Last updated: April 29, 2026
A Mumbai-based payment-aggregator’s domain admin password was on a sticky note. When a new system administrator joined, his predecessor handed him the laminated card. Two months later, an internal investigation traced an unauthorised wire transfer back to the use of the domain admin credential — by someone who had photographed the sticky note while consulting on-site. The breach cost ₹4.7 crore in fraudulent transactions and a six-month RBI notification. PAM (privileged access management) is not optional for any organisation processing money. This module covers the fundamentals.
What “privileged” means
Privileged accounts hold elevated permissions. Examples:
- Domain admin / Entra ID Global Admin
- Local administrator on servers / workstations
- Database root / DBA accounts
- Cloud root / org admin / IAM admin
- SaaS super-admin (Salesforce, Workday, GitHub org owner)
- Network device enable / privilege-15
- Application admin in critical systems
- Break-glass / emergency access accounts
If an account can change other accounts’ permissions, exfiltrate data en masse, deploy code, or move money, it is privileged.
Get a DPDP gap assessment
Free 30-minute call. We map your data flows against DPDP §8 obligations and tell you exactly which gaps to fix first. Auditor-defensible output.