What is privileged access management?

Privileged access management (PAM) is the practice of controlling how a person reaches a system with administrative rights: how the session is opened, who approved it, what commands are allowed inside it, and what record it leaves behind.

The distinction that matters: PAM governs the session. Privileged identity management governs the credential. Most organizations need both, and the terms are used loosely enough in the market that you should read what a product actually does rather than the label on it.

Request access → Approval → Brokered session
Request access → Approval → Brokered session

What a PAM session involves

Step What happens
Request A person asks for access to a named system, for a stated reason
Approval A policy either grants it automatically or routes it to an approver
Brokered connection The session is opened through a broker, so the administrator never handles the target credential
Restriction inside the session Commands that would be dangerous are blocked as they are typed
Recording The session is captured so it can be replayed later
Expiry Access ends at a time, not when someone remembers to revoke it

The point of brokering is that the administrator can do the work without ever seeing the password. If they never saw it, they cannot write it down, reuse it, or take it with them when they leave.

Why it matters

Administrative access is where a breach becomes a catastrophe. An attacker who reaches an ordinary account sees one person's work. One who reaches a domain administrator account sees everything.

Every major framework asks for some form of this control.

Framework What it asks for
NIST SP 800-53 AC-6 Least Privilege, AC-17 Remote Access, AU-14 Session Audit
NIST SP 800-171 3.1.5 least privilege, 3.1.12 monitor and control remote access, 3.1.7 log privileged functions
CMMC Level 2 AC.L2-3.1.5, AC.L2-3.1.7, AC.L2-3.1.12
IEC 62443 Remote access requirements for industrial systems

What the kit does

Item

  • Live SSH, RDP, and VNC sessions in the browser through a broker, with approvals and command restriction that blocks dangerous commands as they are typed
  • Recorded SSH, RDP, and VNC sessions with replay, on the Level 3 kit
  • Jump, a managed access path for privileged sessions, isolated on the Level 3 kit
  • Start an application with credentials the user never sees
  • Allow, step up, or deny sign-in by country, network address, and session policy

See capabilities for the full list with availability words, and the privileged access requirements checklist if you are scoring products against a requirements list.

Common questions

Is PAM the same as a password vault?

No. A vault stores credentials. PAM governs the session that uses them. A product can do one without the other, which is why the requirement list matters more than the category name.

Does PAM replace multifactor authentication?

No. Multifactor authentication proves who is asking. PAM governs what they can reach and what they may do once they are there.

Do we need PAM if we already have a jump box?

A jump box is a network path. PAM adds approval, restriction inside the session, expiry, and a record. The path alone proves nothing after the fact.

What is the difference between PAM, PIM, and PUM?

PAM governs sessions, PIM governs credentials, and privileged user management governs elevation on an endpoint. See the glossary.

Related pages

Sources