Skip to main content
Trym HåkanssonSwitch to Labs
All writing

TECHNICAL REFERENCE · PERSONALLY PUBLISHED · NOT AN EMPLOYER PUBLICATION

Palo Alto Networks Completed the CyberArk Acquisition. What Identity Teams Should Check.

Palo Alto Networks completed its CyberArk acquisition on February 11, 2026. The practical question is how the combined ownership changes privileged-access planning.

Palo Alto Networks completed its acquisition of CyberArk on February 11, 2026. The transaction is done. Product integration is not.

That distinction matters. Palo Alto Networks says CyberArk will remain available as a standalone platform while integration proceeds. It does not publish a schedule for specific integrations in the completion announcement.

Identity is already part of the control plane. Map the privileged access you need to control now, then choose an available product that can do that job.

What the announcement confirms

The official completion announcement establishes a narrow set of facts:

  • Palo Alto Networks completed the acquisition on February 11, 2026.
  • CyberArk adds identity security for human, machine and agentic identities to Palo Alto Networks' platform strategy.
  • CyberArk's identity-security solutions will continue as a standalone platform.
  • Integration with the wider Palo Alto Networks ecosystem is underway.
  • CyberArk shareholders are entitled to $45 in cash and 2.2005 Palo Alto Networks shares for each CyberArk ordinary share.

The announcement also contains vendor claims about market position and expected benefits. I would not use those claims as proof of customer outcomes. Nor would I attach an integration date that Palo Alto Networks did not publish.

Entra PIM and broader PAM solve different parts of the problem

I have worked with Microsoft identity security across more than 40 organizations. The recurring architecture mistake is to compare product names instead of access paths.

Entra Privileged Identity Management is useful for making eligible Microsoft cloud roles time-bound and approval-controlled. A broader privileged access management program may also need to govern privileged accounts, credentials and sessions on Linux or Unix servers, databases, network appliances, operational technology and cloud platforms outside Azure.

That does not mean every hybrid organization needs two products. It means the answer comes from coverage, not a generic vendor table.

Ask four questions:

  1. Which identities can perform a high-impact action?
  2. Where are the credentials stored and rotated?
  3. Can privileged sessions be approved, limited and investigated?
  4. What happens when the identity belongs to a service, workload or agent rather than a person?

If Entra controls the required path, use it. If a material path sits outside that boundary, evaluate PAM coverage for that path. Avoid the crude conclusion that one product covers everything and the other covers nothing.

What platform consolidation does not fix

A combined vendor portfolio can reduce some integration work. It can also increase switching cost and make weak operating practices harder to see.

The acquisition does not inventory privileged accounts for you. It does not remove standing access, rotate abandoned secrets or define who reviews a privileged session. Those are operating decisions.

This is why I would not begin with a replacement project. I would begin with a privileged-access map:

  • human administrators and emergency accounts;
  • service accounts and workload identities;
  • application secrets, certificates and API credentials;
  • privileged sessions to servers, databases, network devices and operational technology;
  • delegated access used by automation and AI agents;
  • owners, approval rules, expiry and evidence for each path.

The gaps in that map tell you whether the current architecture needs to change.

What to do now

First, confirm which CyberArk and Palo Alto Networks capabilities are generally available. The press release itself warns that unreleased features may change or never arrive.

Second, test control outcomes rather than logo coverage. Can the product issue short-lived access? Can it rotate the relevant credential? Can an investigator connect a privileged action to a person, workload or approved task?

Third, keep the Microsoft comparison specific. Entra PIM may remain the right control for Microsoft roles while CyberArk or another PAM platform covers accounts and systems outside that scope. Consolidation is an option, not an architecture principle.

The acquisition is relevant because Palo Alto Networks has made identity security a core platform pillar. The work for identity teams is less dramatic: inventory the paths, remove standing privilege and prove that approvals, credentials and logs still work after the ownership change.

Sources

Keep these points.

  • The acquisition completed on February 11, 2026. It is no longer a pending transaction.
  • Palo Alto Networks says CyberArk will remain available as a standalone platform while integration proceeds.
  • Entra PIM and enterprise PAM overlap, but their practical coverage depends on roles, systems, credentials and connectors.
  • Do not buy an integration roadmap. Assess controls that are generally available and test them against your own privileged-access paths.
  • Inventory and operating discipline matter more than platform consolidation by itself.

Questions this article answers.

When did Palo Alto Networks complete the CyberArk acquisition?

Palo Alto Networks announced completion on February 11, 2026. Its press release gives the transaction consideration as $45 in cash and 2.2005 Palo Alto Networks shares for each CyberArk ordinary share.

Will CyberArk still be sold separately?

Palo Alto Networks said CyberArk's identity-security solutions will continue to be available as a standalone platform. The same announcement said integration was underway.

Does CyberArk replace Microsoft Entra PIM?

Not as a general rule. Entra PIM is useful for eligible Microsoft cloud roles. A broader PAM program may also need to govern privileged accounts, sessions and credentials across servers, databases, network devices, operational technology and other clouds. The right boundary depends on the environment.

Should Microsoft customers change their identity architecture now?

Not because of the acquisition alone. First map privileged roles, non-human identities, standing access and secrets. Then test whether current controls cover those paths and where a separate PAM capability is justified.

What should buyers assume about future integrations?

Nothing beyond what is generally available. Palo Alto Networks says integration is underway, but its announcement does not provide a delivery timeline for specific integrations.