Ask your PAM vendor this one question
Oct 1, 2026
Here's a test you can run in about five minutes. Pull up a privileged account in your directory, one that was used in a session yesterday. Is the account still there? Does it still hold the same privileged group memberships it had yesterday? I'd bet good money the answer to both is yes.
That's not a criticism of your PAM tool. It's what traditional credential rotation was built to do, and more importantly, what it was never designed to do.
I understand why rotation became the default answer in our industry. It's simple to explain to a board, simple to audit, and for years it mapped cleanly onto compliance expectations. But even NIST has moved past this. NIST SP 800-63B now explicitly recommends against arbitrary periodic password changes, calling instead for rotation only when there's evidence of compromise. "We rotate every privileged credential after use" sounds responsible, but it isn't the whole picture. When a session ends and the password rotates, the account and its standing access are still there.
What would happen if an attacker found that account? The password is the smallest part of the problem. For most accounts I've seen over the years, an attacker doesn't even need it because the account still authenticates through certificates or tokens that were never rotated and it still holds every privileged group membership it's always had. There are plenty of paths into a privileged account that have nothing to do with the password at all.
None of that shows up the audit. When a session ends and the password rotates, the account behind it stays exactly where it was with the same group memberships and standing access. Netwrix's 2026 Data and Identity Security Report found that 76% of organizations can't immediately revoke standing access when it's no longer needed, and 64% have at least some overprovisioned access sitting on critical data right now. Rotation didn't cause those numbers, but it didn't fix them either.
The account is only secure in the narrow sense that nobody can reuse yesterday's password. It's completely unsecure in every way that actually matters to an attacker who doesn't care about yesterday's password. They just need the account to still exist and still hold privilege.
Why Zero Standing Privilege closes the gap
Zero Standing Privilege removes the gap rotation leaves open, and it's far less complicated than people think. When a session ends, the account either loses every group membership it had, or it stops existing entirely. At Netwrix, our ephemeral accounts do the second option. They're created on the fly for the specific task and deleted the moment it's over. There’s nothing left to find, because there's literally nothing left in Active Directory.
This approach doesn't disrupt how admins actually work. That's what I appreciate about it, and what took me a while to trust after moving away from legacy vaulting. You get full access while you're in the session, and nothing's left behind when you log off.
The non-human identity problem makes this even more urgent. Service accounts and automated agents almost never get reviewed on a regular schedule. They just sit there, privileged and forgotten, until an automated scanner or adversary goes looking for them.
Rotation vs. Zero Standing Privilege: two different philosophies
Ask your PAM vendor this one question, or ask yourself if you know your current setup well enough: after a session ends, does the account still exist with its group memberships intact?
If the answer is yes, you have password rotation, but you don't have Zero Standing Privilege. Those aren't two versions of the same idea. They're two different philosophies about what "secure" means.
Rotation asks how to make sure a credential can't be reused. Zero Standing Privilege asks why the account should exist at all when nobody's using it. In essence, rotation treats standing access as a risk to manage while Zero Standing Privilege treats it as a default to eliminate.
Most PAM programs never ask that second question, because rotation already gave them something to put in the audit report. But an audit report and an empty attack surface are not the same thing. An audit report proves you did something. An empty attack surface proves there's nothing left to find.
Netwrix Privilege Secure shrinks your attack surface with Zero Standing Privilege. Launch in-browser demo.
Share on
Learn More
About the author
Hano Grimm
Hano Grimm is a Product Marketing Manager at Netwrix, leading positioning, messaging, and release management for the company's PAM solutions that protect sensitive data and meet compliance standards. He brings a strong background in enterprise security, channel management, and technical customer support, having spent years helping businesses adopt software solutions and navigate technical requirements.