Access control and privilege

Does the Applicant utilize a Privileged Access Management (PAM) tool?

The question names a product category, but what the underwriter wants to know is whether administrative privilege is standing or borrowed.

Partly verifiable from your tenant

What the carrier is actually asking

The carrier is asking whether privileged credentials are held permanently by people or issued on request, time-bound, approved, and recorded. A dedicated vaulting product satisfies that. So does a well-run Privileged Identity Management deployment, and so does a disciplined just-in-time model built on native tooling. What does not satisfy it is a spreadsheet of admin passwords, however carefully guarded.

Why it is underwritten

Standing privilege is what converts a single phishing success into a tenant-wide event. When privilege is borrowed rather than held, the attacker who compromises an administrator's session finds an account with no active roles, and the elevation attempt produces an approval request and an alert. Underwriters treat this as one of the few controls that changes the shape of a loss rather than just its likelihood.

Where the answer lives in Microsoft 365, Entra ID, and Azure

Microsoft-native privileged access management is measurable in the tenant. A third-party vault is not, so an estate using one answers this partly from Entra and partly from the vendor.

PlatformWhere the setting livesWhat has to be true
Entra IDPrivileged Identity Management, role settings per directory roleRoles are assigned as Eligible rather than Active, with activation requiring justification, and approval for the highest roles
Entra IDDirectory role assignments listed as permanentNo permanent active assignment on Global Administrator, Privileged Role Administrator, or Security Administrator outside documented break-glass accounts
Entra IDPIM alerts and access review configurationRole assignment changes raise alerts, and privileged roles are reviewed on a recurring schedule rather than at audit time
AzureSubscription Owner and User Access Administrator assignmentsResource-plane privilege follows the same eligible-and-activate pattern, since directory PIM does not cover it automatically
Third-party vaultThe PAM product itself, if one is deployedSession recording, credential rotation, and checkout logs. Insurance Posture does not read third-party vaults, so this portion is attested
Native tooling is a valid answer

Some organisations answer no because they have not bought a product named PAM, while running a stricter just-in-time model than many vault deployments. That is an unnecessary loss of credit. Answer yes and name the mechanism.

What a defensible yes requires

  • Privileged roles are eligible rather than permanently active, with a small, documented set of exceptions.
  • Activation requires justification, and the highest roles require approval by someone other than the requester.
  • Activation and role change events are alerted on and retained long enough to reconstruct an incident.
  • Azure resource-plane privilege is covered as well as directory roles.
  • Where a third-party vault holds credentials, checkout is logged and passwords rotate after use.

How this answer goes wrong

The most common overstatement is answering yes on the strength of a licence. Privileged Identity Management is present in the tenant, a pilot converted three roles to eligible, and eleven permanent Global Administrator assignments remain. The licence is not the control; the assignment model is.

The opposite error is understatement, where an organisation running strict just-in-time elevation answers no because the form said tool and they did not buy one.

Frequently asked

Does Privileged Identity Management count as a PAM tool?

For the purposes of this question, yes, when roles are actually eligible rather than permanent and activation is justified and logged. Name it explicitly on the form so the underwriter is not left guessing.

What about break-glass accounts?

Two emergency accounts with permanent Global Administrator are expected and accepted. They should be cloud-only, excluded from Conditional Access deliberately, alerted on for any sign-in, and their credentials held under seal.

Do we need session recording?

Not to answer this question yes. Session recording appears in follow-up questions for organisations with high-value administrative access, particularly service providers accessing client systems.

Does this cover on-premises Active Directory?

No. If you run Active Directory, tiering and privileged access workstations are the on-premises half of this answer and they are not visible from the cloud tenant. Evidence has to come from the domain.

Related questions

Stop answering this from memory

Connect Microsoft 365, Entra ID, and Azure read-only. Insurance Posture reads the live configuration behind each application answer and shows you which ones you can prove before you sign.

Assess your posture