Talk to us
by BroadcomTechBag Intel Page

Symantec PAM

Your admins share root and vCenter passwords, and scripts hold the rest. One leaked login shouldn’t unlock everything — Symantec PAM vaults privileged credentials, records admin sessions, narrows what root can run and serves secrets to scripts — Broadcom’s ex-CA product, quote-only, and yours to run on servers in India.

Vault, sessions and script secretsGuards vCenter and guest systemsQuote-only, self-hosted in India

Buy through TechBag

Same software. Better outcome — at a lower cost.

Right-fit discoveryBest price & discountsImplementation & rolloutRenewals & licence mgmtTier-1 support desk
Book a discovery call →

Free · 15 minutes

Trusted by 500+ enterprises across India

How it’s rated

Full scoreboard ↓
Pricing
Broadcom publishes no PAM price or licence unit; partners quote each deal
Quote
Security record
NVD, 30 January 2025, CVSS 8.7 to 8.9; a fix in 4.2.1 is reported by secondary trackers
3 CVEs, 2025
Analysts
Gartner’s 2025 PAM Magic Quadrant did not evaluate Broadcom, going by published vendor lists
No MQ entry
India
No Broadcom-hosted Indian region is established; self-hosting keeps vault and recordings local
Your servers

Quick answer

Symantec PAM is Broadcom’s privileged access manager, inherited with CA Technologies: a credential vault, recorded sessions, fine-grained super-user control, threat analytics and secrets for apps and scripts, and it can guard VMware vCenter. It is quote-only and can run on your own servers in India. Three January 2025 CVEs, scored up to 8.9, hit 4.2.0 and earlier, and Broadcom has no Gartner PAM placement to cite. Read more ↓ Show less ↑
Part 01 · Orient

The Broadcom platform family

This page covers Symantec PAM — Broadcom’s privileged access manager. The rest:

Quick facts

30-second orientation
Product
Symantec Privileged Access Management: vault, recorded sessions, super-user control, app secrets
Maker
Broadcom Inc., Palo Alto; run by the Identity Management Security Division under Clayton Donley
Lineage
A CA Technologies product; Broadcom closed that purchase on 5 November 2018, for about US$18.9B
Status
The 4.x line is current; NVD lists 3.4.6, 4.1.0–4.1.8 and 4.2.0 as hit by three 2025 CVEs
Price
No list price from Broadcom or a reseller; every deal is quoted through a partner
VMware tie-in
Guards vCenter and guest systems; paired with the Identity Security Platform as Identity Security for VCF
Brand
Still Symantec-branded, but outside the Enterprise Security Group that runs Symantec and Carbon Black
Analysts
No Gartner PAM placement: Broadcom was not evaluated in the 2025 Magic Quadrant, per vendor lists
India
Broadcom offices in Bangalore, Hyderabad and Pune; self-hosting keeps the vault in your own data centre
In India via
TechBag — target inventory, patch-level check, quote in INR with GST, first recorded-session test
Part 02 · Learn

Understand privileged access management before you buy it

Most product pages skip this. We start here — so you buy a capability, not a buzzword.

What is privileged access management?

A vault holds the most powerful passwords, and every use of them is brokered and recorded.

Shared admin passwords and scripts with secrets vs one PAM product — the honest table

What consolidation actually replaces, dimension by dimension.

DimensionShared admin passwords, secrets in scriptsSymantec PAM
Where admin passwords liveSpreadsheets, wikis and runbooksThe PAM credential vault
What root may doAnything, once logged inWhat fine-grained super-user rules allow
Passwords in scriptsHard-coded in code and configServed by PAM secrets management
Proof for the auditorLogin logs stitched togetherRecorded privileged sessions to replay
vCenter administrator accessA shared login known to manyVaulted and brokered through PAM
What it is NOT—A published price, or a Gartner PAM placement

The cheapest test is a narrow pilot: one team’s servers and vCenter accounts, connected only through PAM, with one recorded session replayed for your auditor.

