Administrative Workstation
An Administrative Workstation is a hardened workstation dedicated to privileged operations and isolated from standard user activity.
Explore the concepts used across Identity and Access Management, Identity Governance, Access Management, privileged access, authorization and identity security.
Definitions are organized to support search and navigation between related concepts.
An Administrative Workstation is a hardened workstation dedicated to privileged operations and isolated from standard user activity.
A Bastion is a controlled intermediary used to broker and monitor access to sensitive technical targets.
A Domain Administrator Account is a highly privileged account with broad control over directory-managed systems and identity infrastructure.
Firefighter Access is emergency privileged access granted temporarily to resolve urgent operational or security situations.
The practice of combining identity, network, endpoint, and session signals to improve security decisions.
Just-Enough Access is the practice of granting only the minimum privileged capability required for a precise task.
Just-in-Time Access is access that is granted only when needed and for a limited period rather than standing permanently.
Keystroke Logging is the capture of command or keyboard input during a sensitive session for audit and forensic purposes.
A Local Administrator Account is a privileged account with administrative rights limited to a workstation or server instance.
A deeper form of segmentation that controls access at a very granular workload or application level.
Privileged Access Management is the discipline of governing, controlling, and monitoring elevated access to sensitive systems and functions.
A Privileged Account is an account whose rights are sufficient to cause major damage if misused or compromised.
Privileged Elevation is the temporary granting of higher-level access for a specific administrative or sensitive task.
A Robot Account is a non-human account used by an automation or robot that interacts with applications in a human-like way.
Secret Management is the discipline of storing, controlling, distributing, and rotating sensitive credentials and secrets securely.
Secret Rotation is the periodic or event-driven replacement of passwords, keys, or other secrets to reduce exposure.
A Secret Vault is a secured repository used to store and control access to sensitive secrets such as passwords, keys, and credentials.
Session Recording is the capture of privileged session activity so that actions can be reviewed and investigated later.
A principle stating that access must remain under active observation and may be challenged or interrupted dynamically.
A Team Account is a shared account used by multiple members of a team rather than by a single identified person.
Tiering is the separation of administrative scopes into different sensitivity levels so that high-risk assets are isolated from lower-trust environments.
The isolation of network flows so that access paths are restricted to what is actually required.
The idea that IAG, AM, and PAM must be treated as one interconnected security perimeter.
A Unified Security Surface is the principle of treating IAG, Access Management, and PAM as one interconnected security system rather than separate silos.