like when nobody knows who owns half of them?
  • What happens when a rotated credential breaks an application? The answer decides whether the project reaches account 1,000 or stops at fifty.
  • How do our pipelines get their secrets? If the answer is “the same vault, via an API”, ask for a reference doing it at your request volume.
  • What is the break-glass procedure, and when was it last tested? Every vendor has one; almost no deployment has rehearsed it.

The India layer

ARCON is the India-built option — stated factually, including where it is weaker.

  • Where it is genuinely strong: built in Mumbai, quoted and supported in INR from the same time zone, with deep BFSI deployment and reporting shaped for the formats Indian auditors ask for. On-premises is a first-class deployment, not a legacy concession.
  • Where CyberArk is ahead: platform breadth, the integration ecosystem, third-party and cloud-native coverage, and a separate purpose-built secrets platform for pipelines and containers. If machine identity is your gap, that gap is real.
  • The other India-built options: Securden (all-inclusive per user) and miniOrange (the lowest entry price here, published from ₹180 per user per month for workforce identity with PAM quoted on top) — both mid-market in documented scale, both flagged rather than ruled out above 1,000 privileged accounts.
What breaks as you grow

What changes at 50, 250 and 1,000 privileged accounts

PAM scales by accounts onboarded, not licences bought. The bill follows the meter; the timeline follows how many owners you have to find.

50privileged accounts

Getting started is the constraint

  • Any product here covers it; the question is how fast it stands up. Securden, miniOrange, Cloud PAM Essentials and Okta Privileged Access reach a working vault fastest.
  • The accounts are mostly known — domain admins, a few servers, the firewall. Discovery matters less than the workflow your administrators will actually use.
  • All-inclusive per-user pricing is cheapest at this size; per-asset meters rarely are.

Put this in your PoC

Vault the domain administrator account and have someone use it through the broker for a week. If they route around it, the product is wrong or the workflow is.

250privileged accounts

Coverage and ownership are the constraint

  • Discovery finds accounts nobody claims — service accounts, appliance logins, the application credential in a config file. Each needs an owner before it can be onboarded.
  • Platform coverage starts to bite: the one legacy system, the network gear, the database that must not have its password rotated on a schedule.
  • The machine half becomes visible — pipelines and applications now hold more credentials than your administrators do.

Put this in your PoC

Ask for a named reference at your size and industry, and ask them how long onboarding actually took versus the plan.

1,000privileged accounts

The machine half and the evidence are the constraint

  • Non-human identities dominate: service accounts, pipeline credentials, cloud workload identities, agent tokens. A human-only vault is now covering a minority of what signs in.
  • Session-recording storage and retention are a real budget line; certification evidence for the regulator is a recurring process, not a report.
  • Securden, miniOrange, ARCON EPM and One Identity Cloud PAM Essentials are flagged unverified at this size — not ruled out; ask for the reference.

Put this in your PoC

Count your non-human identities and your human ones. If the first number is larger and only the second is vaulted, you have found the next project.

CyberArk, BeyondTrust, ARCON, One Identity Safeguard and Okta document large estates; Securden, miniOrange, ARCON EPM, ARCON My Vault, Securden EPM and One Identity Cloud PAM Essentials are flagged unverified above 1,000 privileged accounts. Where a specific product strains for your estate: [TechBag to confirm].

The switching cost

Leaving a PAM platform means re-onboarding every account

The vault holds credentials, workflows, approvals and years of recordings. None of it moves. Switching is the original onboarding project run a second time, with the first platform still live.

Re-onboarding

Every account is discovered, owned, connected and tested again on the new platform. The plan that took two quarters takes two quarters.

Exit costThe project, again

The recordings

Session recordings live in the old platform's format and storage. Audit and legal retention decide how long you keep it running read-only after the switch.

Exit costKeep it for retention

Integrations and connectors

Ticketing approval flows, SIEM feeds, directory joins and custom connectors are per platform and rebuilt from scratch.

Exit costRebuild and re-test

The overlap

Both vaults run until every account is migrated and rotated. Two PAM bills for two quarters is the honest cost of not leaving a gap in the control the regulator asked for.

