You can stand up a vault in two weeks. The team at One Identity says that’s about how long it takes to get the basics running, from discovery scans to approval workflows. Two to four weeks of work, and a respectable PAM foundation is in place.
That’s not the hard part.
The hard part starts the next morning, when actual users start working around the system.
What adoption failure looks like
In a recent session, the team walked through "a day in the life of a privileged access engineer." The framing was simple: ideal versus reality at different hours of the day. The technical deployment was rarely the issue. What kept showing up was a quieter problem: users finding ways around the controls.
Sometimes that’s literal. Our expert described seeing privileged credentials stored in a proper PAM solution and then copied into a “non-approved vault” somewhere else, because grabbing them from a personal store was faster than going through the workflow. The official vault was working. The users had simply stopped using it.
Sometimes it shows up as a request. “Our passwords are too long,” he’s been told. “We can’t type them in.” One organization wanted seven or eight characters for privileged accounts. The reaction was about what you’d expect.
Other times it’s the break-glass procedure, designed for genuine emergencies, being used as a convenience door. “When it becomes a regular occurrence where it’s just used for convenience,” he says, “that is the real problem. The emergency is now happening, but it’s not really an emergency.”
And the quietest form of failure: access reviews that get rubber-stamped. The PAM telemetry is telling one story, the reviewer is signing off another. “This user hasn’t utilized this account since 2023. Why does this user still have access?”
Why this is the deciding factor
Every one of those workarounds is a sign that something in the experience is harder than the workaround itself. And every workaround widens the gap between what the PAM solution says is happening and what’s actually happening.
The risk doesn’t disappear when users route around the system. It just gets harder to find. A credential parked on a sticky note still gets stolen. A session that never gets recorded never gets reviewed. The gap between policy and reality is where the breach lives.
That’s the real reason adoption is the deciding factor. PAM only reduces exposure when the actual privileged work flows through it. A pristine policy with a side door doesn’t protect anything. It just produces nicer reports.
The path we actually recommend
The good news is that the prescription isn’t a bigger deployment. It’s a smarter sequence.
When asked about the biggest blocker we see in the field, there are things: fear of breaking service accounts, and the impulse to roll out everything at once. The recommended starting point is the work that builds confidence: vault the known accounts, get rotation working on the managed ones, then move end users toward zero standing privilege on the accounts that matter most. Expand from there.
The vault is the beginning, not the destination. Capabilities like just-in-time access, session recording and behavioral governance come later, once the foundation is trusted.
Two to four weeks for the basics. Twelve to eighteen months for the full journey. The pace is up to you. The order matters more than the speed.
Go deeper
The full, on-demand session, A Day in the Life of a PAM Engineer, walks through three maturity tiers and the specific roadmap we use with customers. Check it out and then come back to your own deployment and ask the harder question: are your users actually using it? If not, let’s fix that. Book an assessment. Request a One Identity Assessment for One Identity Safeguard