In summary
- Keeper Security has launched Keeper Privileged Cloud, a just-in-time access capability built natively into KeeperPAM to eliminate standing privileges across providers including AWS IAM, Azure Entra ID, GCP, Okta and Active Directory.
- Elevated access is granted only for an approved session's duration and automatically revoked afterwards, with no standing accounts, shared credentials or manual cleanup required.
- The capability consolidates JIT access into one platform covering password, secrets, session and endpoint privilege management, extending governance to non-human identities and AI agents.
Keeper Security has launched Keeper Privileged Cloud, a just-in-time (JIT) access capability built natively into its KeeperPAM platform, aimed at eliminating standing privileges across cloud identity providers including AWS IAM, Azure Entra ID, Google Cloud Platform, Okta and Active Directory.
The capability grants elevated access only for the duration of an approved session, then revokes it automatically when the session ends. Keeper Security said no standing accounts are created, no privileged credentials are shared with end users and no manual cleanup is required.
When a request for elevated access is approved, Keeper Privileged Cloud applies a pre-configured access level - such as a specific role or group scoped to a defined set of permissions - and adds temporary group membership or role assignment in the target identity platform for the approved window only.
Users launch the target console or application directly from the Keeper Vault through Remote Browser Isolation, with session activity recorded and analysed in real time by KeeperAI.
The company said most organisations currently piece JIT access together across their identity provider, PAM tool and cloud provider, resulting in three separate systems, three separate audit trails and no single enforcement point.
Keeper Privileged Cloud is intended to consolidate that into one platform spanning password management, secrets management, session management and endpoint privilege management.
Keeper Security said the governance model also extends to non-human identities and AI agents, with every identity receiving only the access a task requires for the duration of that task, with a complete audit record.
"Because Keeper Privileged Cloud was built into KeeperPAM from the ground up, rather than layered on afterward, access governance, credential protection and audit all live in the same zero-knowledge architecture," said Craig Lurey, chief technology officer and co-founder at Keeper Security.
"That is the only way zero standing privilege holds up at scale, instead of becoming one more system to maintain."
Keeper Privileged Cloud is available now as part of the KeeperPAM platform and is included in existing KeeperPAM licences.