Exit costOverlap, not a gap

Re-onboarding effort, recording retention and overlap cost for your estate: [TechBag to confirm] — TechBag scopes it from your account inventory and audit retention rules.

What it costs

Per user, per asset, or per target — the difference is often 5×

What you may already hold, the products priced on their own meters at three estate sizes in USD and INR, and what the licence line leaves out — which, for PAM, starts with the onboarding project.

01

Do you already own one?

Four places privileged control may already sit. Two are real; none is a vault for your infrastructure.

Microsoft Entra ID P2
Partly Privileged Identity Management gives eligible-not-permanent Entra and Azure roles with approval and expiry — real PIM, listed at about $9–10 per user per month. It governs Microsoft’s own roles; it vaults no server, database or network credential.
Your endpoint or UEM product
No Some remove local admin rights (PEDM territory). None vaults, brokers or records privileged infrastructure sessions.
A team password manager
No Shared credentials in a business vault — ARCON My Vault is exactly this. No rotation against the target system, no session recording, no discovery, no audit trail an auditor will accept for privileged infrastructure.
Cloud-native privilege tools
Partly AWS IAM roles, Azure PIM and GCP IAM govern privilege inside that cloud, on consumption. They stop at the cloud boundary and do not reach the data centre.

If what you own covers the accounts that actually worry your auditor, we say so. It costs us a sale and saves you one.

02

What the rest actually cost

Reported and published meters (INR for scale), worked at three estate sizes. The meters are not comparable — per privileged user, per managed asset and per target system can differ by 5× on the same estate, so each line states its own unit. The India-built and mid-market options are priced explicitly, because no other comparison does.

50 accounts · 10 adminsper year
  • CyberArk PAM(reported $1,800–12,000 per privileged user / yr; volume curve)$18,0001,20,000 ₹14,94,000₹99,60,000
  • BeyondTrust Password Safe(US GSA $157 per managed asset / yr)$7,850 ₹6,51,550
  • Okta Privileged Access(in the ~$17 / user / mo Essentials bundle list)$2,040 ₹1,69,320
  • miniOrange(workforce identity published from ₹180 / user / mo; PAM quoted on top)$259 ₹21,497
  • ARCON PAM(INR, per privileged user + per target)Quote
  • Securden Unified PAM(all-inclusive, per user)Quote
  • One Identity Safeguard(per user or per asset)Quote
  • CyberArk Secrets Manager(per application)Quote
  • BeyondTrust Privileged Remote AccessQuote
  • CyberArk Vendor PAM(per vendor)Quote
250 accounts · 40 adminsper year
  • CyberArk PAM(reported $1,800–12,000 per privileged user / yr; volume curve)$72,0004,80,000 ₹59,76,000₹3,98,40,000
  • BeyondTrust Password Safe(US GSA $157 per managed asset / yr)$39,250 ₹32,57,750
  • Okta Privileged Access(in the ~$17 / user / mo Essentials bundle list)$8,160 ₹6,77,280
  • miniOrange(workforce identity published from ₹180 / user / mo; PAM quoted on top)$1,037 ₹86,071
  • ARCON PAM(INR, per privileged user + per target)Quote
  • Securden Unified PAM(all-inclusive, per user)Quote
  • One Identity Safeguard(per user or per asset)Quote
  • CyberArk Secrets Manager(per application)Quote
  • BeyondTrust Privileged Remote AccessQuote
  • CyberArk Vendor PAM(per vendor)Quote
1,000 accounts · 120 adminsper year
  • CyberArk PAM(reported $1,800–12,000 per privileged user / yr; volume curve)$2,16,00014,40,000 ₹1,79,28,000₹11,95,20,000
  • BeyondTrust Password Safe(US GSA $157 per managed asset / yr)$1,57,000 ₹1,30,31,000
  • Okta Privileged Access(in the ~$17 / user / mo Essentials bundle list)$24,480 ₹20,31,840
  • miniOrange(workforce identity published from ₹180 / user / mo; PAM quoted on top)$3,110 ₹2,58,130
  • ARCON PAM(INR, per privileged user + per target)Quote
  • Securden Unified PAM(all-inclusive, per user)Quote
  • One Identity Safeguard(per user or per asset)Quote
  • CyberArk Secrets Manager(per application)Quote
  • BeyondTrust Privileged Remote AccessQuote
  • CyberArk Vendor PAM(per vendor)Quote

