Alert icon Keyboard navigation enabled.
Alert icon TAB or Shift+TAB to navigate across. Down ↓ to open menu. ESC to close menu.
Alert icon Down ↓ to select section. Right → to activate. Up ↑ / Down ↓ / Tab to traverse all. ESC to exit.
BeyondTrust
Skip to content Use space or enter to skip.

What can we help you find today?

Instant Results
  • Website Results
  • Technical Documentation

Filter Options

Focus your search

Filtering by

Your recent searches:

Contact Us Chat with Sales Get Support
  • English
  • Deutsch
  • français
  • español
  • 한국어
  • português
  • Home
  • Resources
  • Blog
  • Secure Remote Access by Vendors – It’s a Team Sport current page
Link copied

Secure Remote Access by Vendors – It’s a Team Sport

Jun 14, 2016
Author:
Sgreen
Sandi Green
Product Marketing Manager, BeyondTrust
Blog banner default
Secure Remote Access by Vendors – It’s a Team Sport
Sgreen
Sandi Green
Product Marketing Manager, BeyondTrust

Secure Remote Vendor Access

As businesses have evolved and grown beyond brick and mortar with operations spanning the globe, so has managing the infrastructure to support it. For IT teams that often means facilitating access by external users like consultants, suppliers, and contract workers to support their enterprise datacenter. However, with more data breach investigations revealing exploited third-party credentials as the entry point for the hack, it’s no wonder why the topic of secure remote access can make IT pros skittish.

The 2016 Verizon Data Breach Investigations Report details several incidents, including one about remote vendor access, which we covered in a blog post last quarter.

IT security teams need to identify, manage, and monitor access all privileged access, whether that access is from internal or external users, working on premises or supporting the business remotely.

Here are three tips for ensuring secure remote access:

1) Treat them like they’re one of your own. If your IT strategy is reliant upon partners and you view them as an extension of your workforce, then those external users should adhere to the same security practices as your ‘internal’ workforce. We strongly recommend that you implement least privilege for all accounts – not just for administrators. To accomplish this, start by identifying all managed and unmanaged devices, including those used by third parties, in your IT infrastructure. Then, eliminate all default passwords used on managed systems or devices. Store all credentials in a secure database, then reduce the risk of lost or stolen credentials by systematically rotating passwords for all managed systems.

2) Trust, but verify. Utilize multi-factor authentication to verify users’ identity prior to granting access to servers, apps, and data. Multi-factor authentication can serve as your second line of defense if credentials have been stolen.

3) Keep a bird’s eye view while managing in the weeds. Confidence in your enterprise security will improve knowing that external users are in compliance with your security processes. To achieve that level of confidence, your privileged access management solution should provide complete control, audit, alerting and reporting over all vendor activities. To achieve better visibility and control, establish a workflow for device access when remote vendor access is required. Once access is granted, capture the details of privileged sessions in a recording in case you need to review activities for a future audit. Finally, document all credentials used and requested when remote activity occurs so that you can pinpoint anomalous events such as abnormal device access.

PowerBroker Password Safe enables fast, secure, and reliable access to any device, while enabling you to manage vendor privileges at a very granular level. With Password Safe, you can extend your privileged access management policies to apply to remote vendor activities like:

  • Help Desk and Technical Support
  • Network Management
  • Database Management
  • Desktop and Server Management
  • Development and DevOps
  • Cloud and Virtual Datacenter Management

To read more about our remote vendor access capabilities, check out this data sheet. For more strategies on how to control third-party access to internal systems, you can watch this webinar replay.

Latest Posts
  • Hooked on Identity (Part 2): Abusing OAuth Trust Boundaries in Okta
    Jun 12, 2026 Hooked on Identity (Part 2): Abusing OAuth Trust Boundaries in Okta
    Blog
    7m
  • Hooked on Identity: Abusing SAML Assertion Inline Hooks in Okta
    Jun 9, 2026 Hooked on Identity: Abusing SAML Assertion Inline Hooks in Okta
    Blog
    6m
  • Joining Project Glasswing: Securing the Privilege Backbone of the AI Era
    Jun 8, 2026 Joining Project Glasswing: Securing the Privilege Backbone of the AI Era
    Blog
    5m
  • The Most Common & Most Dangerous Types of Shadow IT
    Jun 5, 2026 The Most Common & Most Dangerous Types of Shadow IT
    Blog
    19m
  • 14 Password Management Best Practices
    May 28, 2026 14 Password Management Best Practices
    Blog
    12m
Related
  • CIA WikiLeaks Breach Reinforces Need for Integrated Privilege & Vulnerability Management
    Mar 9, 2017 CIA WikiLeaks Breach Reinforces Need for Integrated Privilege & Vulnerability Management
    Blog
    1m
  • Don’t Be A Target: Protect and Secure Privileged Accounts with Bomgar
    Jun 29, 2017 Don’t Be A Target: Protect and Secure Privileged Accounts with Bomgar
    Blog
    1m
Share this Article
  • Link
Stay up to Date
Get the latest news, ideas, and tactics from BeyondTrust. You may unsubscribe at any time.

Keep up with BeyondTrust

Customer Support Get Started
  • LinkedIn
  • X
  • Facebook
  • Instagram
  • Add BeyondTrust as a preferred source on Google
  • Privacy
  • Security
  • Manage Cookies
  • Do Not Sell My Data
  • WEEE Compliance

Copyright © 2003 — 2026 BeyondTrust Corporation. All rights reserved. Other trademarks identified on this page are owned by their respective owners. BeyondTrust Corporation is not a chartered bank or trust company, or depository institution. It is not authorized to accept deposits or trust accounts and is not licensed or regulated by any state or federal banking authority.

Prefers reduced motion setting detected. Animations will now be reduced as a result.