Privileged access management: admin accounts, vaults, just-in-time access and admin tiering
Eurokommerz, Vienna, since 2006: Private AI/ML · IT Managed Services · Enterprise Training · AI Hardware & Software
- Privileged access management (PAM) covers every account that can change systems, security settings or other accounts: directory and identity provider administrators, hypervisor root and vCenter administrators, backup, BMC, firewall and cloud administrators, local administrator accounts and service accounts
- Administrators get separate named admin accounts that are used only from a privileged access workstation, directly or through a jump host, and never for email or the web, in line with point 11.3.2 of Implementing Regulation 2024/2690, NIST SP 800-53 AC-6(2) and guidance from the NSA, CISA and the NCSC
- Shared and local administrator passwords go into a vault, unique per system, checked out by one named person and changed after use; the vault is a target of its own, and Mandiant reported in July 2025 that UNC3944 scans for PAM solutions and tries to enumerate weakly protected ones for credentials
- Just-in-time access keeps privileged groups and roles empty and grants rights for one task and a limited time after approval; the NSA and CISA advise time-based access for privileged accounts, and the NCSC notes that a stolen temporary credential soon stops working
- Admin tiering keeps tier 0 credentials off lower-tier machines, and we would put the directory, identity provider, PKI and PAM in tier 0 with the hypervisors and backup servers that host or hold domain controllers; break-glass accounts, logs of privileged activity and reviews at planned intervals are the remaining controls
Eurokommerz × Vixen.UNO: Cyber Resilience Talk to an expert →
What privileged access management is and where to start
Privileged access management (PAM) is the set of policies, processes and tools that control the accounts able to change systems, security settings or other accounts. NIST SP 800-53 defines a privileged user as one “authorized (and therefore, trusted) to perform security-relevant functions that ordinary users are not authorized to perform”.
PAM best practices cover an inventory with an owner per account, separate administrator accounts used only from administrator workstations, admin tiers, a vault for shared passwords, just-in-time elevation instead of standing rights, break-glass accounts, and logs and reviews of privileged activity. CISA and the NSA advise in their identity and access management guidance (March 2023) that privileged accounts “should be separately managed using a Privileged Access Management (PAM) solution with strong identity governance”. A tool helps with the vault and elevation, but the inventory and the separate accounts come first; in our zero trust guide for mid-size companies, privileged access is the third step, after identity and devices.
Privileged accounts in a mid-size estate
Each platform brings its own privileged accounts, from root on every ESXi host and the administrator of every baseboard management controller (BMC) to the fallback account on each firewall. The table lists the usual types and a control for each.
| ACCOUNT TYPE | WHAT IT CONTROLS | CONTROL |
|---|---|---|
| Directory and IdP admins | every joined system and every system trusting its groups | tier 0 accounts on tier 0 workstations only; groups empty outside just-in-time elevation |
| vCenter and ESXi admins | every VM, domain controllers included | vCenter roles outside directory groups; host root in the vault |
| Backup administrators | restore points, and restores of any system | own accounts outside the production directory and identity provider, with MFA |
| BMC accounts | power, firmware and console of a server | unique password per BMC in the vault; management network only |
| Firewall and network admins | rules, VPN and routing between zones | named accounts via central authentication; fallback account in the vault |
| Cloud and SaaS admins | a whole tenant, reachable from the internet | cloud-only admin accounts; roles activated just in time |
| Service accounts | whatever the application reaches | minimum permissions, no interactive sign-in, an owner, rotation through the vault |
| Local administrator accounts | every machine that shares the password | unique password per machine, rotated by a tool |
| Break-glass accounts | everything, when sign-in or the vault fails | sealed offline credentials, alert on every use, scheduled tests |
Our summary, drawing on NSA and CISA advisory AA23-278A (October 2023), the NCSC’s secure system administration guidance (reviewed 7 June 2023), Broadcom’s vCenter baseline (16 September 2026) and Mandiant (23 July 2025).
Build the list from exports: members of the directory’s administrative groups, nested groups included; role assignments in cloud tenants and SaaS consoles; local accounts on hypervisors, BMCs, firewalls and appliances; and accounts that run services or never change their password. Point 11.2.2(e) of Implementing Regulation (EU) 2024/2690 asks for a register of access rights granted, and point 11.5.3 allows identities shared by several people only where they are necessary for business or operational reasons and subject to an explicit approval process and documentation.
Our cyber resilience service sets up privileged access management as part of a zero-trust architecture following NIST CSF 2.0. Send us the number of administrator and service accounts per system and whether their passwords are kept in a vault today.
