Advanced / Compliance lessons

Advanced / Compliance · Lesson 2

Privileged Access Governance

How IGA and PAM work together for admin, root, and break-glass access.

Privileged access is any entitlement that can change systems, identities, or money at scale: cloud root, domain admin, production deploy, break-glass, and powerful SaaS admin roles.

IGA decides who may be eligible, tracks ownership, runs SoD against privileged roles, and certifies them. PAM vaults credentials, brokers sessions, records activity, and prefers just-in-time elevation over standing privilege.

Governance checklist:

  • Inventory privileged entitlements across cloud, SaaS, and on-prem.
  • Remove standing shared passwords; require checkout with MFA.
  • Tie eligibility to roles + manager/security approval with short TTL.
  • Certify privileged access more frequently than standard business roles.
  • Alert on unused privileged grants and emergency access use.

Next: how to prove all of this to auditors without a spreadsheet scramble.

IAM vs IGA vs PAM

IAM, IGA, and PAM — who does what?

How authentication, governance, and privileged access fit together in a modern identity stack. Columns: IAM (Authenticate); IGA (Govern); PAM (Constrain).

  • IAMAuthenticate users and enforce sign-in
  • IGADecide who should have access and prove it
  • PAMConstrain high-privilege accounts

Learn more: Open related lesson →

Interactive check

No game on this lesson — try Access Request Flow or Spot the SoD Conflict.

Mark complete

Save progress on this device. Track completion unlocks badges in a later release.