NEWJoin 2M+ software buyers|Get Weekly Insights, Trends & Expert PicksSubscribe free →

Cybersecurity

What Is Privileged Access Management (PAM)? How It Works, PAM vs IAM vs PIM

Rajat Gupta

Written by

Rajat Gupta

Published September 13, 2026

Updated September 28, 2026

Privileged access management (PAM) is the set of controls and tools that protect accounts with elevated rights: domain admins, root, cloud console owners, database superusers, service accounts and the API keys that machines use to talk to each other. A PAM program finds those accounts, locks their credentials in a vault, hands out access only when someone needs it, records what happens during the session and removes the access afterwards. Identity and access management (IAM) decides who a user is and what they can reach in general. PAM governs the small set of accounts that could take the whole environment down.

This guide explains how PAM works in practice, how it differs from IAM, PIM and a password manager, which capabilities matter, and how to roll it out without stalling your admins. If you already know you need a tool, jump to our comparison of the best privileged access management software.

What counts as a privileged account?

A privileged account is any identity that can change systems, security settings or data beyond what a normal user can. Most organisations undercount them, because the obvious admin logins are only a fraction of the total. A realistic inventory includes:

  • Human admin accounts: domain and enterprise admins in Active Directory, global admins in Microsoft Entra ID or Google Workspace, local administrator accounts on laptops and servers, and root on Linux and Unix hosts.
  • Cloud control planes: AWS root and IAM roles with wide permissions, Azure subscription owners, GCP project owners, and the break-glass accounts that sit outside single sign-on.
  • Infrastructure and data: database superusers, Kubernetes cluster-admin, network device admin logins, hypervisor consoles, backup system admins.
  • Business application admins: ERP, HRIS, payroll and CRM administrators who can change payments, salaries or customer records.
  • Non-human identities: service accounts, scheduled task accounts, CI/CD pipeline credentials, API keys, SSH keys and certificates. In cloud-heavy teams these usually outnumber the humans.
  • Third parties: vendors, contractors and managed service providers who log in to support your systems.

Attackers target these accounts because one stolen admin credential skips every layer below it. That is why PAM sits alongside endpoint protection and monitoring in most security programs, not as an add-on to them.

How does privileged access management work?

Most PAM platforms follow the same lifecycle, whether they are self-hosted, delivered as SaaS or built into a cloud provider.

  1. Discover. The tool scans directories, servers, cloud accounts and databases to find privileged accounts, local admins, SSH keys and hard-coded credentials. Discovery is repeated on a schedule, because new accounts appear every week.
  2. Vault. Credentials move into an encrypted vault. Admins stop knowing the actual passwords; they check them out, or the platform injects them into a session so the secret never reaches the admin’s device.
  3. Rotate. The platform changes passwords and keys automatically, after each use or on a schedule, so a leaked credential expires quickly.
  4. Broker access. Users request access to a target. Policies decide whether it is granted automatically, needs approval, or is refused. Access is tied to the person’s own identity through SSO and MFA, not a shared login.
  5. Monitor and record. Sessions over RDP, SSH, database clients, web consoles and Kubernetes are proxied, logged and often video or keystroke recorded. Risky commands can trigger alerts or end the session.
  6. Remove. When the task ends, access expires. The goal is zero standing privilege: nobody holds admin rights permanently unless there is a documented reason.
  7. Report. Audit trails show who accessed what, when, why and with whose approval. This is the evidence auditors ask for in SOC 2, ISO 27001, PCI DSS, HIPAA and SOX reviews.

PAM vs IAM: what is the difference?

Identity and access management covers every user and every application: provisioning, single sign-on, MFA, directory groups and access reviews. PAM is a specialised layer that applies much stricter controls to the small set of identities with elevated rights.

