Your Linux team shares one root password. Nobody should need to know it — OpenText NetIQ Privileged Access Manager brokers admin sessions without revealing the password and judges every command by user, host and time, recording keystrokes and video — self-hosted on a perpetual licence or, since March 2026, as SaaS.
Buy through TechBag
Same software. Better outcome — at a lower cost.
How it’s rated
Full scoreboard ↓Quick answer
This page covers OpenText NetIQ Privileged Access Manager — the privileged access product, self-hosted or SaaS. The rest:
Most product pages skip this. We start here — so you buy a capability, not a buzzword.
It keeps admin and root passwords in a vault and lets people use them without ever seeing them, with every session recorded.
What consolidation actually replaces, dimension by dimension.
| Dimension | A shared root password | OpenText NetIQ Privileged Access Manager |
|---|---|---|
| Who knows the root password | Every admin on the team | No one; the broker injects it |
| What an admin may run | Anything, once logged in as root | Commands allowed by user, host and time |
| A risky command | Noticed after the damage | Blocked, and its user barred from sessions |
| Evidence for the auditor | Shell history, if it survived | Keystrokes, screenshots and session video |
| Rights for a leaver | Removed when someone remembers | Changed through the Identity Manager driver |
| What it is NOT | — | A CI/CD secrets platform or a public price list |
The cheapest test is twenty servers: vault their local admins, broker the sessions, block one risky command and read the recordings.
Vendors love diagrams; buyers need to know what they’re actually operating. Here’s the whole platform, demystified.
Accounts found by discovery on Windows hosts and over SSH are onboarded into the Credential Vault, which checks credentials out, rotates them on schedule and checks them back in.
Sessions run through web or native SSH and RDP relays, so the administrator never types the target password; web RDP needs resources only on the manager, none on the target.
Agents apply Access Control policy at the host: who the user is, what command they type, on which host and at what time. Agentless SSH sessions are also supported.
Keystrokes, screenshots and session videos land in the audit store; OpenText advises a separate Video Offloading Server so recording does not load the agent or manager.
A vault, session relays and host agents under one policy engine — self-hosted on a perpetual licence or run as OpenText SaaS.
OpenText NetIQ Privileged Access Manager lets admins use root and administrator rights without ever holding the passwords.
Discover and Onboard reads local privileged accounts on Windows hosts and on Linux or UNIX over SSH, then moves them into the vault.
Vaulted credentials rotate on a schedule set by policy; Grupo Arcor resets each password within eight hours at most, by its own account.
Web RDP and SSH sessions open through the broker, encrypted end to end, so an admin works on the server without ever seeing its password.
Rules weigh the user, the typed command, the host and the time, so root can be delegated one command at a time instead of whole.
Commands carry risk levels; since release 4.5 a high-risk command can be blocked outright and the user who ran it barred from new sessions.
An admin requests access to a Linux or Windows server, an approver signs it off, and the right lapses afterwards, with no standing admin.
Each session keeps typed commands, screenshots and video; OpenText sizes video at about 200 KB a minute idle and 1 MB a minute busy.
Security staff can monitor a live privileged session and see each command as it is typed, rather than reading the log the next morning.
Prebuilt reports cover sessions, disconnected sessions and change logs; audit rules can generate custom reports for each regulation.
The first SaaS release (25.4), SSH and RDP session control, just-in-time access and the audit reports. All from OpenText’s official NetIQ channel, recorded in 2026.
What the first SaaS release brings: web RDP and SSH sessions, discovery and onboarding, reports and the vault.
Discovering servers, vaulting SSH keys and RDP passwords, then brokering and logging the sessions.
The request-and-approve flow for time-bound access to a Linux or Windows server.
The reports and audit trail an administrator hands to compliance after the sessions are done.
Want a live, India-context walkthrough for your environment?
Book a guided demo →Here’s what genuinely sets it apart — and exactly where it stops.
