Talk to us
by OpenTextTechBag Intel Page

OpenText NetIQ Privileged Access Manager

Your Linux team shares one root password. Nobody should need to know it — OpenText NetIQ Privileged Access Manager brokers admin sessions without revealing the password and judges every command by user, host and time, recording keystrokes and video — self-hosted on a perpetual licence or, since March 2026, as SaaS.

Per-command rules by user, host and timePerpetual self-hosted or SaaSQuote-only, no public price

Buy through TechBag

Same software. Better outcome — at a lower cost.

Right-fit discoveryBest price & discountsImplementation & rolloutRenewals & licence mgmtTier-1 support desk
Book a discovery call →

Free · 15 minutes

Trusted by 500+ enterprises across India

How it’s rated

Full scoreboard ↓
Pricing
OpenText prints no price for either edition; the self-hosted product is still sold on a perpetual licence
Quote
SaaS uptime
The Core Identity Foundation service description sets a 99.9% availability objective, measured quarterly
99.9% target
Analysts
OpenText claims no Gartner or KuppingerCole PAM placement for this product; its IGA rating is a separate report
No PAM rank
India
Host the vault yourself inside India; OpenText publishes no hosting region for the SaaS edition
Self-host

Quick answer

OpenText NetIQ Privileged Access Manager, formerly NetIQ Privileged Account Manager, ends the sharing of root and administrator passwords: policies on user, command, host and time decide what each admin may run on Windows, Linux and UNIX, and sessions are brokered, keystroke-logged and recorded. It runs self-hosted on a perpetual licence or, since the 25.4 release of March 2026, as SaaS. Pricing is quote-only. Read more ↓ Show less ↑
Part 01 · Orient

The OpenText platform family

This page covers OpenText NetIQ Privileged Access Manager — the privileged access product, self-hosted or SaaS. The rest:

OpenText Content Management
Enterprise content management, formerly Extended ECM.
View page →
OpenText Fortify
Application security testing: SAST, DAST and SCA.
View page →
NetIQ Identity Governance
Access reviews, provisioning and identity lifecycle.
View page →
NetIQ Access Manager
Single sign-on, federation and adaptive MFA.
View page →
NetIQ Privileged Access Manager
This page.
You’re here
OpenText Voltage SecureData
Format-preserving encryption and tokenisation.
View page →
OpenText Enterprise Security Manager
Real-time SIEM correlation, formerly ArcSight.
View page →
OpenText Service Management
ITSM and asset management, formerly SMAX.
View page →
OpenText AI Operations Management
Event and performance monitoring, formerly Operations Bridge.
View page →
OpenText ZENworks
Endpoint management, patching and disk encryption.
View page →
OpenText Data Protector
Enterprise backup for servers, VMs and applications.
View page →
OpenText Availability
Real-time replication and failover, formerly Carbonite.
View page →
OpenText Cloudally Backup
Microsoft 365, Google, Salesforce, Box and Dropbox backup.
View page →
OpenText Performance Engineering
Load and performance testing, formerly LoadRunner.
View page →
OpenText Functional Testing
Automated functional testing, formerly UFT One.
View page →
OpenText Core Endpoint Protection
Cloud endpoint security for SMBs and MSPs, ex-Webroot.
View page →
OpenText Core DNS Protection
DNS filtering for SMBs and MSPs, ex-Webroot.
View page →
OpenText Core Email Threat Protection
Email security and encryption, ex-Zix.
View page →

Quick facts

30-second orientation
Product
Privileged session brokering, credential vault and command-level policy for Windows, Linux and UNIX
Maker
OpenText (Open Text Corporation), headquartered in Waterloo, Canada; Ayman Antoun has been CEO from 20 April 2026
Former name
NetIQ Privileged Account Manager, renamed Privileged Access Manager in release 4.5 (July 2024)
Editions
Self-hosted with a perpetual licence, or the SaaS service, first released as 25.4 in March 2026
Price
Not published; quoted. The SaaS edition is a paid option on OpenText Core Identity Foundation
Sessions
Web RDP and SSH brokered without revealing the password; keystrokes, screenshots and video kept
Assurance
Release 4.5.0.0 holds a Common Criteria EAL2+ certificate (Sweden), valid April 2025 to 2030
Analysts
No Gartner PAM Magic Quadrant placement; the KuppingerCole Leader result OpenText cites is for IGA
India
Self-host it in your own data centre; the SaaS edition publishes no hosting region, so ask
In India via
TechBag — account count, a rupee quote with GST, and a pilot on your own Linux and Windows hosts
Part 02 · Learn

Understand privileged access before you choose a PAM product

Most product pages skip this. We start here — so you buy a capability, not a buzzword.

