MSSP, Privileged access management, Identity, IAM Technologies

KeeperPAM Adds Native Google Cloud Support to Tackle Identity Sprawl in Multi-Cloud Environments

Innovative access control system with biometric authentication, secure data storage, and permission management features, providing a comprehensive solution for safeguarding sensitive information

Keeper Security has added native Google Cloud support to KeeperPAM, extending privileged access governance across another major cloud control plane. The update focuses on a common operational issue: privileged access is still managed separately in each environment, even though identities, workloads and automation already move across them. By pulling Google Cloud infrastructure, Google Workspace users and service accounts into the same policy framework used for AWS and Microsoft Azure, the platform turns access control into a continuous process rather than a set of disconnected configurations.

Native IAM Alone Is Not Enough

The release is not positioned as a replacement for cloud IAM, but as a governance layer that sits above it. Eric Kalseth, Senior Director of Global MSP Sales, Keeper Security, told MSSP Alert, “Cloud IAM is foundational and absolutely necessary. It defines and enforces permissions inside the cloud environment. Most organizations, however, don’t operate purely in one cloud. They run hybrid environments – cloud, on-prem infrastructure, SaaS applications and different operating systems – all at the same time.”

That hybrid reality is where fragmentation starts to create risk and audit complexity. Each platform can enforce its own permissions, but proving consistent least-privilege access, rotating credentials on a fixed schedule and maintaining a single audit trail across all systems becomes difficult. Kalseth said KeeperPAM’s role is to bring those controls together so organizations can demonstrate governance across the full environment, not just within one console. “Customers still use native IAM to define permissions. KeeperPAM ensures those permissions are governed, rotated and auditable across hybrid environments.”

Managing Non-Human Identities

The pressure on access governance is increasing as automation creates more non-human identities than human ones. Service accounts, CI/CD pipelines and API integrations often start with broad access and remain unchanged because tracking them manually does not scale. That creates a large and largely invisible attack surface.

Kalseth pointed to automation as the main way to contain that growth without adding operational overhead. “Non-human identities – like service accounts, automation and CI/CD pipelines – are growing faster than human users in most cloud environments. The challenge isn’t just managing them, but maintaining visibility and consistent control as they proliferate.” He said the platform reduces daily effort by discovering these identities automatically and rotating their credentials without requiring architectural changes. “Security teams aren’t manually tracking keys or logging into multiple consoles; they’re applying consistent governance controls across identities from a single platform.”

The practical shift is from reactive cleanup to lifecycle management driven by policy.

What This Changes for MSSP Service Delivery

For MSSPs, multi-cloud privileged access is moving from a deployment project to a recurring service. Most customers already run hybrid estates, but consistent access control across them is still handled in pieces. Kalseth said the outbound-only, agentless approach removes much of the onboarding friction that slows managed service rollouts. “There are no inbound firewall changes or heavy infrastructure deployment, which shortens implementation timelines and accelerates time-to-value for both the MSSP and the client.”

Multi-tenant policy management then allows the same least-privilege and credential lifecycle controls to be applied across customers without building separate workflows for each cloud. “From a business perspective, this supports recurring revenue through managed privileged access services – including credential rotation, audit reporting, compliance enforcement and continuous monitoring,” he said. That changes the commercial model from tool deployment to ongoing identity risk reduction.

Where KeeperPAM Positions Itself in the Market

In a market crowded with cloud-focused PAM and identity platforms, the differentiation is tied to how access is governed across identity types rather than within a single environment. Kalseth said the key design goal is consistent control without adding operational weight. “Organizations today aren’t just managing people. They’re managing service accounts, APIs and automation created by cloud and AI-driven workflows. The real challenge isn’t centralizing access in one environment – it’s maintaining clear, consistent control across all identity types as they grow.”

That approach reflects how real environments are structured today. Privileged access is no longer tied to a single directory or infrastructure layer, and governance that follows identities across cloud, SaaS and automation reduces both audit friction and breach impact. “It delivers strong identity governance at scale without becoming operationally heavy,” Kalseth said. In practice, the value is less about adding another control point and more about keeping access short-lived, visible and provable across the entire estate.

Suparna Chawla Bhasin

Suparna is the Senior Managing Editor for CyberRisk Alliance’s Channel Brands, including MSSP Alert and ChannelE2E. She manages content development, sharpens editorial workflows, and ensures storytelling is tightly aligned with audience needs. With a background in technology, media, and education, she combines strategic insight with creative execution.

You can skip this ad in 5 seconds