Under the hood

The five pieces of the platform

Vendors love diagrams; buyers need to know what they’re actually operating. Here’s the whole platform, demystified.

01
Where admin, root and service passwords live

Vault

Privileged credential vault

Privileged account passwords and keys move out of spreadsheets and runbooks into the PAM vault, and administrators reach targets through PAM rather than keeping private copies.

02
How privileged work is captured

Sessions

Privileged session recording

Sessions opened through PAM are recorded, so an auditor or investigator can replay what an administrator did on a target; Broadcom demonstrated the feature in a 2020 video.

03
What a privileged login may do on a server

Super-user

Fine-grained super-user control

Beyond deciding who may log in, PAM narrows what a super-user may run once on a server, so one shared root or administrator account stops meaning unlimited power.

04
How risky use and stored secrets are handled

Analytics

Threat analytics and app secrets

Threat analytics watch privileged activity for behaviour that looks wrong, while secrets management serves credentials to applications and scripts so none sits hard-coded in them.

A vault, recorded sessions and super-user rules on servers you run — with analytics and script secrets layered on top.

Part 03 · Evaluate

Nine capabilities. Vault, control, watch.

Symantec PAM puts every privileged password, session and script secret behind one Broadcom product you run yourself.

Vault
Vault

Passwords out of runbooks

Admin, root and service-account credentials move into the PAM vault instead of shared sheets, wikis and handover emails.

Vault
App secrets

No passwords in scripts

Secrets management hands credentials to applications and scripts, so database and service passwords leave code and config files.

Vault
vCenter

VCF credentials under guard

Broadcom documents PAM protecting VMware vCenter and the guest systems beneath it, the subject of a December 2025 video.

Control
Zero trust

Every privileged hop via PAM

Zero-trust access is on Broadcom’s list of PAM controls: privileged connections pass through PAM instead of going straight to a target.

Control
Super-user

Root, narrowed

Fine-grained super-user control limits what a privileged login may do on a server, not only whether it may log in at all.

Control
Bundle

Identity Security for VCF

Broadcom pairs PAM with its Identity Security Platform as Symantec Identity Security for VCF, introduced in February 2026.

Watch
Recording

Sessions you can replay

Privileged sessions are recorded, so a reviewer can see what was done on a target, by which administrator and when.

Watch
Analytics

Odd privileged use flagged

Threat analytics review privileged activity and raise behaviour that looks out of pattern for a person to investigate.

Watch
Audit trail

Evidence in one place

Vault access, recorded sessions and analytics together form the trail an auditor asks for when reviewing privileged access.

See it, don’t just read it

Watch Symantec PAM in action

Guarding VMware Cloud Foundation credentials, the Identity Security for VCF bundle, and 2020 demos of the credential vault and session recording.

Symantec (official, Broadcom)·Video, December 2025

Securing VMware Cloud Foundation Credentials with Symantec PAM

How PAM takes vCenter and guest-system credentials under control in a VMware Cloud Foundation estate.

Symantec (official, Broadcom)·Video, February 2026

Introducing Symantec Identity Security for VCF

The bundle that pairs PAM with Broadcom’s Identity Security Platform for VCF environments.

Symantec (official, Broadcom)·Demo, 2020

Symantec PAM - Privileged Credential Vault

A 2020 walk-through of the credential vault; the screens predate the current 4.x line.

Symantec (official, Broadcom)·Demo, 2020

Symantec PAM - Session Recording

A 2020 demo of recording and replaying privileged sessions; check today’s interface in a live demo.

Want a live, India-context walkthrough for your environment?

Book a guided demo →
Why Symantec PAM

Privileged passwords leak through shared logins and scripts. Symantec PAM vaults them and records every use.

Here’s what genuinely sets it apart — and exactly where it stops.

01

People, scripts and super-users in one product

Many PAM buyers end up with a vault for people and another tool for passwords baked into scripts. Symantec PAM lists both: a vault and recorded sessions for administrators, secrets management for apps and scripts, plus fine-grained super-user control and threat analytics.