What is privileged access management?

It keeps admin and root passwords in a vault and lets people use them without ever seeing them, with every session recorded.

A shared root password vs OpenText NetIQ PAM — the honest table

What consolidation actually replaces, dimension by dimension.

DimensionA shared root passwordOpenText NetIQ Privileged Access Manager
Who knows the root passwordEvery admin on the teamNo one; the broker injects it
What an admin may runAnything, once logged in as rootCommands allowed by user, host and time
A risky commandNoticed after the damageBlocked, and its user barred from sessions
Evidence for the auditorShell history, if it survivedKeystrokes, screenshots and session video
Rights for a leaverRemoved when someone remembersChanged through the Identity Manager driver
What it is NOT—A CI/CD secrets platform or a public price list

The cheapest test is twenty servers: vault their local admins, broker the sessions, block one risky command and read the recordings.

Under the hood

The five pieces of the platform

Vendors love diagrams; buyers need to know what they’re actually operating. Here’s the whole platform, demystified.

01
Where privileged passwords and keys live

Vault

Credential Vault

Accounts found by discovery on Windows hosts and over SSH are onboarded into the Credential Vault, which checks credentials out, rotates them on schedule and checks them back in.

02
How admins reach a server

Relays

SSH and RDP relay managers

Sessions run through web or native SSH and RDP relays, so the administrator never types the target password; web RDP needs resources only on the manager, none on the target.

03
Where commands are judged

Agents

Host agents on Windows, Linux and UNIX

Agents apply Access Control policy at the host: who the user is, what command they type, on which host and at what time. Agentless SSH sessions are also supported.

04
Where the evidence is kept

Audit

Audit Manager and Video Offloading Server

Keystrokes, screenshots and session videos land in the audit store; OpenText advises a separate Video Offloading Server so recording does not load the agent or manager.

A vault, session relays and host agents under one policy engine — self-hosted on a perpetual licence or run as OpenText SaaS.

Part 03 · Evaluate

Nine capabilities. Vault, control, audit.

OpenText NetIQ Privileged Access Manager lets admins use root and administrator rights without ever holding the passwords.

Vault
Discovery

Find the local admins first

Discover and Onboard reads local privileged accounts on Windows hosts and on Linux or UNIX over SSH, then moves them into the vault.

Vault
Rotation

Passwords that expire on use

Vaulted credentials rotate on a schedule set by policy; Grupo Arcor resets each password within eight hours at most, by its own account.

Vault
Passwordless

Sessions without the secret

Web RDP and SSH sessions open through the broker, encrypted end to end, so an admin works on the server without ever seeing its password.

Control
Access Control

Who, what, where, when

Rules weigh the user, the typed command, the host and the time, so root can be delegated one command at a time instead of whole.

Control
Command risk

Block the dangerous command

Commands carry risk levels; since release 4.5 a high-risk command can be blocked outright and the user who ran it barred from new sessions.

Control
Just-in-time

Rights only when approved

An admin requests access to a Linux or Windows server, an approver signs it off, and the right lapses afterwards, with no standing admin.

Audit
Recording

Keystrokes, screens and video

Each session keeps typed commands, screenshots and video; OpenText sizes video at about 200 KB a minute idle and 1 MB a minute busy.

Audit
Live watch

Watch a session as it runs

Security staff can monitor a live privileged session and see each command as it is typed, rather than reading the log the next morning.

Audit
Reports

Evidence an auditor can read

Prebuilt reports cover sessions, disconnected sessions and change logs; audit rules can generate custom reports for each regulation.

See it, don’t just read it

Watch OpenText NetIQ PAM in action

The first SaaS release (25.4), SSH and RDP session control, just-in-time access and the audit reports. All from OpenText’s official NetIQ channel, recorded in 2026.

OpenText NetIQ (official)·Overview, March 2026

OpenText Privileged Access Manager 25.4 | First SaaS Release Overview (2026)

What the first SaaS release brings: web RDP and SSH sessions, discovery and onboarding, reports and the vault.

OpenText NetIQ (official)·Demo, February 2026

SSH & RDP Session Control using OpenText NetIQ Privileged Access Manager (PAM)

Discovering servers, vaulting SSH keys and RDP passwords, then brokering and logging the sessions.

