What is privileged identity management?
Privileged Identity Management (PIM) is the practice of finding privileged credentials, storing them, changing them on a schedule or on demand, and pushing the new value to every place that uses them. The distinction that matters: PIM governs the credential. Privileged Access Management (PAM) governs the session. Most organizations need both.
What PIM Covers
| Step | What Happens |
|---|---|
| Discover | Find systems, accounts, privileged group members, service accounts, keys, and default passwords. |
| Map usage | Find Windows services, scheduled tasks, IIS pools, and other dependents that use each credential. |
| Vault | Store the credential so an administrator does not keep it. |
| Rotate | Change the password or key on the target. |
| Propagate | Write the new value into every dependent, in order, then verify sign-in. |
| Blast radius | Show which systems a shared credential can reach if it is stolen. |
Why It Matters
A shared administrator password on many servers is one compromise away from every one of those servers. Frameworks that ask for this control include NIST SP 800-53 IA-5 Authenticator Management and AC-2 Account Management.
What the AIC Enterprise Privilege Suite Does
- Discovers systems, identities, privileged group membership, and credentials
- Finds where each credential is used
- Changes the credential and updates dependents
- Reports the blast radius of shared credentials
- Covers Windows, macOS, Linux, directories, databases, cloud, network devices, and web-managed devices
See Privileged Identity Management for the full list of capabilities in the AIC Enterprise Privilege Suite.
Common Questions
Is PIM the same as PAM? No. PIM governs the credential: discover, vault, rotate, propagate. PAM governs the session: how an administrator reaches a system, what they may do, and the record that remains.
Does PIM replace a password vault? A vault stores secrets. PIM also finds credentials, changes them, and updates every dependent so the service keeps running.
What is a blast radius? The set of systems and services affected if one credential is stolen. A domain account running services on 40 servers has a blast radius of 40 servers.
Do we need both PIM and PAM? Yes for most programs. Credentials without session control still leave an open path. Sessions without credential control still leave standing passwords.