Decentralized identity and verifiable credentials, MSSP, Privileged access management

Commvault and Delinea Bring Just-in-Time Credential Control to Backup and Recovery

Credential theft remains one of the most reliable ways attackers undermine recovery. Backup systems run with high privilege, rely on automation, and often operate out of sight. When those credentials are exposed, recovery itself becomes the weak point. That’s the risk Commvault and Delinea are addressing with a new integration that connects Delinea Secret Server directly to Commvault Cloud. The goal is simple: bring privileged access control into backup and recovery workflows, not alongside them.

What’s actually new here

Many organizations already run both a PAM tool and a backup platform. The problem is that backup credentials often sit outside PAM control, embedded in scripts, config files, and automation jobs.

Paul Dadamo, Director, Strategic Partner Development at Commvault, explained to MSSP Alert that the integration changes where credential governance actually happens. “Previously, even with both PAM and backup solutions deployed, backup credentials remained scattered across scripts, configuration files, and admin notebooks - outside PAM control.”

With the integration in place, Delinea’s Secret Server becomes the system of record for backup authentication. “When a data protection job runs, Commvault dynamically retrieves temporary credentials from the vault without exposing them,” Dadamo said.

In real environments, that flow looks like this: machine credentials for backup agents, scripts, and APIs are stored in Delinea’s vault; jobs request credentials at runtime; time-bound access is issued for that specific task; and access is revoked as soon as the job completes. Credentials rotate automatically without breaking automation.

“This eliminates embedded credentials in hundreds of scripts, replaces long-lived machine access with just-in-time access, and removes orphaned accounts as environments scale,” Dadamo said. “The result is role-based access with time-bound privileges and the elimination of hard-coded passwords across thousands of automated tasks.”

Why just-in-time matters for recovery systems

Backup platforms are attractive targets because access is persistent and activity often looks legitimate. In traditional deployments, once credentials are compromised, attackers can linger.

Dadamo described the risk plainly. “Attackers can use stolen credentials that remain valid indefinitely, access backup systems using hard-coded passwords found in scripts, delete backups or encrypt recovery data, and move laterally using shared credentials—all while appearing as legitimate machine access.”

Just-in-time access changes that equation. “When an automated backup job runs, it requests temporary credentials from the vault, uses them for that specific task, and those credentials are immediately revoked,” he said. “The machine never holds long-lived access.”

That narrows what an attacker can do. Temporary credentials limit the window for abuse. Static passwords aren’t sitting in scripts or memory. Privilege scope is constrained. Every privileged action is logged.

“Even if an attacker achieves initial compromise, they face credentials that expire faster than they can exploit them,” Dadamo said. “It turns backup and recovery systems from high-value targets with persistent access into systems with constantly shifting authentication.”

What changes for customers and partners

The integration is available at no extra cost, which signals how Commvault views identity inside its platform.

“We see identity security as a core platform capability rather than an integration add-on,” Dadamo said. “Identity resilience is fundamental to cyber recovery - not a premium feature, but baseline protection.”

For customers, that means advanced credential management, just-in-time access, and audit controls without new procurement cycles or budget approvals. “It removes the traditional barrier where security enhancements required separate investments and justifications,” he said.

For partners, the impact is more strategic. “This creates natural joint selling opportunities with identity security providers while positioning Commvault as a more complete cyber resilience platform,” Dadamo said. “Partners can lead with unified data and identity protection instead of stitching together point solutions.”

Credential-based attacks aren’t slowing down, and recovery systems sit directly in their path. Bringing PAM controls into backup workflows closes a gap that many organizations have lived with quietly for years.

By embedding just-in-time credential governance into backup and recovery, Commvault and Delinea are reducing risk where it matters most: at the point where organizations expect systems to save them, not fail them.

Suparna Chawla Bhasin

Suparna is the Senior Managing Editor for CyberRisk Alliance’s Channel Brands, including MSSP Alert and ChannelE2E. She manages content development, sharpens editorial workflows, and ensures storytelling is tightly aligned with audience needs. With a background in technology, media, and education, she combines strategic insight with creative execution.

You can skip this ad in 5 seconds