Question IAM PAM
Who is covered? All employees, contractors and often customers Admins, service accounts, machine identities, privileged vendors
Main job Prove identity and grant the right app access Control, record and limit high-risk access
Typical controls SSO, MFA, lifecycle provisioning, SCIM, access reviews Vaulting, rotation, just-in-time elevation, session recording, command control
Access duration Usually standing, based on role Ideally time-bound and approved per task
Where it sits Front door to SaaS and internal apps Path to servers, databases, cloud consoles and admin tools

The two depend on each other. PAM tools use your IAM provider for login and group membership, and IAM platforms increasingly add basic privileged features. For a view of the wider identity stack, see our roundup of identity and access management tools, and our guides to single sign-on and MFA software, which every PAM login should sit behind.

PAM vs PIM: are they the same thing?

The acronyms overlap, and vendors use them loosely.

  • Privileged identity management (PIM) focuses on the identity side: which people hold privileged roles, making those roles eligible instead of permanent, and requiring activation with approval and justification. Microsoft uses the name for Entra ID Privileged Identity Management, which governs admin roles in Entra ID, Azure and Microsoft 365.
  • Privileged account management is an older term for vaulting and rotating the credentials of shared admin accounts.
  • Privileged access management is the umbrella: accounts, credentials, sessions, elevation and audit across the whole estate.

In practice, a Microsoft-centric company might use PIM for cloud admin roles and a dedicated PAM product for servers, databases, network gear and third-party access.

PAM vs a password manager

A business password manager stores and shares credentials for people. Some include admin-friendly features such as shared vaults and audit logs. A PAM platform goes further: it rotates credentials on the target system, hides the password from the user entirely, brokers and records the session, and enforces approval workflows. A password manager is a good baseline for everyday logins; it does not replace PAM for domain admins, production databases or vendor access.

PAM vs secrets management

Secrets management handles credentials used by applications and pipelines: database passwords, API tokens, certificates and encryption keys that code reads at runtime. Tools like HashiCorp Vault and AWS Secrets Manager focus on that developer workflow. PAM focuses on humans and admin sessions, though most large PAM vendors now sell a secrets module too. Our guide to secrets management tools covers that side in detail.

What is just-in-time (JIT) access?

Just-in-time access grants privileges only for the time a task needs, then removes them. An engineer requests access to a production database for a named ticket, a manager or on-call lead approves it, the platform creates or unlocks access for, say, an hour, and then revokes it. JIT shrinks the attack surface because stolen credentials are useless when no standing access exists.

JIT comes in a few forms:

  • Ephemeral accounts created for the session and deleted afterwards.
  • Group or role elevation, where a user is added to an admin group temporarily.
  • Short-lived certificates, common in infrastructure access tools, where a certificate expires after the approved window.
  • Endpoint elevation, where an application runs with admin rights without the user holding local admin.

Core capabilities to expect from a PAM tool

Capability What it does Why it matters
Account discovery Finds privileged accounts, keys and local admins You cannot protect what you have not found
Credential vault and rotation Stores and changes passwords and keys automatically Limits the life of any leaked credential
Session management Proxies, records and can terminate sessions Evidence for investigations and audits
Just-in-time access and approvals Time-bound access with workflow Removes standing privilege
Endpoint privilege management Removes local admin, elevates approved apps Blocks common ransomware paths
Remote and vendor access VPN-less access for third parties Replaces shared VPN accounts
Secrets for machines Delivers credentials to apps and pipelines Removes hard-coded passwords
Analytics and alerting Flags risky commands and unusual behaviour Feeds your SIEM and SOAR tooling

What problems does PAM solve?

Shared admin passwords. When five people know the same root password, nobody can say who did what. PAM ties every session to a named person.

Credential theft and lateral movement. Attackers who phish one user try to harvest admin credentials from memory or scripts. Vaulting, rotation and removing local admin rights cut those paths off.

Third-party risk. Vendors with always-on VPN accounts are a frequent entry point. PAM gives them brokered, recorded, time-limited access to only the systems they support.

Audit findings. Auditors regularly flag excessive admin rights, missing access reviews and unlogged changes. PAM produces the evidence in one place.