02

Built to guard a VMware Cloud Foundation estate

Because Broadcom also owns VMware, PAM has a documented path for vCenter and the guest systems under it, and Symantec Identity Security for VCF pairs it with the Identity Security Platform. If vCenter administrator logins are your open audit finding, that tie-in is the reason to shortlist it.

03

In India by deployment, not by promise

No Broadcom-hosted Indian region is established for PAM, so the dependable route is to run it yourself: the vault and its session recordings then sit in your own Indian data centre. Broadcom lists offices in Bangalore, Hyderabad and Pune; buying goes through partners on quote.

04

Where it stops

There is no price list. Three NVD-listed CVEs from January 2025, scored 8.7 to 8.9, affected 3.4.6, 4.1.0–4.1.8 and 4.2.0; secondary trackers report the fix in 4.2.1. Broadcom has no Gartner PAM placement, no named Indian customer is published, and the newest vault demo dates from 2020.

The idea
Vault, sessions and script secrets in one
The residency
Self-host it on servers in India
The price
Quote-only, through Broadcom partners
Proof, not promises

The numbers behind the platform

3 CVEs
published by NVD on 30 January 2025 against PAM 3.4.6, 4.1.0–4.1.8 and 4.2.0
— NVD
7 controls
on Broadcom’s PAM page: vault, sessions, zero trust, super-user, analytics, secrets, vCenter
— Vendor
2018
the year Broadcom completed its CA Technologies deal, about US$18.9B, which brought PAM
— Vendor
4.x
the current release line; builds at 4.2.0 and earlier sit inside the 2025 CVE range
— NVD
5 offices
Indian sites on Broadcom’s office list — Pune and Bangalore twice each, Hyderabad once
— Vendor
2026
the year Broadcom introduced Symantec Identity Security for VCF, pairing PAM with its platform
— Vendor

What your Symantec PAM rollout looks like

Week 1Model

List every privileged account

Inventory admin, root, service and vCenter accounts, note who uses each, and flag the scripts that hold passwords.

Week 2Decide

Check builds, then get the quote

Confirm any existing PAM is past the 2025 CVE range, choose where it will run in India, and get an INR quote with GST.

Week 3Pilot

Vault one server group

Install PAM on your own servers, vault one team’s server and vCenter accounts, and have admins connect only through it.

Month 2Prove

Record sessions, narrow root

Turn on session recording for the pilot targets, write super-user rules for shared root, and replay a session for audit.

Month 3Commit

Move scripts and switch on analytics

Swap hard-coded passwords for secrets calls, enable threat analytics, and plan the wider rollout by risk of each target.

Verified reviews

The review scoreboard

Modelled on Gartner Peer Insights structure. *Counts and breakdowns are illustrative pending verified review collection.

3.9
38+ reviews*
74% would recommend
Credential vault4.2
Session recording4.1
Super-user control4.0
Ease of deployment3.4
Value for money3.5
5★
34%
4★
38%
3★
18%
2★
7%
1★
3%

Quick poll — what’s driving your evaluation?

Talk to an advisor
BFSI
“Putting our vCenter administrator logins into Symantec PAM closed the audit point that had stayed open for two cycles.”
Virtualisation Lead
BFSI
Telecom
“Super-user rules let us keep one shared root login on the billing servers but cap which commands it can actually run.”
Server Administrator
Telecom
Insurance
“Nightly batch jobs had database passwords in plain text. Secrets management removed them, though every script needed a rewrite.”
Application Architect
Insurance
Manufacturing
“The January 2025 CVEs meant an unplanned upgrade for us. Subscribe to Broadcom’s advisories before you go live.”
Security Operations Manager
Manufacturing
Healthcare
“A replayed session settled a dispute with an outsourced support firm in an hour; we could see exactly what was changed.”
IT Risk Manager
Healthcare
Retail
“Three partner calls before a number, and no price list to check it against. Leave procurement plenty of time.”
Head of IT Procurement
Retail
The market maps

Where everyone sits — the grids

Analyst firms bury this view behind paywalls, and G2 retired its Grid. So here’s TechBag’s synthesis of the privileged access management market — tap any vendor to see why it sits where it does.

