How to Choose Between PASM and PEDM for Your Business
Identity and Access Management is a keystone for cybersecurity. It is essential to ensure that endpoint devices are authorised and the users using them are who they say they are. This applies across the whole IT landscape: staff, customers, their devices, other IT systems, applications, plus IoT devices, sensors, and other edge computing infrastructure.
Some users and systems are so critical that they need additional security layers applied. This is where Privileged Access Management (PAM) comes in. Any User ID or system that can make changes beyond their primary job role should be considered privileged. Examples include:
- User IDs with admin access to specific servers, applications, or critical network services.
- Access to industrial control systems that are controlling infrastructure.
- Access to financial payment systems that can transfer money to other accounts.
- Development accounts that can promote new code.
- Others that will depend on each organisation's specific use cases.
PAM solutions are designed to protect all the privileged accounts and systems mentioned above. They ensure that any action that requires privileged access is done from a User ID that is appropriately authorised to perform it. PAM systems also record the activities performed during a privileged session. This allows for extremely fine-grained logging, reporting, and security auditing to be completed.
As PAM has been used, nuances related to privileged accounts and systems have emerged. In recognition of this, in 2017, Gartner's analysts started referring to two strands of PAM - Privileged Account and Session Management (PASM) and Privilege Elevation and Delegation Management (PEDM).
PASM & PEDM - How do the two strands of PAM compare?
PASM solutions allow privileged account credentials to be securely created and distributed by the PAM solution. This mechanism is similar to the operation of a password vault. Thus, when users need to access a specific server or system, they request access and receive a temporary account with relevant privileges. This access account is valid for a single session only, and all session activities are monitored and recorded. However, the privileged access granted during that temporary session provides full admin access. Often this gives access to all parts of the system and the ability to perform tasks that are not required for the specific task at hand. This means the risk is increased.
PEDM access, on the other hand, is designed to give regular user accounts all the granular access rights they need to perform their job function. Only a bare minimum level of access to the specific parts of the system are provided. This is a best practice from the concept of least privilege. PEDM solutions promote robust PAM practices by:
- Strengthening the principle of least privilege - PEDM solutions can reduce the risks of privileged access. As rights are granted at a narrow granular level to apps, scripts, and admin tools, with the ability to assign specific privileges to a user to perform certain restricted actions.
- Reduce the attack surface - General admin-level accounts can be reduced when users are given the access levels they need via PEDM. Not having generic full access admin accounts greatly reduces the attack surface and risk from cyberattacks due to credential leakage.
Choosing between PASM and PEDM
The choice between using PASM or PEDM solutions to manage privileged access accounts and user access rights will vary between organisations. In most real-world scenarios, we see that a mix of both PASM and PEDM is often required. With the goal to be to use as many PEDM accounts as possible and to reduce the PASM accounts. The table below compares PASM and PEDM functionality across the three main areas of PAM.
| PAM Area | PASM | PEDM |
| Privilege | PASM tools make use of an "all-or-nothing" strategy when it comes to privileges. This is because standard user accounts do not have administrative privileges, but shared accounts have full administrative access. Users are required to go through an approval workflow to use one of these privileged accounts. | PEDM uses granular access controls to grant regular user accounts only the required privileges according to their profile or job role. Each user is given limited privileges just to perform their function. These rights cannot be used to do any tasks they are not authorised to perform. |
| Accounts & Passwords | PASM establishes shared accounts that have full administrative privileges. Since these accounts are not owned by a single user, they are available when someone needs additional access. To keep the entire process secure, users do not have access to the shared account password. Each time access is required, a new password is issued, and a new session started. | PEDM tools grant the required privileges on standard user accounts. Users gain access through their own accounts by using their regular password. There is no delay waiting for approval workflows to be signed off by managers. Nor can users make a change to a critical system by mistake. |
| Monitoring | As PASM tools allow users to have full administrative access for a limited period, each session is carefully monitored and recorded for analysis if required. | PEDM allows users to use their standard accounts with just the access privileges they need. Therefore less monitoring and recording is required. However, this can be done if necessary under PEDM. |
As outlined above, we see a mix of both PASM and PEDM in many scenarios. If only one approach can be implemented, then PASM is the one to choose and later introduce PEDM when possible.
Find Out More
Renaissance and Senhasegura have the solutions to deliver all your PAM needs - via both PASM and PEDM. Contact us today to discuss your needs and find out more. And don't forget to check out our Demystifying Identity Management resources page.