OpenText NetIQ (official)·Demo, February 2026

Just-in-time (JIT) access demo | OpenText Privileged Access Manager

The request-and-approve flow for time-bound access to a Linux or Windows server.

OpenText NetIQ (official)·Overview, March 2026

Auditing privileged access | Overview of OpenText Privileged Access Manager’s auditing capabilities

The reports and audit trail an administrator hands to compliance after the sessions are done.

Want a live, India-context walkthrough for your environment?

Book a guided demo →
Why OpenText NetIQ Privileged Access Manager

Shared root is a breach waiting for a name. NetIQ PAM lets admins work without holding it.

Here’s what genuinely sets it apart — and exactly where it stops.

01

Delegate root one command at a time

Most vaults hand out a whole password. Here policies judge the user, the exact command, the host and the hour, and a high-risk command can be blocked and its user barred from new sessions. Where a Linux team shares root, that is finer control than checkout alone.

02

Own it outright, or rent it

OpenText still sells the self-hosted product on a perpetual licence, now rare in PAM, and since March 2026 also as SaaS on Core Identity Foundation with a 99.9% uptime objective. A bank keeping the vault in its own Indian data centre and a firm wanting nothing to run buy the same product.

03

Sits inside the NetIQ identity stack

A PAM driver ships with Identity Manager 4.9, so joiners and leavers change privileged rights too, and Advanced Authentication can add a second factor at session start. Release 4.5.0.0 holds a Common Criteria EAL2+ certificate valid to April 2030, useful in a regulated tender.

04

Where it stops

No public price, no Gartner PAM placement, no published SaaS region. The SaaS edition is young: 25.4 discovers local accounts on Windows and SSH hosts only. CVE-2024-12111, an LDAP injection sign-in bypass (CVSS 8.0), hit releases 4.4 and 4.5. Nor is it a CI/CD secrets platform.

The idea
Delegate root one command at a time
The choice
Perpetual self-hosted or SaaS since 2026
The price
Quote-only; no public list
Proof, not promises

The numbers behind the platform

50%
less time to grant an access request at Grupo Arcor, according to its CISO on OpenText’s page
— Customer
30%
faster onboarding reported by Procomix Technology Group after moving access requests to self-service
— Customer
8 hours
the longest a privileged password lives at Grupo Arcor before PAM resets it
— Customer
25 sessions
concurrent web RDP sessions per CPU core and 2 GB of RAM in OpenText’s sizing guide
— Vendor
24 hours
the recovery-time objective the SaaS service description sets for a region-wide disaster
— Vendor
2030
the year the Common Criteria EAL2+ certificate for release 4.5.0.0 runs until (April)
— Certification

What your OpenText NetIQ PAM rollout looks like

Week 1Model

Count who holds root today

List shared root, domain admin and service accounts on Windows, Linux and UNIX, and who uses each one in a normal week.

Week 2Decide

Choose perpetual or SaaS

Decide whether the vault must stay in your Indian data centre on a perpetual licence, or can run as the SaaS service.

Week 4Pilot

Pilot on twenty servers

Discover and onboard local admins on a few Linux and Windows hosts, broker sessions through the relays and record them.

Month 2Prove

Write the command rules

Model who may run which commands where and when, mark risky commands, and switch on blocking for the high-risk ones.

Month 3Commit

Wire it to identity and audit

Connect the Identity Manager driver and second-factor login, size video storage, and hand the first report to audit.

Verified reviews

The review scoreboard

Modelled on Gartner Peer Insights structure. *Counts and breakdowns are illustrative pending verified review collection.

3.9
38+ reviews*
76% would recommend
Command-level control4.4
Session recording4.2
Identity stack fit4.1
Ease of setup3.4
Value for money3.6
5★
34%
4★
40%
3★
17%
2★
6%
1★
3%

Quick poll — what’s driving your evaluation?

