ARCON partner in Dubai
ARCON covers privileged access and endpoint privilege control. It is widely deployed across banking and government here, so the assessors who examine you already know it.

Our ARCON partnership
iConnect is a leading ARCON partner in Dubai, delivering privileged access management and endpoint privilege control for organisations across the Emirates. We handle account discovery, vaulting, session control and the policy design that decides who reaches what.
ARCON is widely deployed across banking and government in this region, which matters when an assessor already knows the product. We focus on the onboarding and policy work that determines whether the controls hold up under examination.
ARCON products we deploy
ARCON spans vaulting, session control, endpoint privilege and compliance reporting. We scope against where privileged risk concentrates in your environment.
How we deliver ARCON
We find the privileged accounts in use, including service accounts and local administrators that were never documented. The count is usually higher than expected.
- Service accounts traced to their dependent systems before any change is made
- Local administrator accounts enumerated per machine, because builds drift over time
- Credentials held in spreadsheets and personal vaults brought into scope
Accounts are onboarded in waves, highest risk first. Password rotation follows dependency mapping rather than preceding it, because a rotated service account takes systems down.
- Dependency mapping completed per account before rotation is switched on
- Onboarding sequenced by risk, with the highest exposure handled first
- Break-glass procedure written and tested before shared passwords are withdrawn
Administrator and third-party access is routed through recorded sessions, replacing shared credentials and ad hoc remote tools.
- Third-party and vendor access moved onto recorded sessions first
- Recording retention set against the standard you report on
- Ad hoc remote tools withdrawn only once the managed path is proven
Local administrator rights are withdrawn and replaced with on-demand elevation, phased by user group so the support desk is not overwhelmed.
- Applications needing elevation catalogued from actual usage before rights are withdrawn
- Elevation rules written per application so work is not interrupted
- Rollout phased by group to keep support volume manageable
The platform is connected to your directory, ticketing system and SIEM, so approvals follow existing process and session events reach monitoring.
- Approvals raised in your existing ticketing, so the audit trail stays in one system
- Session events forwarded to monitoring with fields an analyst can use
- Directory groups reused so entitlements are maintained in one place
Onboarding, policy changes and access reviews are handled by our team in Dubai, with entitlements revisited at agreed intervals.
- New privileged accounts onboarded as they appear, not at audit time
- Entitlements reviewed against the person's current role, with removals actioned that week
- Session recordings sampled on a schedule, with findings raised to the account owner
ARCON and UAE regulatory requirements
UAE Information Assurance Standards
Privileged account control, session monitoring and audit trail are named requirements in the IAS. ARCON supplies all three; we map the configuration to the control set you report against.
DESC ISR
For Dubai government and semi-government bodies, privileged access and session evidence are examined line by line. Session recordings and approvals are held in the format and for the period an assessor expects.
Central Bank of the UAE
Financial institutions face specific expectations around administrator access to core systems. Session control and the compliance reporting module address them directly.
UAE PDPL
Privileged access to systems holding personal data requires justification and a record. Session logs can carry personal data, so retention is set against your lawful basis for holding it.
Why organisations choose iConnect
Scoped before it is quoted
We establish what you run and which obligations apply before recommending modules, so you are not paying for capability that duplicates something already in place.
Configured for your environment
Policy is built around the systems you run and the way your teams work, not left on vendor defaults.
Local delivery and support
Deployment and support come from our team in Dubai, working your hours and your change windows.
Documented for assessors
Configuration is mapped to the UAE framework you report against and documented, so an audit becomes a retrieval exercise instead of a reconstruction.
Integrated with your estate
The platform sits alongside your identity, endpoint and infrastructure systems. We handle those integrations as part of the deployment.
Reviewed on a schedule
Estates change and attacker technique moves. Policy is revisited at agreed intervals, not left as it was at go-live.
What our clients say
“Whenever an issue arises, iConnect is there immediately: quick, efficient and proactive in keeping everything running without disruptions. iConnect has become a crucial part of our operations.”
Head of IT Infrastructure and Network SecurityDragon OilFrequently asked questions
Yes. iConnect is a leading ARCON partner in Dubai and the UAE, handling licensing, implementation and ongoing management for organisations across the Emirates.
We work across the range: Privileged Access Management, Endpoint Privilege Management, My Vault, Converged Identity, Security Compliance Management, Cloud Governance, adaptive MFA and Global Remote Access.
ARCON is widely deployed across banking and government in this region, so assessors and auditors are often already familiar with it. Where that matters to you it is a genuine advantage; where it does not, we will say so and compare it against the alternatives we also deploy.
Some applications do need elevation, which is why endpoint privilege management exists. We identify those during testing and configure elevation rules for them, so nobody is blocked mid-task on the day rights are withdrawn.
Yes. Onboarding, policy changes, access reviews and session audit run as a managed service from our Dubai team.
Privileged account control, session monitoring and audit trail appear explicitly in the UAE Information Assurance Standards, DESC ISR and Central Bank expectations. We configure to the standard that applies to you and leave the documentation behind.


