BLOG · GUIDE ·

Privileged access management: admin accounts, vaults, just-in-time access and admin tiering

Eurokommerz, Vienna, since 2006: Private AI/ML · IT Managed Services · Enterprise Training · AI Hardware & Software

IN BRIEF
  • Privileged access management (PAM) covers every account that can change systems, security settings or other accounts: directory and identity provider administrators, hypervisor root and vCenter administrators, backup, BMC, firewall and cloud administrators, local administrator accounts and service accounts
  • Administrators get separate named admin accounts that are used only from a privileged access workstation, directly or through a jump host, and never for email or the web, in line with point 11.3.2 of Implementing Regulation 2024/2690, NIST SP 800-53 AC-6(2) and guidance from the NSA, CISA and the NCSC
  • Shared and local administrator passwords go into a vault, unique per system, checked out by one named person and changed after use; the vault is a target of its own, and Mandiant reported in July 2025 that UNC3944 scans for PAM solutions and tries to enumerate weakly protected ones for credentials
  • Just-in-time access keeps privileged groups and roles empty and grants rights for one task and a limited time after approval; the NSA and CISA advise time-based access for privileged accounts, and the NCSC notes that a stolen temporary credential soon stops working
  • Admin tiering keeps tier 0 credentials off lower-tier machines, and we would put the directory, identity provider, PKI and PAM in tier 0 with the hypervisors and backup servers that host or hold domain controllers; break-glass accounts, logs of privileged activity and reviews at planned intervals are the remaining controls

Eurokommerz × Vixen.UNO: Cyber Resilience  Talk to an expert →

What privileged access management is and where to start

Privileged access management (PAM) is the set of policies, processes and tools that control the accounts able to change systems, security settings or other accounts. NIST SP 800-53 defines a privileged user as one “authorized (and therefore, trusted) to perform security-relevant functions that ordinary users are not authorized to perform”.

PAM best practices cover an inventory with an owner per account, separate administrator accounts used only from administrator workstations, admin tiers, a vault for shared passwords, just-in-time elevation instead of standing rights, break-glass accounts, and logs and reviews of privileged activity. CISA and the NSA advise in their identity and access management guidance (March 2023) that privileged accounts “should be separately managed using a Privileged Access Management (PAM) solution with strong identity governance”. A tool helps with the vault and elevation, but the inventory and the separate accounts come first; in our zero trust guide for mid-size companies, privileged access is the third step, after identity and devices.

Privileged accounts in a mid-size estate

Each platform brings its own privileged accounts, from root on every ESXi host and the administrator of every baseboard management controller (BMC) to the fallback account on each firewall. The table lists the usual types and a control for each.

ACCOUNT TYPEWHAT IT CONTROLSCONTROL
Directory and IdP adminsevery joined system and every system trusting its groupstier 0 accounts on tier 0 workstations only; groups empty outside just-in-time elevation
vCenter and ESXi adminsevery VM, domain controllers includedvCenter roles outside directory groups; host root in the vault
Backup administratorsrestore points, and restores of any systemown accounts outside the production directory and identity provider, with MFA
BMC accountspower, firmware and console of a serverunique password per BMC in the vault; management network only
Firewall and network adminsrules, VPN and routing between zonesnamed accounts via central authentication; fallback account in the vault
Cloud and SaaS adminsa whole tenant, reachable from the internetcloud-only admin accounts; roles activated just in time
Service accountswhatever the application reachesminimum permissions, no interactive sign-in, an owner, rotation through the vault
Local administrator accountsevery machine that shares the passwordunique password per machine, rotated by a tool
Break-glass accountseverything, when sign-in or the vault failssealed offline credentials, alert on every use, scheduled tests

Our summary, drawing on NSA and CISA advisory AA23-278A (October 2023), the NCSC’s secure system administration guidance (reviewed 7 June 2023), Broadcom’s vCenter baseline (16 September 2026) and Mandiant (23 July 2025).

Build the list from exports: members of the directory’s administrative groups, nested groups included; role assignments in cloud tenants and SaaS consoles; local accounts on hypervisors, BMCs, firewalls and appliances; and accounts that run services or never change their password. Point 11.2.2(e) of Implementing Regulation (EU) 2024/2690 asks for a register of access rights granted, and point 11.5.3 allows identities shared by several people only where they are necessary for business or operational reasons and subject to an explicit approval process and documentation.