Cyber insurance requirements. Insurers commonly ask about MFA on privileged accounts and controls over admin access in their applications. Check your own policy questionnaire, since requirements vary by carrier.

How is PAM deployed?

  • Self-hosted. Vault, session proxies and management servers run in your data center or cloud account. Maximum control, more infrastructure to patch and scale.
  • SaaS. The vendor runs the control plane; you deploy lightweight connectors or gateways close to your targets. Faster to start and easier to maintain.
  • Cloud-native and developer-focused. Tools built for infrastructure access to servers, Kubernetes and databases, often agent- or proxy-based and driven by config files.
  • Built into your cloud or identity provider. Microsoft Entra ID Privileged Identity Management and short-lived role assumption in AWS, Azure and Google Cloud cover part of the need, usually for cloud admin roles only.

How to implement PAM in six steps

  1. Inventory and rank. Run discovery and rank accounts by blast radius: domain admins, cloud root, production databases and backup admins first.
  2. Vault the crown jewels. Put the top tier behind the vault with rotation and MFA before trying to cover everything.
  3. Remove local admin on endpoints. Use endpoint privilege management to elevate specific apps, not users.
  4. Broker third-party access. Move vendors off shared VPN accounts to recorded, approved sessions.
  5. Introduce JIT. Convert standing admin rights to eligible, time-bound access, starting with cloud consoles.
  6. Tackle machine credentials. Replace hard-coded secrets in scripts and pipelines with vault lookups.

Rollouts fail when admins find the new path slower than the old one. Pilot with one infrastructure team, measure the extra seconds per login, and fix friction before scaling.

Metrics to track

  • Share of privileged accounts vaulted and rotated.
  • Number of standing admin assignments, trending down.
  • Share of privileged sessions brokered and recorded.
  • Endpoints with local admin removed.
  • Hard-coded secrets found versus remediated.
  • Median time to approve a JIT request, so security does not become a bottleneck.

How much does PAM cost?

PAM vendors price in several ways: per privileged user, per named admin, per managed target (server, database or endpoint), per concurrent session, or as bundles that combine vaulting, remote access and endpoint modules. Enterprise suites are usually quote-based, and total cost includes implementation, connectors and admin time. Developer-focused infrastructure access tools tend to price per user. Our PAM software comparison explains each pricing model and what drives the final number, and the PAM software category lists vendors side by side.

What is privileged access management in simple terms?

It is a way to control the accounts that can change or break your systems. PAM locks admin credentials in a vault, grants access only when needed, records what admins do and removes access afterwards.

Is PAM part of IAM?

Yes, most frameworks treat PAM as a specialised discipline within identity security. IAM handles everyday access for everyone; PAM adds stricter controls for admins, service accounts and vendors with elevated rights.

What is the difference between PAM and PIM?

PIM manages who holds privileged roles and makes those roles time-bound and approved. PAM is broader and also covers credential vaulting, rotation, session recording and access to servers, databases and network devices.

Do small businesses need PAM?

Any company with shared admin passwords, outside IT providers or production cloud accounts has the core risk. Smaller teams often start with a business password manager, MFA on every admin account and cloud-native elevation, then add a PAM tool as the number of systems and admins grows.

What does zero standing privilege mean?

No one keeps admin rights by default. Privileges are granted for a specific task and time window, then removed automatically.

Can a password manager replace PAM?

Not for high-risk systems. A password manager stores and shares credentials, while PAM rotates them on the target, hides them from users, records sessions and enforces approvals.

Which compliance frameworks expect PAM controls?

Controls over privileged access appear in SOC 2, ISO 27001, PCI DSS, HIPAA security guidance, SOX IT general controls and NIST frameworks. None of them names a product; they expect least privilege, logging and regular review, which PAM helps prove.

Spotsaas advisor
Find the best IT Management Software for your team
  • Independent picks for exactly what you just read about
  • Matched to your team size & needs
  • Vendors don't pay for placement

Step 1 of 4

How big is your team?

We tailor recommendations to companies your size.

Trusted by teams at

Related Articles