NIST describes a privileged account as a system account with the permissions of a privileged user; this includes local and Domain Admins, break-glass accounts as well as application and Service Accounts. It is precisely these accounts that open up security-relevant functions denied to ordinary users - and they are therefore attacked deliberately. According to the Verizon DBIR 2025, credential abuse at 22 percent is the most common entry vector, and 88 percent of attacks on web applications used stolen credentials.
Privileged Access Management (PAM)
Privileged accounts are the shortest path to compromising entire environments. PAM governs their provisioning, use and monitoring across governance, architecture and operations - VamiSec supports design, rollout and ongoing operation.
22%credential abuse as the most common initial access vector (Verizon DBIR 2025)
88%of attacks on web applications used stolen credentials (DBIR 2025)
3tiers in the Microsoft Enterprise Access Model - Tier 0 to Tier 2 with an enforced hierarchy
0permanently dormant permissions - the Zero Standing Privilege target state
Privileged access - administrator, break-glass, service and Service Accounts - is the preferred target for attackers, because it opens up far-reaching control over systems, data and security functions. The Verizon Data Breach Investigations Report 2025 identifies credential abuse at 22 percent as the most common initial access vector; 88 percent of attacks on web applications used stolen credentials. Privileged Access Management (PAM) is the discipline within identity and access management that governs the provisioning, use and monitoring of these accounts. Effective PAM is not merely a tool but an interplay of governance, processes and architecture - from the Zero Standing Privilege principle through tiering to gapless logging. VamiSec supports PAM initiatives vendor-neutrally, from requirements gathering to operation.
The Essentials at a Glance
Six topic blocks - tap to expand.
Core building blocks: from vaulting to Zero Standing Privilege
Five building blocks govern privileged access - tap a block for details.
- Credentials, SSH keys and API tokens are secured through encrypted Credential Vaulting.
credentialsSSH keysAPI tokens
- The vaulted credentials, SSH keys and API tokens are rotated regularly.
- Privileged sessions are proxied and captured via tamper-proof Session Recording.
proxyingSession Recording
- Just-in-Time access grants rights only temporarily and after activation.
- Microsoft defines JIT as a model in which permissions are granted exclusively when needed and expire afterwards.
activationwhen needed
- Zero Standing Privilege means no permanently dormant permissions.
- Combined with Least Privilege and approval workflows before every issuance.
Least Privilegeapproval workflows
Standards & Sources
The content on this page is based on the following publicly available guides and studies.
NIST SP 1800-18 & CSRC-Glossar: Privileged Account Management
Definition of privileged accounts (local/Domain Admins, break-glass, application and Service Accounts) and classification of PAM as a sub-discipline of IAM.
Microsoft Learn: Entra PIM, Enterprise Access Model & Privileged Access Workstations
Just-in-Time activation, eligible/active, Conditional Access for privileged roles, tier model and PAW.
ISO/IEC 27001:2022, Annex A Control 8.2 'Use of privileged access rights'
Restriction and control of privileged access rights; related controls A.5.15, A.5.18 and A.8.5 (paraphrased, not standard text).
BSI IT-Grundschutz-Kompendium, Baustein ORP.4 'Identitaets- und Berechtigungsmanagement' (Edition 2023)
Least Privilege (A2), MFA for far-reaching permissions (A10), separation of duties (A4) and the four-eyes principle for administrative activities (A24).
VamiSec PAM-Anforderungskatalog (Projektmethodik)
Internal requirements catalog with 9 categories as well as priority, lifecycle and role model; foundation of the vendor-neutral consulting methodology.
Related Services
Roll out PAM in a structured way - from requirement to operation
VamiSec supports you vendor-neutrally with the requirements catalog, tiering concept, tool selection, rollout and operation. Talk to us about your PAM initiative.