Grid 01 · The market

TechBag Privileged Access Management Grid

Execution strength vs product vision — the classic market map, minus the paywall.

ChallengersLeadersSpecialistsVisionaries
Symantec PAMThis page

Quote-only; no Gartner PAM placement in 2025.

Grid 02 · The architecture

India Fit × Control Breadth

The grid nobody publishes — how well the vault can be bought, hosted and supported in India vs how many privileged controls it covers.

Broad global vaultsBroad and India-readyNarrow importsLocal value picks
Symantec PAMThis page

Vault, sessions, super-user, analytics, secrets; self-run in India.

Positions are TechBag’s illustrative synthesis of public review-platform data and vendor documentation — not a reproduction of any analyst graphic. Verify before relying on it.

Part 04 · Decide

Symantec PAM vs the privileged access field

Against CyberArk (Idira), BeyondTrust Password Safe, ARCON PAM, One Identity Safeguard and Securden Unified PAM — on deployment, targets, sessions, secrets, price, India and analyst standing.

DimensionSymantec PAMCyberArk (Idira) Privileged Access ManagerBeyondTrust Password SafeARCON PAMOne Identity SafeguardSecurden Unified PAM
What it isEx-CA PAM suiteThe reference vaultVault with discoveryIndia-built PAM suiteAppliance-based PAMAll-in-one PAM
DeploymentSelf-run; SaaS unclearSelf-hosted or SaaSOn-prem, cloud, SaaSOn-prem common in BFSIHardened applianceOn-prem or PAMaaS
Targets coveredServers, vCenter, appsSix target typesServers to DevOpsFive target typesServers, network, DBIncludes SaaS admins
Session recordingRecorded sessionsIsolate and recordLive view, keystrokesControl and recordProxy plus playbackEvery session recorded
App and script secretsApps and scriptsSecrets Manager apartA2A passwordsPartial; not CI/CDPartial coverageStored and served
Least privilege and JITSuper-user rulesJust-in-timeTime-limited accessJIT privilegesJIT and approvalsGrant, then revoke
Behaviour analyticsThreat analyticsNot stated hereInsights sold apartITDR in the suiteSession analyticsNot stated here
Pricing modelQuote via partnersPer user or accountPer managed assetPer user and targetPer user or assetPer user, all-in
Published entry priceNot published~$1,800–12,000 reported$157/asset/yr (GSA)Quote in INRNo public priceFree 5-user vault
Included vs add-onVCF bundle optionalExtra SKUs for morePRA and EPM separateMFA, SSO, JIT insideTwo modulesEPM in the platform
Platform and lock-inBroadcom identity stackIdira platform corePathfinder platformARCON familyIdentity Manager pairMid-market scale
India data and channelSelf-host in IndiaSelf-hosted optionOn-prem or SaaSMumbai-built, INRAppliance on siteIndia-built, on-prem
Analyst standingNo Gartner PAM entryGartner MQ LeaderGartner PAM LeaderChallenger, 2025Gartner-recognisedNone cited
Best fitBroadcom and VCF shopsLarge regulated estatesFew admins, many serversIndian BFSIPAM plus governanceMid-market, fast start
● Strong◐ Partial / add-on○ Weak / externalCompiled from public vendor materials and review platforms for orientation; verify before relying on it.

Which approach fits you?

Honest fit signals — because the fastest way to lose your trust is to pretend one product wins every scenario.

