What is Privileged Access Management (PAM)?
PAM is the set of controls used to protect, monitor, and audit privileged accounts and privileged sessions. It covers human administrators, emergency accounts, service accounts, and application-management accounts. Common controls include account discovery, strong authentication, credential or key protection, approval and just-in-time access, session monitoring, and rapid revocation. PAM does not require passwords, and frequent password changes are not its defining control.
Why it matters
A privileged account can change security controls, access sensitive data, or disrupt important systems. PAM reduces standing authority and makes privileged use easier to approve, trace, and revoke.
How it works
- Discover privileged human and workload accounts, their credentials, owners, and reachable systems.
- Apply least privilege, strong authentication, approval, time limits, and protected credential or key handling before use.
- Monitor and audit privileged activity, review access, and revoke an account or session when it is no longer required.
Example
An engineer reaches an SSH administration route only after identity-provider sign-in and a Pomerium policy check for the approved operations group and device. Authorization logs record the access decision.
Pomerium boundary
Pomerium can protect web, TCP, UDP, and native SSH administration routes with identity- and context-aware policy. Pomerium Enterprise can record, store, and play back interactive native SSH sessions. Pomerium does not provide every PAM function, such as privileged account discovery or credential vaulting.
Limits and non-claims
- A route gateway does not discover, rotate, or vault every privileged credential in an organization.
- Emergency and service accounts need separate lifecycle, ownership, and recovery controls.
- Logs help investigation only when they are complete, protected, retained, and reviewed.
Evaluation checklist
- Which privileged identities, credentials, resources, and actions are in the control scope?
- Are elevation, approval, credential use, session evidence, and expiry bound to one task?
- Can shared credentials, emergency access, a direct path, or weak recovery bypass PAM?
Sources and further reading
- NIST Privileged Account ManagementPrimary source
- NIST Least Privilege DefinitionsPrimary source
- Pomerium authorization and policy enforcementPomerium documentation
- Pomerium auditing and privileged access managementPomerium documentation
- Pomerium native SSH accessPomerium documentation
- Pomerium SSH session recordingPomerium documentation
