Netwrix 1Secure delivers unified visibility across data and identity - free for 14 days with full access. Start a free trial

Resource centerBlog

Bring Your Own Vault: Why "rip and replace" isn't the only option

Bring Your Own Vault: Why "rip and replace" isn't the only option

Oct 9, 2026

Part 3 of 3 in our Rethinking Privileged Access series. Catch up on Part 1: The password was never the only problem and Part 2: Beyond the vault.

If your security team has operated a mature PAM deployment, you know that the technology is rarely the hard part of switching tools. You've spent years, and often a significant budget, building workflows, integrations, and institutional muscle memory around your existing legacy PAM vault. Telling them to "just migrate everything at once" starts a change-management and risk conversation, and most organizations rightly balk at it.

Parts 1 and 2 of this series made the case for modern PAM: eliminating standing privilege instead of only vaulting the password behind it. They also showed how much of the Windows/AD credential-attack catalog that closes off. Now, the pushback you’ll likely get is that this sounds like a full platform swap. But it doesn't have to be.

Netwrix Privilege Secure (NPS) has a feature built for that situation: Bring Your Own Vault (BYOV).

What BYOV does

BYOV lets NPS connect directly to the vault you already have (a legacy PAM vault, CyberArk, BeyondTrust, HashiCorp Vault, or Microsoft LAPS) and treat the accounts stored there exactly like NPS's own managed accounts.

The accounts sitting in your existing vault get the full NPS session treatment on top of whatever your current tool already does:

  • Enabling and disabling the account around the session
  • Granting privilege at session start (adding the account to Domain Admins, local Administrators, or a sudo group, for example) and removing that privilege the moment the session ends
  • Turning RDP on only for the duration of the session and off again afterward
  • Applying whatever other Activities your NPS policies define, including the Kerberos ticket purging and unauthorized-account scanning covered in Parts 1 and 2

Once the session ends, NPS writes the new, rotated password back into the original vault, which remains the system of record. Your existing vault's role stays the same: it keeps storing and rotating the credential. The change is in everything that happens around that credential while it's in use. That's where NPS adds the modern PAM layer that legacy PAM was never designed to provide, eliminating standing privilege around the session itself.

Two ways customers use BYOV

In practice, BYOV gets used in two different ways, and both are valid.

Defense in depth. Some customers have no intention of moving off their current vault. They're happy with it, it's deeply embedded, and there's no business case to change. For them, BYOV adds session-layer security controls to a legacy PAM tool built around credential protection.

A migration path with no cliff edge. Other customers are trying to get off their existing tool, often for cost reasons, but can't stomach a hard cutover. A full rip-and-replace means re-onboarding every account, every workflow, and every integration at once, with all the operational risk that implies. BYOV lets customers bring the new capability online immediately against their existing vault. From there, they migrate accounts and user groups over to NPS-managed or ephemeral accounts at whatever pace their operations team can absorb, phasing out the legacy PAM platform along the way.

Why this matters for the budget conversation, too

Cost matters as much as architecture here. NPS is generally priced well below the legacy PAM tools it's most often deployed alongside, and CyberArk in particular carries a well-known premium in this market. For a customer already carrying that cost, BYOV lets them prove out the value of modern PAM immediately, without waiting for a full migration project to justify the spend or defending a "throw out what we already paid for" line item.

That's the point of BYOV: it decouples adopting better session security from replacing your existing infrastructure.

Wrapping up the series

Across this series, we've argued that:

  • Part 1: standing privilege, along with the password protecting it, is the real attack surface. That's where legacy PAM's vault-and-checkout model splits from the session-and-Activities model of modern PAM with NPS.
  • Part 2: eliminating that standing privilege closes off far more of the Windows/AD credential-attack catalog than vaulting alone, such as Pass-the-Hash, Pass-the-Ticket, Kerberoasting, and more. The post also covers what this approach doesn't touch (Golden Tickets, AD CS abuse, DPAPI backup key theft).
  • Part 3: you don't need a rip-and-replace project to start getting those benefits. BYOV lets your existing vault keep doing the job it was built for while NPS adds the layer legacy PAM was never built to provide, on whatever timeline your operations team can absorb.

The password was never the only problem. The privilege sitting behind it, waiting indefinitely to be used, was the rest of it.

Share on

Learn More

About the author

Tyler reese headshot

Tyler Reese

VP of Product Management, CISSP

With more than two decades in the software security industry, Tyler Reese is intimately familiar with the rapidly evolving identity and security challenges that businesses face today. Currently, he serves as the Vice President of Product Management for the Netwrix Identity Product Portfolio, where his responsibilities include evaluating market trends, setting the direction for the Identity product line, and, ultimately, meeting end-user needs. His professional experience ranges from IAM consultation for Fortune 500 companies to working as an enterprise architect of a large direct-to-consumer company. He is CISSP certified.