Our cyber resilience service sets up privileged access management as part of a zero-trust architecture following NIST CSF 2.0. Send us the number of administrator and service accounts per system and whether their passwords are kept in a vault today.

How attackers use privileged accounts

In advisory AA23-278A (October 2023), the NSA and CISA listed the ten most common network misconfigurations their red, blue, hunt and incident response teams found, including improper separation of user and administrator privilege. They describe accounts with several roles, service accounts whose elevated rights pass to whoever compromises the application, and administrator accounts used for everyday tasks. Once such an account signs in to a compromised host, an attacker can steal its credentials and authentication token and move through the domain. The advisory’s mitigations include time-based access for privileged accounts and no privileged accounts for email or web browsing.

In AA24-038A (February 2024), CISA, the NSA, the FBI and partner agencies describe Volt Typhoon actors who aim “to obtain administrator credentials within the network” and achieve full domain compromise by extracting the directory database from a domain controller. The advisory recommends separate user and privileged accounts and just-in-time and just-enough access when administrators elevate.

Mandiant reported on 23 July 2025 that UNC3944 scans for password managers and PAM solutions and tries to enumerate weakly protected ones for credentials. How the same actors reached vCenter and the ESXi hosts is in our guide to ESXi ransomware hardening.

Separate admin accounts, admin workstations and admin tiering

Point 11.3.2 of the regulation asks for strong authentication such as MFA for privileged accounts, accounts used exclusively for system administration, privileges individualised and restricted “to the highest extent possible”, and administration accounts that connect only to administration systems. Point 11.6.2(f) adds separate credentials, and point 11.4.2 keeps administration systems for administration, logically separated from other application software. NIST SP 800-53 AC-6(2) asks privileged users to use non-privileged accounts or roles “when accessing nonsecurity functions”.

Each administrator keeps an everyday account for email and the web and uses named administrator accounts only from a privileged access workstation (PAW) that runs nothing but administration tools, directly or through a jump host; our phishing-resistant MFA guide covers their protection. The NCSC calls administering from a device less trusted than the system “browse up”, an anti-pattern, because an attacker who compromises the device could inherit its access, and email exposes a device to phishing. It adds that an administration proxy alone does not stop a compromised management device, so a jump host reached from an everyday laptop does not replace a PAW.

For admin tiering, the NCSC bases tiers on “the potential impact of a compromise” and calls tier 0 “the root of trust that all other administration relies upon”, and the Volt Typhoon advisory asks for a tiering model that segregates administrative accounts by access level and risk. The NCSC’s example has four tiers; for 200 to 2,000 staff we would use three: tier 0 for the directory, the identity provider, the PKI and the PAM system, tier 1 for servers and applications, and tier 2 for workstations. Tier 0 accounts never sign in to lower-tier machines, where a compromise would expose their credentials.

A hypervisor or backup server that hosts or holds the domain controllers belongs in tier 0, since whoever controls it can read or restore their disks. Mandiant advises running tier 0 assets, among them domain controllers, PAM and Veeam, in a dedicated “identity cluster” and calls hosting them on the virtualisation platform they secure “a critical architectural flaw”.

Password vaults, rotation and service accounts

Shared and local administrator passwords belong in a vault. AA23-278A advises considering password managers “to generate and store passwords” and not reusing local administrator passwords across systems, and AA24-038A advises against storing plaintext credentials on any system. A unique password per system, checked out by one named person and changed after use, makes each session on a shared account traceable to one person. Point 11.6.2(c) asks for credential changes initially, at predefined intervals and upon suspicion of compromise, which a vault can run on a schedule and on demand.

AA23-278A asks that service accounts get only “the permissions necessary for the services they control to operate” and recommends a review process that looks for cleartext credentials in files and systems; include scripts and scheduled tasks. Deny service accounts interactive sign-in, record an owner for each and rotate their passwords through the vault where the application can follow. Our guide to the Veeam hardened repository covers the separate administrator and security officer accounts of the backup repository.

