← Back to PAM Best Practice main site
PAM Academy › Module 4 — Securing Privileged Access by Risk

Module 4: Securing Privileged Access by Risk

Priya found the doors. Now Omar has to decide the locks. Follow eight real privileged journeys at Abby Steel and see how protection follows risk, from Tier 0 to the furnace floor.

Story: “The Locksmith”
~39 minutes
Lead: Omar, Infrastructure Security Architect
Risk TiersLeast PrivilegeCredential RotationSession ManagementJust-in-Time AccessOT & Vendor AccessAI Agents
Included
Part of the PAM Best Practice Academy curriculum
Start Module 4 → ← Back to Module 3
  • 26-scene narrated slide module in 8 parts
  • Follows Omar at Abby Steel
  • Practical, vendor-neutral PAM guidance
  • Key facts and real-world examples
  • 10-question knowledge check
Overview
Curriculum
Instructors
4
Module Number
26
Scenes
39
Minutes
10
Quiz Questions
The question this module answers
How should each privileged journey be protected?

Module 3 ended with a list: 312 privileged accounts that no list had ever held. Priya found the doors; now Omar has to decide the locks. Following Ahmed, Chloe, Hannah, Tom, Marco and an AI agent through their real privileged journeys at Abby Steel, you see what happens today, what could go wrong, how PAM protects it and what changes for the person doing the work.

Omar's philosophy fits on a sticky note: everything equally protected means nothing properly protected. Protection follows risk.

He pilots the design on ten production servers, then hands Sofia the problems any platform will have to solve, and what it must never let anyone bypass.

What you will learn
▶
Trace any privileged journey through the seven-box chain: person, identity, credential, path, privilege, target and action.
▶
Use risk tiers to decide how strongly each account should be protected.
▶
Explain what core PAM capabilities change in a journey, from vaulting and credential injection to session recording, just-in-time access, MFA and secrets management.
▶
Spot the complications: service account dependencies, bypass routes, OT constraints, the help desk reset path, exceptions and break-glass.
▶
Name the capabilities a use case needs without choosing a product.
Module curriculum
1
Part 1: From map to locksScenes 1–3: The Locksmith · The Privileged Access Chain · The Tier Decides the Lock
Narrated slides
2
Part 2: Tier 0: the keys to the kingdomScene 4: The Keys to the Kingdom
Narrated slides
3
Part 3: Ahmed on Windows, Linux and his laptopScenes 5–10: Ahmed Before PAM · How PAM Protects Ahmed · Ahmed After PAM · Ahmed Pushes Back · Ahmed on Linux · Ahmed's Laptop
Narrated slides
4
Part 4: Machines, cloud and AIScenes 11–14: svc_furnace · Chloe and the Pipeline · Chloe in the Console · The Agent That Picked Up Ahmed's Ticket
Narrated slides
5
Part 5: Data, network and the help deskScenes 15–17: Hannah and the Database · Tom and the Network · The Help Desk Is an Authentication System Too
Narrated slides
6
Part 6: The plant and the vendorScenes 18–20: Marco Before PAM · Marco After PAM · When Access Moves Machinery
Narrated slides
7
Part 7: Controls that follow every journeyScenes 21–22: Where Does MFA Sit? · Session Recording Is a Control, Not a Camera
Narrated slides
8
Part 8: Finishing the job and the handoverScenes 23–26: Cleaning Up What Priya Found · When It Doesn't Fit · Ahmed Didn't Change. The Organisation Did. · The Handover
Narrated slides
9
Knowledge Check10 questions · pass mark 8/10
Quiz
The four tiers
Tier
What it covers
How it is locked
Tier 0
Accounts that can take over everything: the domain, the backups, the certificate authority, the PAM platform
Heaviest controls; nobody holds it permanently
Tier 1
Production servers, the finance database, the network core, the furnace controls and anyone reaching them from outside
Vaulted, recorded, MFA through PAM
Tier 2
Important but contained: test servers, internal tools, IT laptops
Managed with metadata-level logging
Tier 3
Low reach, low power: reporting and read-only access
Sensible defaults, and no more
Who you will meet
Omar leads the module, working from Priya's Module 3 inventory and Layla's Module 2 strategy.
Character
Role
Their journey
Omar
Infrastructure Security Architect
Fifteen years hardening servers, databases, network devices and furnace control systems. Leads the module.
Ahmed
Senior Infrastructure Engineer
The engineer everyone trusts. His Windows, Linux and laptop journeys run through the module.
Chloe
Platform Engineer
Builds the pipelines that deploy Abby Steel's cloud applications.
Hannah
Database Administrator
One of four DBAs who shared a single admin account.
Tom
Network Engineer
Looks after 200 switches and firewalls that shared one password.
Marco
Vendor Field Engineer
Supports the furnace controls from home, often at 3am.
Sofia
Solutions Engineer
Takes Omar's folder into Module 5 to evaluate platforms.
Part 1: From map to locks

