PAM360 Privileged Access For The NHS
Others deliver and disappear. We stay - to govern, harden, monitor, and evolve - turning frameworks into action, not just checklists.


The accounts that can do the most damage in an estate are usually the ones managed the least. Domain admins, service accounts and local administrator rights are the keys to everything, and in most organisations they are held permanently, shared informally and reviewed rarely.
That is not an oversight anyone chose. It is what happens when access is granted to solve a problem and never revisited. It is also precisely what an attacker looks for, because one compromised administrative account is worth a thousand ordinary ones.
Standing privilege is privilege that exists whether or not anyone is using it. It sits in the directory waiting, and its risk is constant rather than tied to the work it was granted for. ManageEngine PAM360 inverts that. Access is granted for a purpose, held for a defined period, monitored throughout and withdrawn when the work finishes. At platform level it standardises how elevated access is controlled and gives end-to-end visibility into actions performed on critical systems, databases and cloud resources.
What it consolidates is worth knowing early, because it explains what you are buying. ManageEngine has three long-standing point products in this space: Password Manager Pro for credential vaulting, discovery and rotation, Key Manager Plus for the SSH key and certificate lifecycle, and Access Manager Plus for remote privileged session management. PAM360 brings those into a single platform and adds the correlation between them. If you already own one of them, the commercial question is not whether to buy something new but whether to consolidate what you already run, and the answer is frequently that you are paying for two thirds of the platform already.
This is written for the person who has to run it rather than the person who signs for it, and everything here traces back to ManageEngine's own documentation, linked as we go, so you can check any of it at source. McCormickCo Security is the UK's first ManageEngine Gold Partner and delivers PAM360 end to end for the NHS and the wider regulated sector.
Privilege That Expires
If privileged passwords live in spreadsheets, scripts or somebody's memory, that is the real attack surface, whatever the rest of the security architecture looks like.
PAM360 discovers privileged accounts, users and credentials across the estate first, which in practice is where the uncomfortable findings appear, and holds them in an encrypted store with automated rotation and fine-grained role-based access control. Credentials are fetched at run time when a session starts, so the user connects to the target without the credential passing through their hands. For SSH and RDP sessions the platform uses the stored credential tied to the target machine, validating the user's access rights through multi-factor authentication or policy-based access control before the session begins.
The practical consequence is that a credential cannot be written down, shared with a colleague, or carried to a new employer, because nobody ever had it. It also means rotation stops being a change event that breaks things, because nothing downstream is holding a copy.
Vaulting on its own still leaves the privilege standing, though, and the safest standing privilege is none at all. Just in time elevation provisions higher privileges only when a user genuinely needs them, for a defined task and a defined time, then revokes them automatically and resets the password afterwards. Users are elevated into local or domain privileged groups for the job and dropped back out when it is done. Application and command controls limit what can be done with the privilege while it is held, so the grant is bounded in scope as well as in time.
Access approval workflows can be tied to ticket validation, so credential retrieval for a service request is authorised only once the ticket status has been verified. For an NHS organisation already running a service desk, this is one of the more valuable integrations in the platform and one of the least demonstrated. It links the access grant to the documented reason for it, which is exactly what an auditor asks for and exactly what is usually missing. It also removes the most common informal practice in IT operations, which is elevating first and raising the ticket afterwards.
Taken to its conclusion, that becomes ephemeral accounts: temporary, time bound privileged accounts created on the target system when an access request is approved, and removed automatically once the session ends. Nothing persistent is left behind to be discovered, misused or forgotten in a later access review, which removes an entire category of standing risk rather than managing it. It reduces lateral movement risk specifically, because there is no dormant privileged account for an attacker to find after compromising something adjacent. All activity through an ephemeral account remains fully auditable, so removing the account does not remove the record.
Control At The Point Of Use
When someone holds the keys to a critical system, knowing that they connected is not the same as knowing what they did.
PAM360 lets you launch, monitor and shadow privileged remote sessions in real time, with dual control where the system warrants it, and the ability to terminate a session in progress. Sessions are captured and archived as video files to support investigative audits. Access policies can be defined by user group, address restriction or device specific rule, so the controls around a session reflect the sensitivity of what sits behind it rather than applying uniformly across the estate.
The point we would add is that recorded sessions are only evidence if somebody has tested retrieving and replaying one. An untested evidence store is an assumption, and it is the assumption most often found to be wrong at the moment it matters.
Below the session layer sits the quieter problem. Local administrator rights are convenient, and they are also how one compromised user becomes a full breach, because malware inherits whatever the logged on account holds. Endpoint privilege management revokes unnecessary local admin accounts and enforces least privilege through allowlisting and blocklisting applications per endpoint, restricting child processes so that an approved application cannot be used to launch something else, and granting just in time elevation for the specific tasks that genuinely need it. Users keep the ability to do their jobs and lose the standing administrative power attackers depend on.
