I've been working on getting our team to use our PAM (CyberArk) more consistently. I keep hearing "the passwords rotate automatically," but I was never 100% sure it was actually happening for all our service accounts.
So I wrote a small Python script that connects to the PAM's API, pulls a list of managed accounts, and checks the last password change timestamp. Then it compares that to the rotation policy defined for each account. I've already found a couple that were way past their rotation schedule. Has anyone else done something like this? I'm wondering if I'm overcomplicating it or if there's a better way to get this kind of assurance.
You're definitely not overcomplicating it. Trust but verify is the only sane approach to automated credential rotation. I've seen similar gaps even with well established vault setups.
We actually built a similar check into our Prometheus monitoring. The script exports the last rotation timestamp as a metric for each account, and we have an alert rule that fires if the current time minus that timestamp exceeds the policy window. That way it's visible on the same dashboards as everything else and we get paged. The tricky part is handling accounts that are excluded from rotation by design, we have to maintain an allowlist for those.
Your manual script is the right first step, but I'd recommend pushing those findings into your existing alerting system. Otherwise you're just creating another thing you have to remember to check.
Automate everything. Twice.