Alert icon Keyboard navigation enabled.
Alert icon TAB or Shift+TAB to navigate across. Down ↓ to open menu. ESC to close menu.
Alert icon Down ↓ to select section. Right → to activate. Up ↑ / Down ↓ / Tab to traverse all. ESC to exit.
BeyondTrust
Skip to content Use space or enter to skip.

What can we help you find today?

Instant Results
  • Website Results
  • Technical Documentation

Filter Options

Focus your search

Filtering by

Your recent searches:

Contact Us Chat with Sales Get Support
  • English
  • Deutsch
  • français
  • español
  • 한국어
  • português
  • Home
  • Resources
  • Blog
  • Privileged Session Monitoring: If You See Something, DO Something current page
Link copied

Privileged Session Monitoring: If You See Something, DO Something

Jun 29, 2016
Author:
Mcannard
Martin Cannard
Blog banner default
Privileged Session Monitoring: If You See Something, DO Something
Mcannard
Martin Cannard

Session Monitoring

To terminate or not to terminate, that is the question…

This is the issue facing many security managers who use session monitoring to overlook administrative sessions in process. Many session management solutions allow you to terminate a live session if you see something suspicious. But the problem is that termination is destructive. While an RDP session may sometimes be reconnected, an SSH session is killed —that means that any processes or scripts that were running are no more. Perhaps this is a good thing— but what if you made a mistake? You now have potentially corrupted systems that were being updated by a totally legit script.

The main reason that many admins choose NOT to terminate is fear of killing the wrong session.

So wouldn’t it be nice if there were a way to safely disconnect a user from their administrative session without breaking anything?

BeyondTrust’s PowerBroker Password Safe has the unique capability to safely LOCK an administrator out without destruction; in fact it is currently the only product on the market with this capability. It does this by preventing the admin from interacting with their active session. A customizable message can be displayed to the admin, informing them that the session is locked - you might even add text to suggest the user calls a number for assistance. In this manner, there is no risk to blocking suspicious activity. If the activity is deemed to be correct, the security manager simply selects an unlock option to allow the user to resume their session. Of course, there is also the option to terminate the active session, as well as terminate any active session the user may have started.

So now there is NO excuse… If you SEE something DO something!

PowerBroker Password Safe provides secure session management, with the ability to proxy access to RDP, SSH and Windows, Unix & Linux Applications. Dynamic assignment of just-in-time privileges, via Adaptive Workflow Control, allow organizations to lock down access to resources based upon the day, date, time, and location. By limiting the scope to specific runtime parameters, it narrows down the window of opportunity where someone might be exploiting misappropriated credentials. For example, if you normally expect the administrator (or third-party vendor) to be logging on from particular systems, you can ensure that access is only permitted from predefined allowable address ranges. Similarly, you can set up policies to control when the accounts are accessible, and alert when specific access policies are invoked.

On top of its granular access controls, PowerBroker Password Safe ensures managed accounts have their passwords regularly rotated – every time a password is released, it can be a one-time password for security. Passwords can be regularly changed using strong and complex policies to ensure that any credential breach, whether directly by the user or indirectly via malware, has a limited window of exploitation. Several additional capabilities in the product help to mitigate the risks of administrative/third-party access:

  • Adaptive Workflow Control can route workflow to different groups according to runtime parameters.
  • Password Safe’s Application Proxy can automatically log users onto resources using managed credentials with zero exposure. Passwords may also be securely passed to any Windows, Unix, or Linux application.
  • All user activity may be recorded for later playback, and as mentioned above, real-time monitoring capabilities allow sessions to be monitored with options to remotely terminate or pause (lock) active sessions.

To learn more about about session management in PowerBroker Password Safe, request a free trial.

Latest Posts
  • Hooked on Identity (Part 2): Abusing OAuth Trust Boundaries in Okta
    Jun 12, 2026 Hooked on Identity (Part 2): Abusing OAuth Trust Boundaries in Okta
    Blog
    7m
  • Hooked on Identity: Abusing SAML Assertion Inline Hooks in Okta
    Jun 9, 2026 Hooked on Identity: Abusing SAML Assertion Inline Hooks in Okta
    Blog
    6m
  • Joining Project Glasswing: Securing the Privilege Backbone of the AI Era
    Jun 8, 2026 Joining Project Glasswing: Securing the Privilege Backbone of the AI Era
    Blog
    5m
  • The Most Common & Most Dangerous Types of Shadow IT
    Jun 5, 2026 The Most Common & Most Dangerous Types of Shadow IT
    Blog
    19m
  • 14 Password Management Best Practices
    May 28, 2026 14 Password Management Best Practices
    Blog
    12m
Related
  • Understanding Privileged Access Management (PAM)
    Feb 18, 2016 Understanding Privileged Access Management (PAM)
    Blog
    1m
  • ICAM, CDM Programs Strengthen Government Endpoint Security
    Aug 13, 2020 ICAM, CDM Programs Strengthen Government Endpoint Security
    Blog
    1m
Share this Article
  • Link
Stay up to Date
Get the latest news, ideas, and tactics from BeyondTrust. You may unsubscribe at any time.

Keep up with BeyondTrust

Customer Support Get Started
  • LinkedIn
  • X
  • Facebook
  • Instagram
  • Add BeyondTrust as a preferred source on Google
  • Privacy
  • Security
  • Manage Cookies
  • Do Not Sell My Data
  • WEEE Compliance

Copyright © 2003 — 2026 BeyondTrust Corporation. All rights reserved. Other trademarks identified on this page are owned by their respective owners. BeyondTrust Corporation is not a chartered bank or trust company, or depository institution. It is not authorized to accept deposits or trust accounts and is not licensed or regulated by any state or federal banking authority.

Prefers reduced motion setting detected. Animations will now be reduced as a result.