What Privileged Access Management Is
Three separate problems get sold as one product: where credentials live, how access is granted, and what happened during a session.
Explainer
Three separate problems get sold as one product. Plus the condition every other control works around: administrative rights that are permanent, and the tiering rule that closes the most paths.
6 notes
Three separate problems get sold as one product: where credentials live, how access is granted, and what happened during a session.
Explainer
Domain administrator is the obvious case. The accounts that cause incidents are usually the ones nobody classified as privileged at all.
Reference
Permanent administrative rights are the condition every other control works around. Removing them is the intervention with the largest effect.
Analysis
Vaulting, elevation, secrets management and session brokering are separate capabilities sold in overlapping bundles. Which one solves which problem.
Reference
Storing the password improves attribution and rotation. It does not reduce who can obtain administrative rights, which is the exposure.
Analysis
A shared administrative account means no record of who did anything. The migration to individual accounts is the least glamorous work with the largest audit effect.
Procedure