Most vaults hand out a whole password. Here policies judge the user, the exact command, the host and the hour, and a high-risk command can be blocked and its user barred from new sessions. Where a Linux team shares root, that is finer control than checkout alone.
OpenText still sells the self-hosted product on a perpetual licence, now rare in PAM, and since March 2026 also as SaaS on Core Identity Foundation with a 99.9% uptime objective. A bank keeping the vault in its own Indian data centre and a firm wanting nothing to run buy the same product.
A PAM driver ships with Identity Manager 4.9, so joiners and leavers change privileged rights too, and Advanced Authentication can add a second factor at session start. Release 4.5.0.0 holds a Common Criteria EAL2+ certificate valid to April 2030, useful in a regulated tender.
No public price, no Gartner PAM placement, no published SaaS region. The SaaS edition is young: 25.4 discovers local accounts on Windows and SSH hosts only. CVE-2024-12111, an LDAP injection sign-in bypass (CVSS 8.0), hit releases 4.4 and 4.5. Nor is it a CI/CD secrets platform.
List shared root, domain admin and service accounts on Windows, Linux and UNIX, and who uses each one in a normal week.
Decide whether the vault must stay in your Indian data centre on a perpetual licence, or can run as the SaaS service.
Discover and onboard local admins on a few Linux and Windows hosts, broker sessions through the relays and record them.
Model who may run which commands where and when, mark risky commands, and switch on blocking for the high-risk ones.
Connect the Identity Manager driver and second-factor login, size video storage, and hand the first report to audit.
Modelled on Gartner Peer Insights structure. *Counts and breakdowns are illustrative pending verified review collection.
“Our Linux team no longer shares the root password. Each admin gets the commands their role needs, and nothing more.”
“We already ran NetIQ Identity Manager, so the PAM driver let leavers lose their server rights the day HR closed them.”
“The auditor asked who ran a delete on the billing database last quarter. We had the keystrokes and video within minutes.”
“Plan storage for video early. Our busy RDP sessions recorded far more per minute than we budgeted for at first.”
“Blocking risky commands is the feature we use most; a junior admin cannot run a recursive delete as root any more.”
“Policies are powerful but slow to model at first, and the quote took several rounds. Budget for partner help.”
Analyst firms bury this view behind paywalls, and G2 retired its Grid. So here’s TechBag’s synthesis of the privileged access management market — tap any vendor to see why it sits where it does.
Execution strength vs product vision — the classic market map, minus the paywall.
Quote-only; perpetual self-hosted licence or a paid SaaS option.
The grid nobody publishes — how many ways the vault can run and where its data can sit, India included, vs how finely it controls and records a privileged session.
Perpetual or SaaS; per-command rules, keystrokes and video.
Positions are TechBag’s illustrative synthesis of public review-platform data and vendor documentation — not a reproduction of any analyst graphic. Verify before relying on it.
Against CyberArk Privileged Access Manager, BeyondTrust Password Safe, ARCON PAM, Securden Unified PAM and Devolutions PAM — on deployment, systems covered, price, recording, governance, support and India.
