Privileged Access Management (PAM)
Privileged Access Management (PAM) is the set of processes and technologies for protecting particularly far-reaching user and system accounts. These include administrators, root accounts, service accounts and technical identities whose permissions enable changes to systems, data or security configurations.
Privileged accounts are particularly attractive to attackers because a compromised access often allows far-reaching movement within the IT environment. PAM reduces this risk by storing credentials securely and by approving, time-limiting and logging access. Sessions are frequently also monitored or recorded so that critical activities remain traceable.
Typical PAM functions are password vaulting, automatic rotation of credentials, just-in-time permissions and session monitoring. PAM thus implements the least privilege principle for the most critical accounts and complements the more broadly based identity and access management, which addresses all user identities. As a core building block of Identity Security, PAM is at the same time a prerequisite for Zero Trust, because permanent, uncontrolled privileges are incompatible with this model.