Module 3 ended with 312 privileged accounts that no list had ever held. Omar takes Priya's ranked list, draws the seven-box privileged access chain (person, identity, credential, path, privilege, target, action) and turns her four risk questions into four tiers.

  • The Locksmith. Module 3 ended with 312 privileged accounts no list had ever held.
  • The Privileged Access Chain. Every privileged task follows the same seven boxes: person, identity, credential, path, privilege, target and action.
  • The Tier Decides the Lock. Priya's four questions (reach, power, state, autonomy) become four tiers.
“Everything equally protected means nothing properly protected. Protection follows risk.”
Part 2: Tier 0: the keys to the kingdom

Domain admins, backup operators and the certificate authority can take over everything. Omar empties the Tier 0 groups by default: access by ticket, a second approver, one hour, from a clean admin workstation, recorded and rotated. The PAM platform itself is Tier 0 from day one.

  • The Keys to the Kingdom. Tier 0 accounts control identity itself: domain and enterprise admins, backups and the certificate authority.
“If the device you administer from is compromised, everything you touch is compromised.”
Part 3: Ahmed on Windows, Linux and his laptop

Ahmed's four-minute fix leaves no evidence and a password shared by forty servers. Credential management and session management are kept separate, credentials are injected through a proxy, the direct route is closed, SSH keys are cleared out, and endpoint privilege management ends local admin rights.

  • Ahmed Before PAM. Ahmed restarts a failed service on APP-SRV-07 over Remote Desktop with a password he has known for years.
  • How PAM Protects Ahmed. Credential management protects the secret; session management protects the use of privilege.
  • Ahmed After PAM. In the ten-server pilot Ahmed signs into the PAM portal, approves on his phone and opens Remote Desktop.
  • Ahmed Pushes Back. Twenty-five servers a day, PowerShell, file transfers and a 2am outage: Ahmed is right that PAM must not make the job harder.
  • Ahmed on Linux. Priya found copies of SSH keys on sixty servers, three belonging to leavers.
  • Ahmed's Laptop. Local admin rights and a shared local admin password let an attacker walk from laptop to laptop.
“Security that users bypass is not security. A feature only becomes a control when the design makes it hard to avoid.”
Part 4: Machines, cloud and AI

svc_furnace's dependencies are mapped before its password is changed, Chloe's pipelines get a secrets manager with short-lived credentials, cloud admin roles become eligible rather than active, and the AI operations agent gets its own identity, a human sponsor and task-scoped tokens.

  • svc_furnace. svc_furnace has Domain Admin, a four-year-old password, six people who know it and no owner.
  • Chloe and the Pipeline. Chloe's pipelines held a cloud key in a script, a database password in config and a token in chat.
  • Chloe in the Console. Five permanent cloud owners, an over-used root login and an application role that could read every bucket.
  • The Agent That Picked Up Ahmed's Ticket. An AI operations agent closes Ahmed's ticket in forty seconds, logging in with Ahmed's admin account.
“The agent never holds more power than the person who asked it to act.”
Part 5: Data, network and the help desk

Hannah's team swap a shared DBA account for named ones, Tom's 200 network devices each get their own vaulted password with change-controlled access on a separate management network, and the help desk reset path is treated as Tier 0.