In a clinical setting the granularity matters more than the principle. The cost of a user being unable to complete a task is measured in patient time, so a blanket removal of local admin without an elevation path is not a security improvement, it is a service incident waiting to happen. The sequence that works is discovery, then allowlisting for what is genuinely needed, then removal.
Around all of it, PAM360 evaluates the request rather than only the requester. A trust scoring mechanism covers both users and devices, access is granted in real time on trust score and context rather than a static rule set, and it can be challenged, limited or withdrawn the moment risk is detected. Verification is continuous rather than a decision taken once at login and assumed for the rest of the session. Machine learning anomaly detection surfaces unusual privileged activity, which is the category of event least likely to be caught by a rule written in advance.
The Identities That Are Not People
Hard-coded passwords in scripts and pipelines are a breach waiting to happen, and they are common in every estate that has automated anything.
PAM360 secures and rotates the credentials used by non-human identities: machines, applications, services, scripts, processes and DevOps pipelines. Secrets are retrieved securely at run time rather than embedded in source. Integration is through SDKs, global APIs and SCIM connectors, so privileged access routines can be woven into your own applications and delivery pipelines without slowing development down. Application to application and application to database retrieval runs over secure REST and SSH based command line APIs, with identity verified through SSL certificates and hostname validation, and registered API users holding unique authentication tokens.
Keys and certificates are the same problem wearing different clothes. An expired certificate or an orphaned SSH key looks like a small oversight until it takes a service down or grants access nobody is auditing. PAM360 discovers SSH devices across the network and enumerates the keys already deployed on them, which is usually the first time an organisation sees the true number. It creates and deploys new key pairs with a single action and enforces automated periodic rotation, which removes the key sprawl that grants quiet, unaudited access. Alongside it, SSL and TLS certificate lifecycle management handles discovery, renewal and deployment. With public certificate lifetimes shortening under the CA/Browser Forum ballot, the manual approach to renewal has a visible expiry date of its own, and the workload is about to triple.
In cloud environments, excessive permissions accumulate the same way. They are easy to grant, rarely reviewed, and invisible until something uses them. Cloud Infrastructure Entitlements Management identifies the risk that comes from excessive permissions, policy violations and misconfigurations, presenting vulnerable permissions from a centralised dashboard, with detection and mitigation workflows that support the move towards zero standing privileges in the cloud.
One point of accuracy that a demonstration will not always make clear. The release notes describe cloud entitlement coverage as focused on AWS environments. If your cloud estate is principally Azure, which for most NHS organisations it is, confirm the current coverage position before this capability carries weight in a business case. We would rather tell you that now than after a procurement.
What The Auditor Asks For
Privileged access is where auditors look hardest, so it pays to start from a foundation built for scrutiny.
PAM360 is built to meet the standards regulated organisations are held to, including NIST, PCI DSS, FISMA, HIPAA, SOX and ISO/IEC 27001, with real time audits and ready made compliance reports. Every privileged action is tied to validated business context and captured for audit, so demonstrating adherence to internal controls and external regulatory requirements, whether for the NHS DSPT or another framework, is a report rather than a research project.
One governance question is worth settling before go live. PAM360 applies AI to session analysis and cloud entitlement recommendations, and supports both hosted providers and self hosted models running inside your own infrastructure. For an NHS information governance conversation, the difference between a hosted model under a third party agreement and a self hosted model inside your own boundary is the difference between a lengthy assessment and a short one. Decide which route you are taking before the capability is switched on, not after.
As with Log360, the product produces the evidence and the mapping is the work. Knowing which DSPT outcome a privileged session recording evidences is what turns a capability into an audit position. Where both are deployed, PAM360 feeds privileged session and credential activity into Log360, so a privileged action can be correlated against everything else happening at that moment rather than sitting in a separate audit log nobody opens between assessments.
See It On Your Own Estate
The clearest way to judge a privileged access platform is against your own accounts, because the interesting findings are always the ones nobody expected. Discovery alone usually changes the conversation.
We can show you PAM360 in action: a live demonstration, or a proof of concept in your own environment. As the UK's first ManageEngine Gold Partner, we handle design, licensing, deployment, onboarding of privileged accounts and ongoing operation, with the compliance mapping regulated organisations need alongside it.
If you'd like to see what PAM360 could do for your security team, we'd welcome the conversation.
Contact | McCormickCo Security. Our team can talk through architecture, licensing, deployment and DSPT evidence mapping, and help you assess how this fits your environment.







