What Is PAM (Privileged Access Management)?

Also called: Privileged account management

Related problems: Shared admin passwords that nobody rotates; No record of what administrators or vendors did on our servers; Cyber insurer asking how we protect admin accounts; Outside IT vendors with permanent remote access to our systems

Privileged access management (PAM) is the set of tools and practices that protect the accounts able to change your systems: domain and cloud administrators, server and database admins, local admin rights on laptops, network device logins and powerful service accounts. PAM keeps these credentials out of people’s hands where possible, grants elevated access when it is needed, and records what was done with it. Because attackers who reach an admin account can often reach everything, PAM is one of the most direct ways to limit the damage of a breach.

At a glance

  • Focuses on the small number of accounts that can do the most damage, human and non-human.
  • Core functions usually include a credential vault, password rotation, brokered and recorded sessions, and time-limited elevation.
  • Many products also manage local admin rights on endpoints and third-party vendor access.
  • Puts least privilege into practice for administrators.
  • Frequently asked about by cyber insurers and auditors, alongside MFA on admin access.

What problem it solves

In many organizations, admin access grows informally. IT staff log in daily with accounts that hold domain admin rights, shared passwords for firewalls and servers live in spreadsheets, an outside support company has permanent remote access, and old service accounts with powerful rights run scripts nobody remembers writing. Ransomware groups and other attackers look specifically for these accounts, because one of them can be enough to disable backups, push malware to every machine or export data.

PAM reduces how many privileged credentials exist, who can see them and how long access lasts. It also gives you a record of privileged activity, which helps with investigations and with proving control to auditors and insurers.

How it works

Discovery. The tool scans directories, servers, cloud accounts and endpoints to find privileged accounts, including forgotten local admins and service accounts.

Vaulting and rotation. Admin passwords, SSH keys and similar secrets are stored in an encrypted vault and rotated, often after each use or on a schedule. People check out access rather than knowing the password.

Session brokering and recording. Admins and vendors connect to servers and devices through the PAM system, which injects the credential, can restrict commands and often records the session for review.

Just-in-time elevation. Instead of permanent admin rights, users request elevation for a task. Approval can be automatic, by policy or by a manager, and rights expire afterwards. Requiring multi-factor authentication (MFA) at this step is common.

Endpoint privilege management. Many products remove local admin rights from laptops and servers while allowing specific approved applications or tasks to run elevated.

Non-human accounts. PAM tools increasingly manage credentials for non-human identities such as service accounts and application secrets, so they are not hard-coded in scripts.

PAM logs typically feed your security monitoring, and some organizations pair PAM with identity threat detection and response (ITDR) to spot misuse of privileged accounts.

When it matters for buyers

  • At cyber insurance renewal. Applications commonly ask how admin accounts are protected, whether MFA is required for privileged access, and whether local admin rights are restricted.
  • When facing an audit or compliance deadline. Many frameworks expect control and logging of privileged access; specifics vary by framework.
  • When outside vendors or an MSP manage your systems. Brokered, recorded access is easier to defend than shared VPN accounts.
  • After an incident or a peer’s breach. Privileged accounts are often how an intrusion spread.
  • When choosing between a dedicated PAM product and features in your identity, endpoint or cloud platforms. Bundled features may cover basics; dedicated tools usually go deeper on sessions and discovery.

Questions to ask vendors

  • Which systems can you discover and manage out of the box: directory, cloud platforms, Windows and Linux servers, network devices, databases, SaaS admin consoles?
  • Is the product delivered as SaaS, self-hosted, or both, and what infrastructure do we need to run?
  • How do you handle break-glass access if your service or our identity provider is unavailable?
  • Is endpoint privilege management included or a separate module?
  • How are sessions recorded, how long are recordings kept, and where are they stored?
  • How do outside vendors connect, and do they ever see the underlying password?
  • What do implementation and ongoing administration typically require from our team?

How it differs from IAM and IGA

Identity and access management (IAM) handles sign-in, single sign-on and access for all users and applications. Identity governance and administration (IGA) manages who should have which access, through provisioning, access reviews and policy. PAM concentrates on the high-risk accounts and adds controls the others typically don’t provide in depth: credential vaulting, session brokering and recording, and just-in-time elevation. Most organizations need all three to some degree, and some platforms combine them. See our privileged access management overview for how buyers compare options.

Frequently Asked Questions

What counts as a privileged account?
Any account that can change systems, security settings or other people's access: domain and cloud admins, local admin accounts on servers and laptops, database and network device admins, SaaS super-admins, and service accounts with broad permissions. Emergency break-glass accounts count too.
Is PAM the same as IAM?
No. Identity and access management (IAM) covers every user's sign-in and access. PAM is a specialized layer for the small set of accounts that can do the most damage, adding vaulting, session control, elevation on request and recording.
Do small and mid-sized companies need PAM?
Many do, at least in a basic form. Removing standing admin rights, vaulting and rotating admin passwords, and requiring MFA on admin access are common insurer and audit expectations. Cloud-delivered PAM and features bundled into identity or endpoint platforms have made this more practical for smaller teams.
Can PAM control third-party vendor access?
Many PAM products include vendor or remote access features that let outside technicians connect through a brokered, recorded session without being given the underlying password. Check whether this is included or a separate module.
How is PAM usually priced?
Commonly per privileged user, per managed system or endpoint, or by module, such as password vaulting, session management and endpoint privilege management. Compare quotes on the same scope, because packaging varies widely.

You Don’t Need Another Sales Call. You Need an Answer.

30 minutes. No pitch. Just an honest conversation about where you are, what you need, and whether working together makes sense.

We use your details to set up and prepare for the call, and send the newsletter only if you ask for it. Privacy policy.