Xage Extended Privileged Access Management, or XPAM for short, redefines what PAM should deliver for the modern enterprise.
Unlike traditional PAM, Xage XPAM is simple, delivering immediate protection from day one and providing comprehensive security across every identity, account, and asset in your enterprise.
It offers comprehensive privileged account discovery and onboarding, password management, and a quantum proof, distributed secrets vault without any cloud dependency.
Here’s how it works. The Xage Fabric protects all your assets and provides secure privileged access to all your assets from day one without discovering any privileged accounts, simply by creating Zero Trust access policies between your enterprise users and assets.
On day two, XPAM allows you to discover and manage all of your privileged accounts and allows you to access your privileged systems remotely or locally using those privileged accounts without the need for any agent.
Here’s the list of all of my discovered accounts. My assets are listed under Devices. We have three types of accounts: standard, privileged, and reconcile.
With account security policies, you can define and apply tailored password rules to specific assets. This ensures security while accommodating systems with limitations, like legacy assets that may not support special characters or specific password lengths.
All of the columns here are filterable to make searching for anything a breeze.
Let me show you how to rediscover the accounts for this Dell Ubuntu 321 Linux machine using the filters to bring this up.
I see I only have two user accounts here. I know I have more user accounts on this machine and I want to discover them, so how do I do that?
To do so, I’m going to use something called an account discovery workflow.
For context, Xage has a powerful feature called Workflows, which comes in two types: Account Discovery and Password Management.
Workflows are essential for automating account onboarding and ongoing password management. The Account Discovery workflow identifies and imports accounts automatically or on demand, while the Password Management workflow handles continuous password rotation and updates, keeping these processes separate for better manageability.
To support these workflows, we use plugins. Given the wide variety of devices and protocols, plugins allow us to quickly expand support for a variety of assets.
A plugin is a packaged set of scripts, like Ansible or Python, that enables the system to interact with a device for tasks such as account discovery or password rotation.
They also allow for fine grained control, such as discovering only specific accounts based on attributes like group membership.
The best part is these plugins can be developed and deployed independently, so customers get new functionality without needing a full product upgrade.
Because I’m doing account discovery, I’m going to filter on it and select the one that applies to my device, which I can see from the Name and Devices columns here.
As you can see, this plugin includes customizable fields. In this case, it imported only the users from the sudo group, which are the two accounts we saw earlier.
While it’s possible to import all accounts, doing so could clutter the system. Instead, I’ll extend its discovery by selectively adding accounts from the general users group on the same machine.
Finally, I click Discover and watch the magic.
All of the user accounts are now here. These are part of the general users and sudo groups.
With all of the accounts discovered, I’m now going to show you how I can securely connect to this machine using this privileged account.
First, I will set the account to be privileged by selecting this discovered account and clicking Change Account Type.
Since this account was just discovered, I’ll need to change this password before storing it securely. I’ll do this by rotating the password, which is managed through the Password Management workflow in Xage. This ensures the account is fully controlled and compliant with our security policies.
I can choose to set a new password or generate a random password based on my account security policy.
Lastly, I’ll need to add this user to the account group, which my IT admin, Scott, is a part of. He will be responsible for managing all privileged accounts and can connect to this device with one of the privileged accounts.
Now I’m all set. Let’s see this in action.
I’m going to sign in as Scott into the Xage Fabric. Notice the left panel now shows both devices and accounts, demonstrating Xage’s flexibility in managing them independently.
To access the Dell Ubuntu device, Scott simply clicks Launch.
This will let him into that machine as that specific privileged user account.
Now, say Scott finishes his work. He can disconnect by closing out of this tab.
If someone needs extended access to this account, Xage’s Account Checkout feature rotates the password and restricts access to that user for a specified time, preventing others, like Scott, from using it.
Once I click Checkout, the account is exclusively checked out to me.
Scott can’t launch the SSH session until the account is available again unless I check it back in like this.
Now the account is accessible to others with the necessary permissions.
Xage provides a simpler, more effective approach to PAM that won’t eat up your entire cybersecurity budget.
The addition of PAM to today’s Xage portfolio offers you flexibility, allowing you to implement a modern approach to PAM today and grow your security and access with Xage in the future.