The meters, side by side — why these numbers are not comparable

Per privileged user. CyberArk, Securden, miniOrange, Okta. Cheap when a few administrators manage many machines; the bill grows with headcount, not estate. A 40-admin estate at CyberArk’s reported mid-band is a different order of magnitude from the same estate on Securden’s all-inclusive number.
Per managed asset or target. BeyondTrust (about $157 ≈ ₹13,031 per asset per year on the US GSA schedule), ARCON’s target dimension, One Identity’s asset option. Cheap for small teams over large estates; 1,000 assets is $157000 ≈ ₹1,30,31,000 a year before anything else.
Per something else entirely. Vendor PAM per supplier, Secrets Manager per application, PEDM per endpoint. Four products from one vendor can carry four meters — insist every line of a quote states its unit and its quantity.
Tier-match: the vault is not the platform. CyberArk PAM is not Secrets Manager is not EPM is not Vendor PAM — four SKUs, four projects. BeyondTrust Password Safe is not Privileged Remote Access. Price the SKU that solves the finding you actually have.
Term-match: annual, three-year, perpetual. Enterprise PAM is commonly a three-year term with the discount in year one; SaaS options quote monthly per user and bill annually. Normalise to a year before comparing, and ask what year four looks like.
The India line. ARCON quotes in INR from Mumbai; Securden and miniOrange are India-built with INR pricing through the channel; the global vendors quote USD and land in INR with GST through a partner. TechBag gives INR pricing, GST, PO cycle, minimums and tier-matched quotes.

TechBag gives INR pricing, GST, PO cycle, minimums and tier-matched quotes. The INR above is conversion for scale at ≈₹83/$; the tier-matched INR quote is ours.

03

What isn’t in the licence price

The onboarding project

Discovery, finding an owner for every account, connectors, application testing and the rotation exceptions — measured in quarters at enterprise scale and the single largest hidden number in this category. Your figure: [TechBag to confirm].

Session-recording storage

Full recording is video-scale data with a retention policy attached. It is not in the licence, it grows with adoption, and the audit that asks for playback also asks how long you keep it. Size it before go-live.

The break-glass rehearsal and the exceptions

The emergency path, tested; the application whose credential cannot rotate on a schedule; the legacy system that needs a bespoke connector. Every deployment has them, no licence includes them.

Before you commit

What goes wrong

Documented behaviour and project outcomes, cross-checked against TechBag engagements before any becomes a named case. Each is cheaper to read here than to discover in month nine.

Discovery finding thousands of accounts nobody will own

The scan succeeded and produced a list no team would claim. Onboarding stalls at the ownership conversation, not the technology — start it before the purchase order.

Break-glass procedures that were never tested

The vault, the directory or the network was down and nobody could reach the emergency credentials. Rehearse it quarterly; write down who holds what.

Session recording storage growing without a retention plan

Recording was switched on for everything; a year later storage was the largest line in the programme. Set retention by system class before go-live.

Agents that don't cover the one legacy system that mattered

The vault covered 95% of the estate and not the mainframe, the appliance or the industrial system the auditor asked about. Write the awkward list first, and test against it.

Buying PAM and never getting past the first fifty accounts

The domain admins went in and the project stopped. The remaining thousands are service accounts — which is the machine-identity problem wearing a different hat.

PEDM bought to answer a vault finding

Local admin rights were removed from laptops; the audit was about database and network credentials. Different product, different budget, same brochure vocabulary.

Rotation breaking the application nobody documented

A credential rotated on schedule and a batch job failed at 3am. Application-aware exceptions are a design decision, not a support ticket.

The pipelines never entering the vault

Human accounts are governed; CI/CD variables, container images and cloud workload identities are not. Non-human identities outnumber humans in most estates — and are usually outside the programme entirely.

Three doors — pick by where you are

Researching

See the whole landscape and where each product sits.

Identity & Access map →

Evaluating

Get your shortlist scoped against your real estate.

Scope my shortlist →

Buying

Tier-matched USD + INR quote with GST.

Get a quote →

Vendor-neutral. No gated content.