Privileged access management (PAM) is the set of tools and practices that protect the accounts able to change your systems: domain and cloud administrators, server and database admins, local admin rights on laptops, network device logins and powerful service accounts. PAM keeps these credentials out of people’s hands where possible, grants elevated access when it is needed, and records what was done with it. Because attackers who reach an admin account can often reach everything, PAM is one of the most direct ways to limit the damage of a breach.
At a glance
- Focuses on the small number of accounts that can do the most damage, human and non-human.
- Core functions usually include a credential vault, password rotation, brokered and recorded sessions, and time-limited elevation.
- Many products also manage local admin rights on endpoints and third-party vendor access.
- Puts least privilege into practice for administrators.
- Frequently asked about by cyber insurers and auditors, alongside MFA on admin access.
What problem it solves
In many organizations, admin access grows informally. IT staff log in daily with accounts that hold domain admin rights, shared passwords for firewalls and servers live in spreadsheets, an outside support company has permanent remote access, and old service accounts with powerful rights run scripts nobody remembers writing. Ransomware groups and other attackers look specifically for these accounts, because one of them can be enough to disable backups, push malware to every machine or export data.
PAM reduces how many privileged credentials exist, who can see them and how long access lasts. It also gives you a record of privileged activity, which helps with investigations and with proving control to auditors and insurers.
How it works
Discovery. The tool scans directories, servers, cloud accounts and endpoints to find privileged accounts, including forgotten local admins and service accounts.
Vaulting and rotation. Admin passwords, SSH keys and similar secrets are stored in an encrypted vault and rotated, often after each use or on a schedule. People check out access rather than knowing the password.
Session brokering and recording. Admins and vendors connect to servers and devices through the PAM system, which injects the credential, can restrict commands and often records the session for review.
Just-in-time elevation. Instead of permanent admin rights, users request elevation for a task. Approval can be automatic, by policy or by a manager, and rights expire afterwards. Requiring multi-factor authentication (MFA) at this step is common.
Endpoint privilege management. Many products remove local admin rights from laptops and servers while allowing specific approved applications or tasks to run elevated.
Non-human accounts. PAM tools increasingly manage credentials for non-human identities such as service accounts and application secrets, so they are not hard-coded in scripts.
PAM logs typically feed your security monitoring, and some organizations pair PAM with identity threat detection and response (ITDR) to spot misuse of privileged accounts.
When it matters for buyers
- At cyber insurance renewal. Applications commonly ask how admin accounts are protected, whether MFA is required for privileged access, and whether local admin rights are restricted.
- When facing an audit or compliance deadline. Many frameworks expect control and logging of privileged access; specifics vary by framework.
- When outside vendors or an MSP manage your systems. Brokered, recorded access is easier to defend than shared VPN accounts.
- After an incident or a peer’s breach. Privileged accounts are often how an intrusion spread.
- When choosing between a dedicated PAM product and features in your identity, endpoint or cloud platforms. Bundled features may cover basics; dedicated tools usually go deeper on sessions and discovery.
Questions to ask vendors
- Which systems can you discover and manage out of the box: directory, cloud platforms, Windows and Linux servers, network devices, databases, SaaS admin consoles?
- Is the product delivered as SaaS, self-hosted, or both, and what infrastructure do we need to run?
- How do you handle break-glass access if your service or our identity provider is unavailable?
- Is endpoint privilege management included or a separate module?
- How are sessions recorded, how long are recordings kept, and where are they stored?
- How do outside vendors connect, and do they ever see the underlying password?
- What do implementation and ongoing administration typically require from our team?
How it differs from IAM and IGA
Identity and access management (IAM) handles sign-in, single sign-on and access for all users and applications. Identity governance and administration (IGA) manages who should have which access, through provisioning, access reviews and policy. PAM concentrates on the high-risk accounts and adds controls the others typically don’t provide in depth: credential vaulting, session brokering and recording, and just-in-time elevation. Most organizations need all three to some degree, and some platforms combine them. See our privileged access management overview for how buyers compare options.