How attackers use privileged accounts
In advisory AA23-278A (October 2023), the NSA and CISA listed the ten most common network misconfigurations their red, blue, hunt and incident response teams found, including improper separation of user and administrator privilege. They describe accounts with several roles, service accounts whose elevated rights pass to whoever compromises the application, and administrator accounts used for everyday tasks. Once such an account signs in to a compromised host, an attacker can steal its credentials and authentication token and move through the domain. The advisory’s mitigations include time-based access for privileged accounts and no privileged accounts for email or web browsing.
In AA24-038A (February 2024), CISA, the NSA, the FBI and partner agencies describe Volt Typhoon actors who aim “to obtain administrator credentials within the network” and achieve full domain compromise by extracting the directory database from a domain controller. The advisory recommends separate user and privileged accounts and just-in-time and just-enough access when administrators elevate.
Mandiant reported on 23 July 2025 that UNC3944 scans for password managers and PAM solutions and tries to enumerate weakly protected ones for credentials. How the same actors reached vCenter and the ESXi hosts is in our guide to ESXi ransomware hardening.
Separate admin accounts, admin workstations and admin tiering
Point 11.3.2 of the regulation asks for strong authentication such as MFA for privileged accounts, accounts used exclusively for system administration, privileges individualised and restricted “to the highest extent possible”, and administration accounts that connect only to administration systems. Point 11.6.2(f) adds separate credentials, and point 11.4.2 keeps administration systems for administration, logically separated from other application software. NIST SP 800-53 AC-6(2) asks privileged users to use non-privileged accounts or roles “when accessing nonsecurity functions”.
Each administrator keeps an everyday account for email and the web and uses named administrator accounts only from a privileged access workstation (PAW) that runs nothing but administration tools, directly or through a jump host; our phishing-resistant MFA guide covers their protection. The NCSC calls administering from a device less trusted than the system “browse up”, an anti-pattern, because an attacker who compromises the device could inherit its access, and email exposes a device to phishing. It adds that an administration proxy alone does not stop a compromised management device, so a jump host reached from an everyday laptop does not replace a PAW.
For admin tiering, the NCSC bases tiers on “the potential impact of a compromise” and calls tier 0 “the root of trust that all other administration relies upon”, and the Volt Typhoon advisory asks for a tiering model that segregates administrative accounts by access level and risk. The NCSC’s example has four tiers; for 200 to 2,000 staff we would use three: tier 0 for the directory, the identity provider, the PKI and the PAM system, tier 1 for servers and applications, and tier 2 for workstations. Tier 0 accounts never sign in to lower-tier machines, where a compromise would expose their credentials.
A hypervisor or backup server that hosts or holds the domain controllers belongs in tier 0, since whoever controls it can read or restore their disks. Mandiant advises running tier 0 assets, among them domain controllers, PAM and Veeam, in a dedicated “identity cluster” and calls hosting them on the virtualisation platform they secure “a critical architectural flaw”.
Password vaults, rotation and service accounts
Shared and local administrator passwords belong in a vault. AA23-278A advises considering password managers “to generate and store passwords” and not reusing local administrator passwords across systems, and AA24-038A advises against storing plaintext credentials on any system. A unique password per system, checked out by one named person and changed after use, makes each session on a shared account traceable to one person. Point 11.6.2(c) asks for credential changes initially, at predefined intervals and upon suspicion of compromise, which a vault can run on a schedule and on demand.
AA23-278A asks that service accounts get only “the permissions necessary for the services they control to operate” and recommends a review process that looks for cleartext credentials in files and systems; include scripts and scheduled tasks. Deny service accounts interactive sign-in, record an owner for each and rotate their passwords through the vault where the application can follow. Our guide to the Veeam hardened repository covers the separate administrator and security officer accounts of the backup repository.
In the NCSC’s words, “The PAM system is itself an attack surface”, so the vault sits in tier 0, administered only from tier 0 workstations, patched and backed up; other administrators reach only its check-out interface. The NCSC also advises high availability and an emergency process for reaching systems when PAM is down, which a ransomware recovery needs if the vault is encrypted too.
Just-in-time access, approvals and supplier access
Just-in-time access leaves privileged groups and roles empty and grants rights for one task and a limited time. CISA and the NSA describe users being “temporarily granted privileged access in order to complete a specific task or resolve an issue”. In the NCSC’s model the administrator’s credential only requests access, an approval releases a temporary credential, and a stolen one is useful only briefly. Approval can come from a second person, a vote among several approvers or rules such as a linked change ticket.
The NSA and CISA advisory describes administrator accounts disabled automatically at the directory level and enabled on request for a set time, and for cloud environments names “per-session federated claims or privileged access management tools”. NIST SP 800-53 AC-2(2) asks that temporary and emergency accounts be removed or disabled automatically after a defined period.
