PAM (Privileged Access Management)
Last updated
Definition
Privileged Access Management is the set of controls and tooling that governs accounts capable of changing a system rather than just using it – domain and Global Admin, local administrator, service accounts, and the consoles of the RMM, hypervisor, firewall, and backup platform. PAM vaults those credentials, grants elevation just-in-time for a bounded window instead of leaving it standing, and logs or records what was done with it. Where IAM covers every identity, PAM covers the few that can do the most damage.
Why it matters to an MSP
Your technicians are the most privileged users in every client environment you manage, and a standing admin account that works across forty tenants is one phished technician away from forty incidents. GDAP decides which roles your partner tenant may hold in a customer's Microsoft 365; PAM decides how a technician actually exercises them – activation through Entra PIM for a few hours with a ticket reference, phishing-resistant MFA on the elevation, and no shared admin logins. Insurers now ask about it by name on questionnaires, and a "no" moves premiums or eligibility. On the client side, the highest-return move is removing local admin from end users – the first thing ransomware and commodity malware need – and replacing it with endpoint privilege management that approves specific installs on request. Expect a burst of elevation tickets in month one, then pre-approved application rules absorb most of it. Endpoint PAM tooling typically runs $2–$5 per endpoint per month, sold at margin inside a security tier. The one thing PAM cannot fix is a technician using a personal account for admin work; that is a policy and offboarding discipline, covered in identity and access for SMB.
Related terms: GDAP, IAM, Zero Trust, MFA