Ask your PAM vendor this one question
Here's a test you can run in about five minutes. Pull up a privileged account in your directory, one that was used in a session yesterday. Is the account still there? Does it still hold the same privileged group memberships it had yesterday? I'd bet good money the answer to both is yes. That's not a criticism of your PAM tool. It's what traditional credential rotation was built to do, and more importantly, what it was never designed to do.