  • Hannah and the Database. Four DBAs share one admin account whose password lives in a spreadsheet.
  • Tom and the Network. Two hundred network devices share one admin password, and the backup server depends on it.
  • The Help Desk Is an Authentication System Too. Who can reset a privileged password or register a new MFA device? At Abby Steel, anyone with a phone call and two questions.
“There's no point locking the front door if anyone can phone up and ask for a new key.”
Part 6: The plant and the vendor

Marco's shared, always-on VPN becomes named, approved, four-hour access to one workstation through a bastion host, designed around OT's safety constraints. Ukraine 2015 and Stuxnet show what happens when privileged access reaches industrial control.

  • Marco Before PAM. Marco, the furnace-control vendor's field engineer, connects at 3am on a shared, always-on VPN with no second factor, and the jump server password is on a label in the control room.
  • Marco After PAM. Marco gets his own account, requests access against a work order, and the OT lead approves four hours on one engineering workstation through a fortified bastion host.
  • When Access Moves Machinery. In Ukraine (December 2015) attackers used stolen credentials and remote access to open circuit breakers; Stuxnet used a hard-coded password to spin centrifuges to destruction.
“In industrial environments, privileged access doesn't just touch data. It moves the physical world.”
Part 7: Controls that follow every journey

MFA is matched to the tier and placed where no route can skip it. Session recording becomes a real control through notice, review, alerts on risky moments such as a PAM bypass, and encryption of the vault that holds every key.

  • Where Does MFA Sit?. MFA only counts where it sits and if no route skips it.
  • Session Recording Is a Control, Not a Camera. Recording links a named person, system, time, reason and action.
“Controls don't exist on slides. They exist at specific points in a journey, and only if the journey can't go around them.”
Part 8: Finishing the job and the handover

Orphaned and over-privileged accounts are cleaned up, reviews and weekly discovery keep it clean, exceptions get owners and break-glass works even when PAM is down. Omar hands Sofia the problems and required capabilities, not a product.