For suppliers, point 11.2.2(d) limits third-party access “in scope and in duration”, and point 6.7.2(h) allows service providers’ connections “only after an authorisation request and for a set time period”. A supplier account stays disabled until a ticket opens it for the maintenance window, and the session runs through the jump host. Session recordings show what a named person did and are personal data under the GDPR, so set their purpose, retention period and viewers before recording.
Break-glass accounts and logs of privileged activity
Break-glass accounts cover the day the identity provider, the MFA service or the vault is down, and the NCSC asks that this emergency path be “carefully protected”. Keep the identity provider’s emergency credentials offline and sealed, with copies of the root and local administrator passwords of the hypervisors, backup server, BMCs and firewalls, even where the vault holds them, so a recovery does not depend on the vault. Rotate these by hand at set intervals, since automatic rotation would leave the sealed copies outdated. Each use triggers an alert, a review and new credentials, and each account is tested on a schedule.
Among the events to log, point 3.2.3 of the regulation lists, where appropriate, the creation, modification or deletion of users, extension of permissions and all privileged access and administrative activities, and point 3.2.5 asks that logs be protected from unauthorised access or changes. NIST SP 800-53 adds AC-6(9), “Log the execution of privileged functions”, and AC-2(7), which asks to monitor privileged role assignments and revoke access when they are no longer appropriate. Send these events to a collector administrators cannot edit, and alert on new members of tier 0 groups, privileged sign-ins outside administrator workstations, vault check-outs outside change windows and every break-glass sign-in.
PAM requirements in Regulation 2024/2690 and NIST SP 800-53
Implementing Regulation (EU) 2024/2690 details the NIS2 measures for the digital infrastructure and ICT providers listed in its Article 1, such as cloud, data centre and managed service providers. For other companies it is a reference, not an obligation, and whether NIS2 applies is a legal assessment for the company’s legal department. The table maps its access control points and related NIST SP 800-53 Rev. 5 controls to evidence; all ten NIS2 measures are in our NIS2 Article 21 guide.
| REQUIREMENT | 2024/2690; SP 800-53 | EVIDENCE |
|---|---|---|
| Admin-only accounts | 11.3.2(b), 11.6.2(f); AC-6(2) | admin accounts listed, each linked to one person |
| Admin systems only for admin | 11.3.2(d), 11.4.2 | PAW and jump host inventory; management network firewall rules |
| Least privilege | 11.2.2(a), 11.3.2(c); AC-6, AC-6(5) | role matrix per system; count of standing assignments |
| Reviews at planned intervals | 11.2.3, 11.3.3; AC-6(7) | dated review record with the changes |
| Shared identities approved | 11.5.3; AC-2(9) | approval per shared account; vault check-out log |
| Temporary and third-party | 11.2.2(d), 6.7.2(h); AC-2(2) | expiry settings; supplier tickets with start and end |
| Privileged activity logged | 3.2.3, 11.2.2(f); AC-2(7), AC-6(9) | log samples, alert rules, last alert handled |
Implementing Regulation (EU) 2024/2690 of 17 October 2024, Annex points 3.2, 6.7 and 11.2 to 11.6; NIST SP 800-53 Rev. 5, release 5.2.0 (August 2025). The mapping and the evidence column are our recommendation.
Our cyber resilience assessment covers infrastructure, access, backups and NIS2 requirements and ends with a risk map and a prioritised action plan. Tell us which of these records you can produce today and how often privileged rights are reviewed.
What we do
Under Cyber Resilience, our engineering partner Vixen.UNO builds a zero-trust architecture following NIST CSF 2.0 with privileged access management, multi-factor authentication, network segmentation, mobile device management (MDM) and data loss prevention (DLP). The paid technical assessment delivers a risk map, a compliance analysis and a prioritised action plan. Changes roll out in agreed maintenance windows with a rollback plan. During the project Vixen.UNO works in your environment under your access controls; access is granted by you, scoped to what the work needs, and ends with the engagement, as our security and compliance page describes. The first call is free of charge, and the price of the technical assessment is fixed before work begins.
FAQ
What is privileged access management (PAM)?
What are PAM best practices?
What counts as a privileged account?
What is just-in-time access?
What is admin tiering (tier 0, tier 1 and tier 2)?
What does NIS2 require for privileged accounts?
Send us the number of administrator, service and break-glass accounts per system, how administrators sign in to the directory, hypervisors, backup and firewalls today, and whether shared passwords are kept in a vault. We reply within one business day to arrange a first call, from which you leave with two or three possible solution scenarios. The first call is free of charge.
Talk to an expertWe reply within one business day