What is privileged access management?
Privileged access management (PAM) is the practice of controlling how a person reaches a system with administrative rights: how the session is opened, who approved it, what commands are allowed inside it, and what record it leaves behind.
The distinction that matters: PAM governs the session. Privileged identity management governs the credential. Most organizations need both, and the terms are used loosely enough in the market that you should read what a product actually does rather than the label on it.
What a PAM session involves
| Step | What happens |
|---|---|
| Request | A person asks for access to a named system, for a stated reason |
| Approval | A policy either grants it automatically or routes it to an approver |
| Brokered connection | The session is opened through a broker, so the administrator never handles the target credential |
| Restriction inside the session | Commands that would be dangerous are blocked as they are typed |
| Recording | The session is captured so it can be replayed later |
| Expiry | Access ends at a time, not when someone remembers to revoke it |
The point of brokering is that the administrator can do the work without ever seeing the password. If they never saw it, they cannot write it down, reuse it, or take it with them when they leave.
Why it matters
Administrative access is where a breach becomes a catastrophe. An attacker who reaches an ordinary account sees one person's work. One who reaches a domain administrator account sees everything.
Every major framework asks for some form of this control.
| Framework | What it asks for |
|---|---|
| NIST SP 800-53 | AC-6 Least Privilege, AC-17 Remote Access, AU-14 Session Audit |
| NIST SP 800-171 | 3.1.5 least privilege, 3.1.12 monitor and control remote access, 3.1.7 log privileged functions |
| CMMC Level 2 | AC.L2-3.1.5, AC.L2-3.1.7, AC.L2-3.1.12 |
| IEC 62443 | Remote access requirements for industrial systems |
What the kit does
Item
- Live SSH, RDP, and VNC sessions in the browser through a broker, with approvals and command restriction that blocks dangerous commands as they are typed
- Recorded SSH, RDP, and VNC sessions with replay, on the Level 3 kit
- Jump, a managed access path for privileged sessions, isolated on the Level 3 kit
- Start an application with credentials the user never sees
- Allow, step up, or deny sign-in by country, network address, and session policy
See capabilities for the full list with availability words, and the privileged access requirements checklist if you are scoring products against a requirements list.
Common questions
Is PAM the same as a password vault?
No. A vault stores credentials. PAM governs the session that uses them. A product can do one without the other, which is why the requirement list matters more than the category name.
Does PAM replace multifactor authentication?
No. Multifactor authentication proves who is asking. PAM governs what they can reach and what they may do once they are there.
Do we need PAM if we already have a jump box?
A jump box is a network path. PAM adds approval, restriction inside the session, expiry, and a record. The path alone proves nothing after the fact.
What is the difference between PAM, PIM, and PUM?
PAM governs sessions, PIM governs credentials, and privileged user management governs elevation on an endpoint. See the glossary.
Related pages
- Privileged identity management: the credential side
- Privileged user management: elevation on the endpoint
- What is session recording
- What is just-in-time access
- What is zero standing privileges
- What is least privilege
- Privileged access requirements checklist
- Capabilities and industry terms
- AIC Enterprise Privilege Management Suiteâ„¢ and pricing
- Glossary