Privileged Access Management (PAM)
Also known as: PAM · Privileged Identity Management · PIM
Definition
Privileged Access Management (PAM) is the category of security platforms that protect privileged accounts — root, domain admin, service accounts — through credential vaulting, session monitoring, and just-in-time elevation.
PAM platforms vault privileged credentials so users never see them directly. Privileged sessions are launched through a PAM proxy that records what happens. JIT elevation grants admin rights only for the duration of a specific task. Leaders include CyberArk, BeyondTrust, Delinea, and HashiCorp Vault (for DevOps secrets).
Auditor expectations have shifted dramatically toward "zero standing privilege" — no permanently-elevated accounts. The 2025 CyberArk study found only 1% of organizations had fully adopted JIT privileged access; the gap is the single largest IAM modernization opportunity.