Keeper Security launches just-in-time cloud identity access in KeeperPAM
Keeper Security said July 16, 2026 that Keeper Privileged Cloud is now available inside KeeperPAM to deliver just-in-time access and zero standing privilege across major cloud identity providers. The feature is meant to cut attack surface, simplify audit trails and automatically revoke elevated access when approved sessions end.
Why it matters: - Keeper Privileged Cloud is designed to remove standing privileged access from cloud identity environments, where dormant credentials can become attack paths. - The feature targets AWS IAM, Azure Entra ID, Google Cloud Platform, Okta and Active Directory. - Keeper says the approach limits privileged access to the exact duration of an approved session and revokes it automatically at the end. - Keeper research found 64% of organisations lack fully consolidated privileged access governance, and 43% still allow direct application logins that bypass their identity provider.
What happened: - Keeper Security announced Keeper Privileged Cloud on July 16, 2026 in London. - The capability launched within KeeperPAM earlier in 2026. - Keeper Privileged Cloud brings just-in-time access and zero standing privilege to cloud identity providers. - Existing KeeperPAM customers can enable the feature through their Keeper customer success team. - New customers can request a demo at keepersecurity.com.
The details: - A user submits an elevated access request and an administrator-approved policy applies the preconfigured access level for that request type. - Keeper Privileged Cloud adds temporary group membership or role assignment in the target identity platform for a defined window. - After approval, the user opens the target console or application from the Keeper Vault through Remote Browser Isolation. - KeeperAI records and analyzes every action in the session in real time. - When the approved window expires, KeeperPAM removes the elevated access automatically. - No standing accounts are created, no privileged credentials are shared with end users, and no manual cleanup is required. - Keeper says the capability is included in existing KeeperPAM licences. - KeeperPAM combines password management, secrets management, session management and endpoint privilege management in one platform. - The governance model also extends to non-human identities and AI agents. - Keeper says every identity receives only the access required for the task and a complete audit record.
Between the lines: - Keeper is positioning native JIT access as a platform issue, not a point-solution problem. - The company argues that stitching together identity provider, PAM and cloud tools leaves three systems and three audit trails instead of one enforcement layer. - Craig Lurey, Keeper Security CTO and co-founder, said many JIT tools are added after the fact and sit on top of systems that were never built to revoke access automatically. - Lurey said building Keeper Privileged Cloud inside KeeperPAM is what lets zero standing privilege scale inside one zero-knowledge architecture. - The message also reflects a broader shift toward governing machine identities and AI agents with the same controls used for human users.
What's next: - Existing KeeperPAM customers can turn on the feature now. - New customers can evaluate the product through a demo request. - Keeper is likely to push the feature as part of a broader zero-trust and zero-knowledge platform story for enterprises managing cloud identity sprawl.
The bottom line: - Keeper Security is betting that eliminating standing privilege at the platform level will reduce risk, simplify audits and make privileged access easier to control across human and machine identities.
Disclaimer: This article was produced by AGP Wire with the assistance of artificial intelligence based on original source content and has been refined to improve clarity, structure, and readability. This content is provided on an “as is” basis. While care has been taken in its preparation, it may contain inaccuracies or omissions, and readers should consult the original source and independently verify key information where appropriate. This content is for informational purposes only and does not constitute legal, financial, investment, or other professional advice.
Sign up for:
The Consumer News Network
The daily local news briefing you can trust. Every day. Subscribe now.
Check Your Email!
We sent a one-time activation link to: .
Confirm it's you by clicking the email link.
If the email is not in your inbox, check spam or try again.
Welcome back!
is already signed up. Check your inbox for updates.