Talk to an advisor
BFSI
“Our Linux team no longer shares the root password. Each admin gets the commands their role needs, and nothing more.”
UNIX Systems Lead
BFSI
Telecom
“We already ran NetIQ Identity Manager, so the PAM driver let leavers lose their server rights the day HR closed them.”
IAM Architect
Telecom
Insurance
“The auditor asked who ran a delete on the billing database last quarter. We had the keystrokes and video within minutes.”
IT Risk Manager
Insurance
Manufacturing
“Plan storage for video early. Our busy RDP sessions recorded far more per minute than we budgeted for at first.”
Infrastructure Engineer
Manufacturing
Healthcare
“Blocking risky commands is the feature we use most; a junior admin cannot run a recursive delete as root any more.”
Security Operations Lead
Healthcare
Retail
“Policies are powerful but slow to model at first, and the quote took several rounds. Budget for partner help.”
Head of IT Security
Retail
The market maps

Where everyone sits — the grids

Analyst firms bury this view behind paywalls, and G2 retired its Grid. So here’s TechBag’s synthesis of the privileged access management market — tap any vendor to see why it sits where it does.

Grid 01 · The market

TechBag Privileged Access Grid

Execution strength vs product vision — the classic market map, minus the paywall.

ChallengersLeadersSpecialistsVisionaries
OpenText NetIQ Privileged Access ManagerThis page

Quote-only; perpetual self-hosted licence or a paid SaaS option.

Grid 02 · The architecture

Deployment Choice × Session Control

The grid nobody publishes — how many ways the vault can run and where its data can sit, India included, vs how finely it controls and records a privileged session.

Deep but one way to runDeep and flexibleLight with few optionsFlexible but light
OpenText NetIQ Privileged Access ManagerThis page

Perpetual or SaaS; per-command rules, keystrokes and video.

Positions are TechBag’s illustrative synthesis of public review-platform data and vendor documentation — not a reproduction of any analyst graphic. Verify before relying on it.

Part 04 · Decide

OpenText NetIQ PAM vs the privileged access field

Against CyberArk Privileged Access Manager, BeyondTrust Password Safe, ARCON PAM, Securden Unified PAM and Devolutions PAM — on deployment, systems covered, price, recording, governance, support and India.

DimensionOpenText NetIQ Privileged Access ManagerCyberArk Privileged Access ManagerBeyondTrust Password SafeARCON Privileged Access ManagementSecurden Unified PAMDevolutions PAM
What it isVault + command policyThe category referenceBeyondTrust’s vaultMumbai-built suiteAll-in-one PAMModule in a package
DeploymentPerpetual or SaaSSelf-hosted or cloudAppliance or AzureOn-prem or SaaSOn-prem or SaaSOwn server or Cloud
Systems coveredWindows, Linux, UNIXWidest target listServers, cloud, appsServers, network, DBsServers, network, DBsWide; some reset-only
Pricing modelQuoted per dealPer privileged userPer managed assetPer user and targetPAM users onlyPer named user
Published entry priceNot publishedReported $1,800+/user~$157/asset/yr (GSA)Quote onlyQuote; free vault tier$50/user/month
Included vs add-onSaaS PAM is extraSecrets sold apartPremium cloud SKUEPM, remote apartEPM and vendor extraAll in the package
Scale and standingNo PAM analyst rankMQ Leader, ~9k customersMQ Leader, 7th time1,500+ organisationsYounger at scaleNo MQ; KC Rated
Recording and securityKeystrokes and videoIsolated, recordedKeystrokes, SOC 2Monitored sessionsVideo and keystrokesVideo, no search
IntegrationsNetIQ stack firstLargest ecosystemIdP, SIEM, ServiceNow300+ integrationsSDKs, Azure Key VaultOpens rival vaults
Governance and JITWho/what/where/whenJIT, least privilegeApproved, time-boundApprovals, JIT, MFARequest and releaseCheckout approval
India storageSelf-host; SaaS unstatedIndian data centreAzure Central IndiaOn-prem; SaaS: askOn-prem; SaaS unstatedSelf-host only
Support99.9% SaaS objectiveSet in the contractNot publishedSame time zonePhone lines listed48 h standard
Lock-in and exitPerpetual right to runDeep, slow to leaveCloud videos stay putNo public anchorCancel and refundYearly, reads rivals
Best fitNetIQ, UNIX-heavy shopsLarge, regulated estatesFew admins, many hostsIndian BFSIMid-market, one meterRDM teams, small IT
● Strong◐ Partial / add-on○ Weak / externalCompiled from public vendor materials and review platforms for orientation; verify before relying on it.

Which approach fits you?

Honest fit signals — because the fastest way to lose your trust is to pretend one product wins every scenario.

