Taking over a PAM platform you didn't build is more common than you'd think, but the good news is you can get a handle on it faster than you'd expect. A well-built environment can help you understand it if you know where to look. Here are the five steps to follow.
Start with the same review you would use for the first stage of a PAM Risk Assessment. Go through the backend (the Vault and component servers if you're on-prem) and the front end (PVWA) to understand any inconsistencies or risks that should be corrected.
That review that you completed in step 1 reveals what others put into place but didn't document.
Every safe, account, platform, and permission — recorded in one place.
A clear picture of how access actually works today.
Fill in the gaps you didn't have when you took over.
Record everything that you find into an inventory and create a map of how access works today. This will give you the missing pieces you didn't have when you took over this environment, and you can start making sense of it all.
Don't try to fix it all at once. Put together a list of all of your findings and rank them by risk. This will help you identify what to tackle first and spend your effort where it matters most.
Toxic permissions, exposed safes, broken rotations
Ownerless safes, policy misalignment, unhealthy servers
Cleanup, documentation, naming and housekeeping
Once you understand the environment and you've fixed the high-priority items, get it onto a role-based permission model if it isn't already. When access is granted through defined roles and groups, anyone can look at a safe and see who has access to what and why, and you're never stuck reverse-engineering someone else's work again.
If you've inherited a PAM setup and you're flying a little blind, please reach out. A risk assessment is a great place to start, and we can knock one out in a couple of weeks.