The Privileged Access Management (PAM) service provides secure, centralized management of privileged accounts, credentials, secrets, certificates, and machine identities across the university.
As a core component of the Identity and Access Management (IAM) program, PAM helps reduce security risk by enforcing least privilege, protecting sensitive credentials, and providing controlled, auditable access to critical systems and services.
Built on Delinea Secret Server and HashiCorp Vault, the service delivers enterprise-grade password vaulting, secret management, automated credential rotation, and secure access workflows for both human and machine identities. PAM supports on-premises, cloud, and hybrid environments while helping organizations meet security, compliance, and operational requirements.
Why Privileged Access Management?
Privileged accounts represent some of the highest-value targets for attackers. Traditional methods of sharing and storing credentials, including spreadsheets, personal password managers, shared documents, or institutional knowledge, increase the risk of unauthorized access and credential compromise.
The PAM service helps organizations eliminate these risks by securing privileged credentials and enforcing consistent access controls across the university environment.
Key Benefits
The PAM service provides solutions for:
- Secure storage and management of privileged credentials and sensitive secrets
- Automated password generation, rotation, and lifecycle management
- Shared account access without exposing passwords to users
- Multi-factor authentication (MFA) for privileged access workflows
- Fine-grained, role-based access controls and delegated administration
- Comprehensive audit logging, monitoring, and reporting
- Secure management of service accounts, API keys, tokens, and certificates
- Just-in-time and time-bound access for elevated privileges
- Reduced operational risk associated with employee transitions and personnel changes
- Compliance support through centralized governance and access visibility
Request PAM Access
Complete the ServiceNow intake form to request new access for a service or department. You must log in to view the form.
Modern Secrets Management for Human and Machine Identities
The PAM platform secures more than user passwords. Through HashiCorp Vault, organizations can manage application secrets, dynamic credentials, encryption keys, certificates, and cloud-native workloads. Support for Kubernetes, AWS IAM, TLS certificates, and API-based integrations enables secure automation across modern infrastructure and development environments.
For administrative users, Delinea Secret Server provides a streamlined experience for requesting, approving, and accessing privileged accounts while maintaining strong security controls and full auditability.
Accessible, Secure, and Automated
The PAM service is hosted on highly available infrastructure and is accessible from any approved device using Ohio State credentials and multi-factor authentication. Authorized users can securely retrieve the credentials and secrets they need while organizations retain visibility, control, and accountability over privileged access.
In addition to secure storage and access management, the platform offers:
- Automated secret and password rotation
- Policy-driven access controls and approval workflows
- Secret discovery and onboarding capabilities
- REST APIs and SDKs for automation and integration
- Centralized auditing and reporting
- Cloud and hybrid infrastructure support
By combining secure credential management, secrets automation, and governance capabilities, the Privileged Access Management service enables the university to protect critical assets, support modern infrastructure, and advance a Zero Trust security strategy.