Does the Applicant utilize a Privileged Access Management (PAM) tool?
The question names a product category, but what the underwriter wants to know is whether administrative privilege is standing or borrowed.
What the carrier is actually asking
The carrier is asking whether privileged credentials are held permanently by people or issued on request, time-bound, approved, and recorded. A dedicated vaulting product satisfies that. So does a well-run Privileged Identity Management deployment, and so does a disciplined just-in-time model built on native tooling. What does not satisfy it is a spreadsheet of admin passwords, however carefully guarded.
Why it is underwritten
Standing privilege is what converts a single phishing success into a tenant-wide event. When privilege is borrowed rather than held, the attacker who compromises an administrator's session finds an account with no active roles, and the elevation attempt produces an approval request and an alert. Underwriters treat this as one of the few controls that changes the shape of a loss rather than just its likelihood.
Where the answer lives in Microsoft 365, Entra ID, and Azure
Microsoft-native privileged access management is measurable in the tenant. A third-party vault is not, so an estate using one answers this partly from Entra and partly from the vendor.
| Platform | Where the setting lives | What has to be true |
|---|---|---|
| Entra ID | Privileged Identity Management, role settings per directory role | Roles are assigned as Eligible rather than Active, with activation requiring justification, and approval for the highest roles |
| Entra ID | Directory role assignments listed as permanent | No permanent active assignment on Global Administrator, Privileged Role Administrator, or Security Administrator outside documented break-glass accounts |
| Entra ID | PIM alerts and access review configuration | Role assignment changes raise alerts, and privileged roles are reviewed on a recurring schedule rather than at audit time |
| Azure | Subscription Owner and User Access Administrator assignments | Resource-plane privilege follows the same eligible-and-activate pattern, since directory PIM does not cover it automatically |
| Third-party vault | The PAM product itself, if one is deployed | Session recording, credential rotation, and checkout logs. Insurance Posture does not read third-party vaults, so this portion is attested |
Some organisations answer no because they have not bought a product named PAM, while running a stricter just-in-time model than many vault deployments. That is an unnecessary loss of credit. Answer yes and name the mechanism.
What a defensible yes requires
- Privileged roles are eligible rather than permanently active, with a small, documented set of exceptions.
- Activation requires justification, and the highest roles require approval by someone other than the requester.
- Activation and role change events are alerted on and retained long enough to reconstruct an incident.
- Azure resource-plane privilege is covered as well as directory roles.
- Where a third-party vault holds credentials, checkout is logged and passwords rotate after use.
How this answer goes wrong
The most common overstatement is answering yes on the strength of a licence. Privileged Identity Management is present in the tenant, a pilot converted three roles to eligible, and eleven permanent Global Administrator assignments remain. The licence is not the control; the assignment model is.
The opposite error is understatement, where an organisation running strict just-in-time elevation answers no because the form said tool and they did not buy one.
Frequently asked
Does Privileged Identity Management count as a PAM tool?
For the purposes of this question, yes, when roles are actually eligible rather than permanent and activation is justified and logged. Name it explicitly on the form so the underwriter is not left guessing.
What about break-glass accounts?
Two emergency accounts with permanent Global Administrator are expected and accepted. They should be cloud-only, excluded from Conditional Access deliberately, alerted on for any sign-in, and their credentials held under seal.
Do we need session recording?
Not to answer this question yes. Session recording appears in follow-up questions for organisations with high-value administrative access, particularly service providers accessing client systems.
Does this cover on-premises Active Directory?
No. If you run Active Directory, tiering and privileged access workstations are the on-premises half of this answer and they are not visible from the cloud tenant. Evidence has to come from the domain.
Related questions
Stop answering this from memory
Connect Microsoft 365, Entra ID, and Azure read-only. Insurance Posture reads the live configuration behind each application answer and shows you which ones you can prove before you sign.
Assess your posture