Privileged Access Management
Privileged access management controls, monitors, and records the use of accounts with elevated permissions such as administrator accounts, service accounts, and root access. These accounts are the most valuable targets for attackers as they provide broad access to critical systems.
Term
description · examples · notesPrivileged access management controls, monitors, and records the use of accounts with elevated permissions such as administrator accounts, service accounts, and root access. These accounts are the most valuable targets for attackers as they provide broad access to critical systems.
Description
PAM solutions provide a secure vault for storing privileged credentials, automatic password rotation, real-time session monitoring, and just-in-time access approval instead of permanent standing access.
This technology is key to preventing lateral movement and privilege escalation by limiting an attacker's ability to abuse compromised privileged accounts.
What people often say
- PAM is only needed for the IT department.
- Changing passwords once a year is sufficient for privileged accounts.
Covers / does not cover
Covers
- Secure storage and rotation of privileged passwords
- Just-in-time access approval with time limits
- Recording and monitoring privileged sessions in real time
- Access control for critical servers and network devices
Does not cover
- Regular user account management (that is the domain of IAM)
- Protection against phishing and social engineering
- Endpoint threat detection
Threats
reduces 9Threats it reduces. Select one to open its page.
Techniques
neutralizes 7Techniques it neutralizes. Select one to open its page.