Privileged Access Management

Manish Garg
Manish Garg Associate of (ISC)² · RingSafe
Apr 26, 2026
5 min read
Read as

Last updated: April 29, 2026

PAM controls — vaulting, session brokering, JIT elevation, recording, tiered admin model, PAW, cloud-native PAM. Why PAM is the highest-leverage control for regulated orgs.

A Mumbai-based payment-aggregator’s domain admin password was on a sticky note. When a new system administrator joined, his predecessor handed him the laminated card. Two months later, an internal investigation traced an unauthorised wire transfer back to the use of the domain admin credential — by someone who had photographed the sticky note while consulting on-site. The breach cost ₹4.7 crore in fraudulent transactions and a six-month RBI notification. PAM (privileged access management) is not optional for any organisation processing money. This module covers the fundamentals.

What “privileged” means

Privileged accounts hold elevated permissions. Examples:

  • Domain admin / Entra ID Global Admin
  • Local administrator on servers / workstations
  • Database root / DBA accounts
  • Cloud root / org admin / IAM admin
  • SaaS super-admin (Salesforce, Workday, GitHub org owner)
  • Network device enable / privilege-15
  • Application admin in critical systems
  • Break-glass / emergency access accounts

If an account can change other accounts’ permissions, exfiltrate data en masse, deploy code, or move money, it is privileged.

DPDP Act in your stack?

Get a DPDP gap assessment

Free 30-minute call. We map your data flows against DPDP §8 obligations and tell you exactly which gaps to fix first. Auditor-defensible output.

Book DPDP scoping call Replies in 4 working hrs · India-only · Senior consultants