In the NCSC’s words, “The PAM system is itself an attack surface”, so the vault sits in tier 0, administered only from tier 0 workstations, patched and backed up; other administrators reach only its check-out interface. The NCSC also advises high availability and an emergency process for reaching systems when PAM is down, which a ransomware recovery needs if the vault is encrypted too.

Just-in-time access, approvals and supplier access

Just-in-time access leaves privileged groups and roles empty and grants rights for one task and a limited time. CISA and the NSA describe users being “temporarily granted privileged access in order to complete a specific task or resolve an issue”. In the NCSC’s model the administrator’s credential only requests access, an approval releases a temporary credential, and a stolen one is useful only briefly. Approval can come from a second person, a vote among several approvers or rules such as a linked change ticket.

The NSA and CISA advisory describes administrator accounts disabled automatically at the directory level and enabled on request for a set time, and for cloud environments names “per-session federated claims or privileged access management tools”. NIST SP 800-53 AC-2(2) asks that temporary and emergency accounts be removed or disabled automatically after a defined period.

For suppliers, point 11.2.2(d) limits third-party access “in scope and in duration”, and point 6.7.2(h) allows service providers’ connections “only after an authorisation request and for a set time period”. A supplier account stays disabled until a ticket opens it for the maintenance window, and the session runs through the jump host. Session recordings show what a named person did and are personal data under the GDPR, so set their purpose, retention period and viewers before recording.

Break-glass accounts and logs of privileged activity

Break-glass accounts cover the day the identity provider, the MFA service or the vault is down, and the NCSC asks that this emergency path be “carefully protected”. Keep the identity provider’s emergency credentials offline and sealed, with copies of the root and local administrator passwords of the hypervisors, backup server, BMCs and firewalls, even where the vault holds them, so a recovery does not depend on the vault. Rotate these by hand at set intervals, since automatic rotation would leave the sealed copies outdated. Each use triggers an alert, a review and new credentials, and each account is tested on a schedule.

Among the events to log, point 3.2.3 of the regulation lists, where appropriate, the creation, modification or deletion of users, extension of permissions and all privileged access and administrative activities, and point 3.2.5 asks that logs be protected from unauthorised access or changes. NIST SP 800-53 adds AC-6(9), “Log the execution of privileged functions”, and AC-2(7), which asks to monitor privileged role assignments and revoke access when they are no longer appropriate. Send these events to a collector administrators cannot edit, and alert on new members of tier 0 groups, privileged sign-ins outside administrator workstations, vault check-outs outside change windows and every break-glass sign-in.

PAM requirements in Regulation 2024/2690 and NIST SP 800-53

Implementing Regulation (EU) 2024/2690 details the NIS2 measures for the digital infrastructure and ICT providers listed in its Article 1, such as cloud, data centre and managed service providers. For other companies it is a reference, not an obligation, and whether NIS2 applies is a legal assessment for the company’s legal department. The table maps its access control points and related NIST SP 800-53 Rev. 5 controls to evidence; all ten NIS2 measures are in our NIS2 Article 21 guide.

REQUIREMENT2024/2690; SP 800-53EVIDENCE
Admin-only accounts11.3.2(b), 11.6.2(f); AC-6(2)admin accounts listed, each linked to one person
Admin systems only for admin11.3.2(d), 11.4.2PAW and jump host inventory; management network firewall rules
Least privilege11.2.2(a), 11.3.2(c); AC-6, AC-6(5)role matrix per system; count of standing assignments
Reviews at planned intervals11.2.3, 11.3.3; AC-6(7)dated review record with the changes
Shared identities approved11.5.3; AC-2(9)approval per shared account; vault check-out log
Temporary and third-party11.2.2(d), 6.7.2(h); AC-2(2)expiry settings; supplier tickets with start and end
Privileged activity logged3.2.3, 11.2.2(f); AC-2(7), AC-6(9)log samples, alert rules, last alert handled

Implementing Regulation (EU) 2024/2690 of 17 October 2024, Annex points 3.2, 6.7 and 11.2 to 11.6; NIST SP 800-53 Rev. 5, release 5.2.0 (August 2025). The mapping and the evidence column are our recommendation.