Choose OpenText NetIQ PAM if…

  • ✓Your UNIX and Linux admins share root and you want to allow commands one by one, by user, host and time
  • ✓You already run NetIQ Identity Manager or Advanced Authentication and want privileged rights in the same lifecycle
  • ✓You want to own a perpetual licence and keep the vault in your own Indian data centre, or rent it as SaaS later

Compare alternatives if…

  • ✓You need the vault every auditor recognises and the widest target list — CyberArk and BeyondTrust are the reference points
  • ✓You want a vendor and support team in India quoting in rupees — ARCON is Mumbai-built and Securden is India-built
  • ✓You want a price before the first call — Devolutions lists $50 a month for each named user, paid annually

Do not expect…

  • ✓A published price or an INR rate card from OpenText
  • ✓A Gartner or KuppingerCole PAM ranking for this product
  • ✓A named hosting region for the SaaS edition, or a CI/CD secrets platform

OpenText NetIQ Privileged Access Manager is one of 29 privileged access management products TechBag carries. The Privileged Access Management guide narrows them to a shortlist and shows the reasoning. →

Do the math

What does hand-run privileged access cost you?

Drag the sliders (privileged accounts you manage; IT staff-hour cost). Estimates model the staff time spent changing shared passwords, granting access by hand and assembling audit evidence, at an assumed 1.5 hours per privileged account a year, with 70% of it saved by vaulting, brokered sessions and recorded audit trails. Both figures are assumptions. Illustrative.

300
2510,000
₹800
₹300₹2,000

Loaded cost = salary + overheads per productive hour. Illustrative only — your TechBag quote models your actual environment and modules.

Current annual privileged-access admin cost
₹3,60,000
Estimated annual savings
₹2,52,000
≈ ₹12,60,000 over 5 years
Turn this into a real quote →
Pricing & plans

Three ways to consume it

Quote only. OpenText publishes no price for Privileged Access Manager. The self-hosted product is sold on a perpetual licence, and the SaaS edition is listed as an optional, paid service on top of an OpenText Core Identity Foundation subscription. OpenText shows no rupee price and names no Indian distributor. TechBag counts your privileged accounts and target hosts first, then returns an itemised quote in INR with GST.

Self-hosted (perpetual)

Best when the vault must stay in your own data centre

  • Perpetual licence, quoted
  • Agents, relays and audit store you run
  • Keystrokes, screenshots and video

+ Platform add-ons

Best for a broader rollout

  • Scoped to your estate
  • Add-on modules as needed
  • Phased, right-sized deployment

SaaS on Core Identity Foundation

Best when you want nothing to run yourself

  • Paid option on Core Identity Foundation
  • 99.9% uptime objective, runs on AWS
  • Hosting region: ask before you sign

Buy it for less — TechBag pricing beats list

Whatever the list prices above, TechBag negotiates a significantly better deal — with GST-compliant INR invoicing and local support. Ask us for your discounted quote.

Get a discounted quote →

Get an India-ready quote

Tell us your requirements and current tools — we’ll model it against what you spend today.

Get Quote
Evaluation kit

The 8 questions to ask every vendor

Take this into your next vendor call — including ours.

1
Edition

Self-hosted on a perpetual licence or the SaaS service? Ask what each includes and how a later move works.

2
Targets

Are all targets Windows, Linux or UNIX hosts? Databases, network gear and SaaS consoles need checking.

3
Discovery

Will SaaS discovery, which covers local accounts on Windows and SSH hosts in 25.4, find the accounts you own?

4
Command rules

Who will model per-command rules by user, host and time, and how many roles will the first wave need?

5
Recording

How much video will you keep? Busy sessions record up to about 1 MB a minute; plan the storage and retention.

6
Hosting

If SaaS, which region holds the vault and recordings? Get it in writing, since no region is published.

7
Patching

Which release will you run? CVE-2024-12111 affected 4.4 and 4.5; confirm the fixed build before go-live.

8
Licence

What is the metric — users, targets or both — and is maintenance quoted? Ask for INR with GST and terms.

FAQ

Questions buyers ask

It is OpenText’s privileged access product, formerly NetIQ Privileged Account Manager. It vaults admin passwords and keys, brokers RDP and SSH sessions so admins never see them, applies rules on user, command, host and time, and records keystrokes, screens and video for Windows, Linux and UNIX.

Ready to evaluate OpenText NetIQ PAM?

Count your shared root and admin accounts first, or let a TechBag advisor choose the edition, pilot it on your own servers and return an itemised rupee quote.

Stats, ratings, review counts and pricing are illustrative and sourced from public materials; verify before purchase.