Skip to content

Palo Alto Networks, Inc.: Idira Endpoint Privilege Manager for Government

FedRAMP AuthorizedRev5High · since March 14, 2024

What its stage means

An agency or the FedRAMP program authorized it. Agencies can reuse that authorization.

See it on the FedRAMP Marketplace

Share this page:LinkedInXEmail

The provider's description

With Idira™ Endpoint Privilege Manager by Palo Alto Networks, government organizations can confidently defend against attacks by automatically removing local admin rights, enforcing least privilege, enabling policy-based comprehensive conditional application control, maintaining application catalog, and protecting the entire endpoint security stack from tampering – in line with a number of recent CISA alerts, advisories and recommendations, and starting day one.

The Idira Endpoint Privilege Manager secure and flexible SaaS management console allows for centralized policy-based and role-based management to ensure automated, robust and differentiated application of policies based on the user’s role. Automatic elevation of known good programs requiring elevation, including those legacy and not-UAC-aware, significantly cuts down on the IT Service Desk requests, while optional automatic access restriction (for example, network connectivity restriction) for unknown applications significantly reduces the area of attack and helps break ransomware kill chain.

Out-of-the-box anti-ransomware policy allows to add additional layer of security around sensitive data and prevent data corruption even in the event of successful asset compromise and ransomware execution.

Additional critical capabilities include blocking credentials, private keys, secrets, passwords, hashes, cookies and other sensitive information from memory, browsers, operating system and credential stores, effectively blocking most attacks based on credential compromise.

Idira Endpoint Privilege Manager helps with audit and compliance by addressing specific regulation requirements and creating audit trail for identity and privilege events on the endpoints.

The following customer side components are authorized as part of the Idira Endpoint Privilege Manager for Government offering: Idira Endpoint Privilege Manager Windows Agent, Idira Endpoint Privilege Manager macOS Agent, Idira Endpoint Privilege Manager Linux Agent.

What FedXchange has recorded

  1. Idira Endpoint Privilege Manager for Government from Palo Alto Networks, Inc. gained an agency authorization, 4 in all.