Our cyber resilience assessment covers infrastructure, access, backups and NIS2 requirements and ends with a risk map and a prioritised action plan. Tell us which of these records you can produce today and how often privileged rights are reviewed.

What we do

Under Cyber Resilience, our engineering partner Vixen.UNO builds a zero-trust architecture following NIST CSF 2.0 with privileged access management, multi-factor authentication, network segmentation, mobile device management (MDM) and data loss prevention (DLP). The paid technical assessment delivers a risk map, a compliance analysis and a prioritised action plan. Changes roll out in agreed maintenance windows with a rollback plan. During the project Vixen.UNO works in your environment under your access controls; access is granted by you, scoped to what the work needs, and ends with the engagement, as our security and compliance page describes. The first call is free of charge, and the price of the technical assessment is fixed before work begins.

FAQ

What is privileged access management (PAM)?
Privileged access management (PAM) is the set of policies, processes and tools that control the accounts able to change systems, security settings or other accounts, such as directory, hypervisor, backup, firewall and cloud administrators and service accounts. It combines an inventory of those accounts, separate administrator accounts used from dedicated workstations, a vault for shared passwords, just-in-time elevation, tiering, break-glass accounts and logging. CISA and the NSA advise managing privileged accounts separately with a PAM solution and strong identity governance.
What are PAM best practices?
We recommend starting with an inventory of privileged and service accounts, each with an owner, and removing those that are no longer needed. Next come separate named administrator accounts used only from dedicated administrator workstations, a vault with a unique, rotated password per system, privileged groups kept empty with rights granted just in time, and tiers that keep top-level credentials off ordinary machines. Log every privileged action to a store administrators cannot edit, review privileged rights at planned intervals and test the break-glass accounts.
What counts as a privileged account?
NIST defines a privileged account as a system account with the authorisations of a privileged user, one trusted to perform security-relevant functions that ordinary users are not authorised to perform. In a mid-size company that includes directory and identity provider administrators, root on hypervisor hosts and vCenter administrators, backup, BMC, firewall and network device administrators, cloud and SaaS administrators, local administrator accounts, service accounts with elevated rights and break-glass accounts.
What is just-in-time access?
Just-in-time (JIT) access grants privileged rights for one task and a limited time, after a request and an approval, instead of permanent membership in administrator groups or roles, and the rights expire on their own. CISA and the NSA describe it as users being temporarily granted privileged access to complete a specific task or resolve an issue. The NCSC notes that a stolen temporary credential stops working after a short period, which narrows an attacker’s window.
What is admin tiering (tier 0, tier 1 and tier 2)?
Admin tiering groups systems by the impact of their compromise and gives each tier its own administrator accounts and workstations, so that credentials of the highest tier are never exposed on a less trusted machine. We would put the directory, the identity provider, the PKI, the PAM system and the hypervisors and backup servers that host or hold domain controllers in tier 0, servers and applications in tier 1, and workstations in tier 2. The NCSC calls tier 0 the root of trust that all other administration relies upon, and Mandiant advises running such assets in a dedicated, separately secured cluster.
What does NIS2 require for privileged accounts?
Article 21(2)(i) of the NIS2 Directive names access control policies, and Implementing Regulation (EU) 2024/2690 details them for the digital infrastructure and ICT providers listed in its Article 1. Its point 11.3 asks for policies for privileged and system administration accounts with strong authentication such as MFA, accounts used exclusively for administration, individualised and restricted privileges, connections only to administration systems and reviews at planned intervals, and point 11.4 limits administration systems to administration. For other companies the regulation is a reference, and whether NIS2 applies is a legal assessment for the company’s legal department.

Send us the number of administrator, service and break-glass accounts per system, how administrators sign in to the directory, hypervisors, backup and firewalls today, and whether shared passwords are kept in a vault. We reply within one business day to arrange a first call, from which you leave with two or three possible solution scenarios. The first call is free of charge.

Talk to an expert
Talk to an expert

We reply within one business day

By sending this form you agree that we process your details to answer your enquiry – see our privacy policy.

request@eurokommerz.at
Jordangasse 7, 1010 Vienna