| Dimension | OpenText NetIQ Privileged Access Manager | CyberArk Privileged Access Manager | BeyondTrust Password Safe | ARCON Privileged Access Management | Securden Unified PAM | Devolutions PAM |
|---|---|---|---|---|---|---|
| What it is | Vault + command policy | The category reference | BeyondTrust’s vault | Mumbai-built suite | All-in-one PAM | Module in a package |
| Deployment | Perpetual or SaaS | Self-hosted or cloud | Appliance or Azure | On-prem or SaaS | On-prem or SaaS | Own server or Cloud |
| Systems covered | Windows, Linux, UNIX | Widest target list | Servers, cloud, apps | Servers, network, DBs | Servers, network, DBs | Wide; some reset-only |
| Pricing model | Quoted per deal | Per privileged user | Per managed asset | Per user and target | PAM users only | Per named user |
| Published entry price | Not published | Reported $1,800+/user | ~$157/asset/yr (GSA) | Quote only | Quote; free vault tier | $50/user/month |
| Included vs add-on | SaaS PAM is extra | Secrets sold apart | Premium cloud SKU | EPM, remote apart | EPM and vendor extra | All in the package |
| Scale and standing | No PAM analyst rank | MQ Leader, ~9k customers | MQ Leader, 7th time | 1,500+ organisations | Younger at scale | No MQ; KC Rated |
| Recording and security | Keystrokes and video | Isolated, recorded | Keystrokes, SOC 2 | Monitored sessions | Video and keystrokes | Video, no search |
| Integrations | NetIQ stack first | Largest ecosystem | IdP, SIEM, ServiceNow | 300+ integrations | SDKs, Azure Key Vault | Opens rival vaults |
| Governance and JIT | Who/what/where/when | JIT, least privilege | Approved, time-bound | Approvals, JIT, MFA | Request and release | Checkout approval |
| India storage | Self-host; SaaS unstated | Indian data centre | Azure Central India | On-prem; SaaS: ask | On-prem; SaaS unstated | Self-host only |
| Support | 99.9% SaaS objective | Set in the contract | Not published | Same time zone | Phone lines listed | 48 h standard |
| Lock-in and exit | Perpetual right to run | Deep, slow to leave | Cloud videos stay put | No public anchor | Cancel and refund | Yearly, reads rivals |
| Best fit | NetIQ, UNIX-heavy shops | Large, regulated estates | Few admins, many hosts | Indian BFSI | Mid-market, one meter | RDM teams, small IT |
Honest fit signals — because the fastest way to lose your trust is to pretend one product wins every scenario.
OpenText NetIQ Privileged Access Manager is one of 29 privileged access management products TechBag carries. The Privileged Access Management guide narrows them to a shortlist and shows the reasoning. →
Drag the sliders (privileged accounts you manage; IT staff-hour cost). Estimates model the staff time spent changing shared passwords, granting access by hand and assembling audit evidence, at an assumed 1.5 hours per privileged account a year, with 70% of it saved by vaulting, brokered sessions and recorded audit trails. Both figures are assumptions. Illustrative.
Loaded cost = salary + overheads per productive hour. Illustrative only — your TechBag quote models your actual environment and modules.
Quote only. OpenText publishes no price for Privileged Access Manager. The self-hosted product is sold on a perpetual licence, and the SaaS edition is listed as an optional, paid service on top of an OpenText Core Identity Foundation subscription. OpenText shows no rupee price and names no Indian distributor. TechBag counts your privileged accounts and target hosts first, then returns an itemised quote in INR with GST.
Best when the vault must stay in your own data centre
Best for a broader rollout
Best when you want nothing to run yourself
Whatever the list prices above, TechBag negotiates a significantly better deal — with GST-compliant INR invoicing and local support. Ask us for your discounted quote.
Tell us your requirements and current tools — we’ll model it against what you spend today.
Take this into your next vendor call — including ours.
Self-hosted on a perpetual licence or the SaaS service? Ask what each includes and how a later move works.
Are all targets Windows, Linux or UNIX hosts? Databases, network gear and SaaS consoles need checking.
Will SaaS discovery, which covers local accounts on Windows and SSH hosts in 25.4, find the accounts you own?
Who will model per-command rules by user, host and time, and how many roles will the first wave need?
How much video will you keep? Busy sessions record up to about 1 MB a minute; plan the storage and retention.
If SaaS, which region holds the vault and recordings? Get it in writing, since no region is published.
Which release will you run? CVE-2024-12111 affected 4.4 and 4.5; confirm the fixed build before go-live.
What is the metric — users, targets or both — and is maintenance quoted? Ask for INR with GST and terms.
Count your shared root and admin accounts first, or let a TechBag advisor choose the edition, pilot it on your own servers and return an itemised rupee quote.
Stats, ratings, review counts and pricing are illustrative and sourced from public materials; verify before purchase.