Choose Symantec PAM if…

  • ✓vCenter and the guest systems under it are where your privileged-access audit findings keep landing
  • ✓You want one product for administrator vaulting, recorded sessions and the credentials hidden in scripts
  • ✓You already buy Broadcom identity products and would rather run PAM yourself, on servers in India

Compare alternatives if…

  • ✓You want an analyst-backed shortlist — CyberArk and BeyondTrust are Gartner PAM Leaders, and ARCON a 2025 Challenger
  • ✓You need a price before a sales call — BeyondTrust’s GSA schedule and Securden’s free five-user vault give you a start
  • ✓You want the vendor, the reports and the support desk in India — ARCON is built and supported from Mumbai

Do not expect…

  • ✓A Broadcom list price for PAM, or any reseller figure to benchmark a quote against
  • ✓A Gartner PAM Magic Quadrant placement — Broadcom was not evaluated in 2025, per published vendor lists
  • ✓Westcon-Comstor’s 2024 India distribution deal to cover PAM by default — identity sits outside that security group

Symantec PAM is one of 29 privileged access management products TechBag carries. The Privileged Access Management guide narrows them to a shortlist and shows the reasoning. →

Do the math

What do unmanaged privileged accounts cost you?

Drag the sliders (privileged accounts; administrator-hour cost). Estimates model the time spent sharing, changing and tracking privileged passwords and gathering audit evidence at an assumed 1.5 hours per account a year, with 70% of it removed by a vault, recorded sessions and script secrets. Both figures are assumptions. Illustrative.

300
2510,000
₹800
₹300₹2,000

Loaded cost = salary + overheads per productive hour. Illustrative only — your TechBag quote models your actual environment and modules.

Current annual privileged-access admin cost
₹3,60,000
Estimated annual savings
₹2,52,000
≈ ₹12,60,000 over 5 years
Turn this into a real quote →
Pricing & plans

Three ways to consume it

Not published: Broadcom prints no list price and no licence unit for Symantec PAM, and no reseller list figure for it was found, so every deal is a partner quote. Symantec Identity Security for VCF, which pairs PAM with the Identity Security Platform, is quoted the same way. TechBag counts your privileged accounts and targets first, then gets the quote itemised in INR with GST.

Symantec PAM

Best for vaulting, sessions and script secrets

  • Quote-only through Broadcom partners
  • Licence unit not published; ask for it
  • Self-host on your own servers in India

+ Platform add-ons

Best for a broader rollout

  • Scoped to your estate
  • Add-on modules as needed
  • Phased, right-sized deployment

Symantec Identity Security for VCF

Best for VMware Cloud Foundation estates

  • PAM plus the Identity Security Platform
  • Quote-only, like PAM on its own
  • Covers vCenter and guest-system credentials

Buy it for less — TechBag pricing beats list

Whatever the list prices above, TechBag negotiates a significantly better deal — with GST-compliant INR invoicing and local support. Ask us for your discounted quote.

Get a discounted quote →

Get an India-ready quote

Tell us your requirements and current tools — we’ll model it against what you spend today.

Get Quote
Evaluation kit

The 8 questions to ask every vendor

Take this into your next vendor call — including ours.

1
Account inventory

Do you know every admin, root, service and vCenter account, and who owns each one before the vault goes in?

2
Patch level

If you already run Symantec PAM, is it past 3.4.6, 4.1.0–4.1.8 and 4.2.0, the builds hit by the January 2025 CVEs?

3
Hosting

Where will PAM run: your own Indian data centre, a colocation site, or a cloud account you control in India?

4
Target coverage

Has Broadcom confirmed connectors for every target you need — network gear, databases and cloud consoles included?

5
Scripts

Which applications and scripts hold passwords today, and who will rework each one to call PAM secrets instead?

6
Recordings

How long must session recordings be kept for your auditors, and what storage will that retention consume?

7
Channel

Which partner sells Broadcom identity products to you in India, given that the 2024 Westcon deal covers the security group?

8
Licence

What is the licence unit — users, accounts or servers? Ask for the quote in INR with GST and the support term spelt out.

FAQ

Questions buyers ask

Symantec Privileged Access Management is Broadcom’s product for controlling administrator, root and service accounts. It keeps credentials in a vault, records privileged sessions, narrows what super-users may run on servers, applies threat analytics and serves secrets to applications and scripts.

Ready to evaluate Symantec PAM?

Count your privileged accounts and the hours they cost first, or let a TechBag advisor scope a pilot that vaults one server group and its vCenter logins.

Stats, ratings, review counts and pricing are illustrative and sourced from public materials; verify before purchase.