Discover and classify privileged human and service accounts across on-premises and cloud environments.
Privileged Access Management and Session Recording Controls
Design a privileged access management programme that vaults credentials, enforces just-in-time elevation, and records privileged sessions for audit and forensic review.
Course Overview
Privileged accounts, whether held by system administrators, database owners or automated service processes, remain the single most valuable target in most breaches because compromising one grants an attacker the keys to everything downstream. This course teaches you to design and operate a privileged access management programme rather than simply deploy a vaulting product. You will discover and classify every privileged and service account across an estate, move standing access to just-in-time elevation approved through a workflow, and vault credentials so they are checked out, rotated and never known to the end user in plain text. Sessions cover configuring session recording and keystroke logging for high-risk access, building break-glass procedures for emergencies, and reviewing recorded sessions efficiently rather than drowning reviewers in footage. You leave able to run a discovery-to-remediation cycle and to prove, with evidence, that privileged access is controlled.
Expected Learning Outcomes
Design a credential vaulting architecture that rotates secrets automatically and removes standing knowledge of passwords.
Configure just-in-time elevation workflows that grant time-boxed privileged access tied to an approved request.
Implement session recording and command logging for high-risk privileged sessions across servers and applications.
Build break-glass access procedures that remain usable during an outage while preserving an audit trail.
Establish a review process that samples recorded sessions efficiently rather than attempting full manual review.
Report privileged access metrics, including standing access reduction and session review coverage, to governance committees.
Who Should Attend
Identity and access management engineers designing or operating a PAM platform
Security operations staff responsible for reviewing privileged session activity
Infrastructure administrators whose own accounts require least-privilege controls
IT auditors assessing privileged access controls for compliance evidence
Cloud platform teams managing privileged roles across multiple providers
Risk and compliance managers accountable for insider threat mitigation
Course Modules
Select any module to see its sessions and points.
01Discovering and Classifying Privileged Access
2 sessions · 8 points
Session 1Locating Privileged and Service Accounts
- Scan directory services, servers and cloud platforms to build a complete inventory of privileged accounts.
- Identify orphaned accounts left behind by departed staff or decommissioned systems.
- Distinguish human privileged accounts from automated service accounts that require different control patterns.
- Classify accounts by the systems they can reach and the damage a compromise of each would cause.
Session 2Assessing Standing Privilege Risk
- Measure how much standing, always-on privileged access exists across the estate before remediation begins.
- Identify shared administrator accounts that obscure individual accountability for privileged actions.
- Assess password reuse and rotation gaps among discovered privileged credentials.
- Prioritise remediation targets by combining account reach with the sensitivity of the systems they control.
02Vaulting Credentials and Enforcing Least Privilege
2 sessions · 8 points
Session 1Building the Credential Vault
- Design a vaulting architecture that stores, rotates and issues credentials without exposing plain-text passwords to users.
- Automate credential rotation schedules for both human accounts and embedded service account secrets.
- Integrate the vault with existing directory services so access approvals align with identity governance.
- Handle credential rotation for legacy systems that cannot support modern vault integration natively.
Session 2Just-in-Time Elevation Workflows
- Replace standing administrator rights with time-boxed elevation requests tied to a documented business justification.
- Configure approval workflows that route elevation requests to the appropriate manager or system owner.
- Set automatic expiry so elevated privileges revert to baseline access without manual revocation.
- Design exception handling for urgent elevation needs that cannot wait for the standard approval cycle.
03Recording and Monitoring Privileged Sessions
2 sessions · 8 points
Session 1Configuring Session Recording
- Deploy session recording and keystroke logging for access to systems classified as high risk.
- Balance recording coverage against storage cost and performance impact on target systems.
- Mask sensitive data such as displayed credentials or personal information within recorded sessions.
- Configure real-time alerting for commands or actions flagged as high risk during a live privileged session.
Session 2Reviewing Recordings and Detecting Misuse
- Build a risk-based sampling method for reviewing recorded sessions rather than attempting to watch every recording.
- Correlate session recordings with security information and event management alerts to investigate suspicious activity.
- Train reviewers to recognise patterns consistent with credential sharing or unauthorised delegation.
- Retain session recordings for a period that satisfies both forensic needs and regulatory requirements.
04Governance, Break-Glass and Continuous Improvement
2 sessions · 8 points
Session 1Break-Glass and Emergency Access
- Design break-glass procedures that grant emergency privileged access without waiting for a full approval workflow.
- Ensure every break-glass use triggers automatic notification and mandatory post-incident review.
- Test break-glass procedures periodically to confirm they remain usable when the primary access system is unavailable.
- Rotate break-glass credentials immediately after each use to prevent reuse of an exposed emergency account.
Session 2Measuring and Reporting the Programme
- Track reduction in standing privileged access as the primary maturity metric for the programme.
- Report session review coverage and time-to-detect metrics for privileged misuse to governance committees.
- Benchmark the privileged access programme against recognised control frameworks during internal audits.
- Plan phased onboarding of remaining legacy systems that still lack vault or session recording coverage.
What the participant receives
4 course modules
A structured syllabus
8 training sessions
across 5 days
32 detailed points
Applied, detailed content
Accredited attendance certificate
On completing the programme
Complete your registration
We will contact you within one business day to confirm.
Ready to start?
Reserve your seat and start building the skill.