  • Cleaning Up What Priya Found. Forty-seven orphaned accounts follow one path: find a claimant, disable, watch thirty days, delete, record why.
  • When It Doesn't Fit. Some systems can't fit the design.
  • Ahmed Didn't Change. The Organisation Did.. Every finding now has a design, an owner and a plan: some in weeks, some in years.
  • The Handover. The design is proven on ten servers but runs on spreadsheets, scripts and willpower.
“Ahmed didn't change. The organisation did.”
Key facts
  • OPM (2015): records on around 22 million people taken, with MFA not enforced, privileged access not limited and audit too weak.
  • Capital One (2019): an over-privileged cloud role, reached through a misconfigured web application firewall, exposed data on more than 100 million people.
  • SingHealth (2018): attackers used privileged credentials to move from one workstation to the patient database, taking around 1.5 million records.
  • Mat Honan (2012): attackers talked a support desk into a reset and wiped a journalist's digital life in under an hour.
  • Ukraine (December 2015) and Stuxnet: privileged access to industrial control damaged physical systems. Nothing was stolen, but machinery broke and people were put at risk.
  • Colonial Pipeline and Target (revisited from Module 2): one unused VPN account with no second factor, and a heating contractor's login, show why MFA placement and third-party access matter.
  • Uber (revisited from Module 3): credentials sitting in code gave anyone who reached the code everything the credentials opened.
  • Horizon Blue Cross Blue Shield: two stolen, unencrypted laptops held the records of around 840,000 people.
Knowledge Check
Q1: Why doesn't Omar simply delete the 47 orphaned accounts Priya found?
Deleting accounts breaks the audit trail
An account nobody recognises may still run a service, task or application, so it follows a controlled retirement path
Orphaned accounts are Tier 3, so they can be left alone
The PAM platform must be bought before anything is removed
Q2: What decides how strongly Omar protects a privileged account?
Its tier, set by what it can reach, how much power it holds, its state and its autonomy
The seniority of the person who uses it
How long the account has existed
Whether the account belongs to a person or a machine
Q3: What is the difference between credential management and session management?
Credential management is for Windows; session management is for Linux
Credential management records sessions; session management rotates passwords
They are two names for the same vaulting feature
Credential management protects the secret; session management protects what happens when privilege is used
Q4: A recorded PAM route to production servers exists, but direct Remote Desktop from the VPN still works. What has Abby Steel created?
A fully controlled privileged route
A zero standing privilege model
A recorded option, not a control
An approved break-glass route
Q5: What does Omar insist on before svc_furnace's password is changed?
Rotating it immediately, because it is four years old
Finding an owner and mapping every dependency, so the change doesn't stop a furnace line
Giving it Domain Admin rights so rotation cannot fail
Sharing the new password with the six people who knew the old one
Q6: How does Omar's design treat the AI operations agent that was using Ahmed's account?
It keeps using Ahmed's account so its actions stay traceable
It is switched off permanently because AI cannot be controlled
It is given standing Domain Admin rights to avoid delays
It gets its own identity, a human sponsor and short-lived task-scoped access, never more power than the person who asked it to act
Q7: According to Scene 20, why is Omar so strict about privileged access to the plant?
In OT, privileged access can change the physical world, affecting availability, production, equipment and potentially people
OT systems hold more personal data than IT systems
Regulators ban all remote access to industrial systems
OT engineers are more likely to misuse their access
Q8: Where should MFA sit in a privileged-access journey?
Only at the VPN, because that is where everyone enters
Only on the PAM portal login page
At the points where identity needs stronger proof, with no easier route around it
Wherever the architecture diagram has space for it
Q9: What turns session recording from a camera into a control?
Recording every keystroke on every system, whatever the risk
Capturing who, what, when, why and what they did; detecting events that matter; and protecting the evidence
Storing recordings for as long as possible
Letting any administrator replay any session
Q10: What keeps break-glass access from becoming a hidden backdoor?
Keeping the emergency credentials inside the PAM platform
Giving every administrator a copy of the credentials
Only creating break-glass accounts after an emergency starts
Restricted accounts, separately protected credentials, an alert and review on every use, a credential change afterwards and regular testing
Requirements
Completion of Module 3 (recommended)
Basic understanding of IT administration or security concepts
Target audience: security and IT professionals, PAM practitioners and programme leads
No vendor-specific tool knowledge required — this module is vendor-neutral
Your instructors
NK
Nabeel Khaliq
IAM & Privileged Access Management SME · Founder, PAM Best Practice Ltd
Practitioner with deep hands-on experience implementing PAM across enterprise environments. Founder of PAM Best Practice Academy, a UK-registered education and community hub for PAM professionals. Arsenal and Middlesbrough fan.
AR
Adrian Russo
IAM & Privileged Access Management Architect
Senior PAM architect with extensive experience designing and deploying large-scale CyberArk and BeyondTrust implementations across enterprise environments globally. Keen cyclist.
ID
Iftikar Din
Manufacturing-focused Cyber Security Engineer
Cyber security engineer specialising in industrial and manufacturing environments. Brings real-world operational technology (OT) security perspective to PAM implementation. Middlesbrough fan who loves gardening.
Your progress
Module 4 — Securing Privileged Access by Risk
Not started0%
Module breakdown
Part 1: From map to locks3 slides
Part 2: Tier 0: the keys to the kingdom1 slide
Part 3: Ahmed on Windows, Linux and his laptop6 slides
Part 4: Machines, cloud and AI4 slides
Part 5: Data, network and the help desk3 slides
Part 6: The plant and the vendor3 slides
Part 7: Controls that follow every journey2 slides
Part 8: Finishing the job and the handover4 slides
Knowledge Check10 questions
Up next
Module 5 — Choosing a PAM Platform
Sofia, Solutions Engineer, takes Omar's folder into Module 5 to find the platform that fits the programme, not the other way round.
PAM Community
Join our network of PAM practitioners, mentors and industry partners across the UK.