By NHI Mgmt Group Editorial TeamDomain: Governance & RiskSource: WallixPublished May 26, 2026

TL;DR: Browser-based admin work is now a privileged access problem, not just a usability issue, because many critical actions happen in web consoles and portals without the monitoring, recording, or granular control PAM teams expect, according to Wallix and a 2025 industry survey. The security model still assumes high-risk access lives in SSH and RDP sessions, but the browser has become a governed workspace that most programmes have not instrumented.


At a glance

What this is: This is an analysis of browser-based privileged access and the finding that many PAM programmes still leave web sessions outside their control plane.

Why it matters: It matters because IAM, PAM, and IGA teams need to govern privileged browser sessions with the same discipline they already apply to server, database, and remote desktop access.

By the numbers:

👉 Read Wallix's analysis of browser-based privileged access and PAM gaps


Context

Privilege is not confined to shells and remote desktop sessions anymore. Administrators, DevOps engineers, finance users, and IT staff increasingly perform sensitive actions inside browsers, which means the governance question is no longer only who can reach the system, but what can happen inside the session once access is granted.

That shift exposes a blind spot in many PAM programmes. Browser-based access to cloud consoles, SaaS admin portals, industrial dashboards, and identity tools often remains authenticated but not truly governed, so the access path is visible to the application but not to the controls designed to supervise high-risk activity.

The result is a growing mismatch between control design and actual work patterns. The browser has become a privileged workspace, but many security models still treat it as an ordinary user interface rather than a high-trust access path.


Key questions

Q: How should security teams implement privileged session oversight without forcing engineers into a browser-only workflow?

A: Security teams should separate access brokering from user experience. Let users keep native clients where needed, while the control plane records, monitors, and can stop the session in real time. The goal is to preserve productivity without exposing standing credentials, adding agents everywhere, or forcing all traffic through a single proxy. This keeps oversight aligned to the task, not the tool.

Q: Why do browser-based admin sessions create a PAM gap?

A: Because many PAM programmes still focus on SSH and RDP, while real administrative work increasingly happens inside web applications. Once the browser session is authenticated, tools often lose visibility into the actions that follow. That leaves configuration changes, identity operations, and data movement outside the same controls applied to traditional privileged access.

Q: What breaks when privileged access is not continuously governed?

A: When privileged access is not continuously governed, standing privilege persists, dormant accounts remain usable, and the attack surface expands across human and machine identities. In practice, that creates a larger blast radius for credential theft and a weaker ability to prove who had access, when, and why. The result is operational drift, not just security exposure.

Q: Should organisations use browser isolation for all privileged access?

A: No. Use it where the browser is the only practical control point and the impact of session abuse is high, such as third-party access, unmanaged endpoints, or sensitive admin portals. For lower-risk workflows, lighter policy controls may be sufficient, but privileged web sessions should never be left outside governance entirely.


Technical breakdown

Why browser sessions behave like privileged access

A browser session becomes privileged when the user can change configuration, administer identities, access financial systems, or alter operational controls from inside a web application. The security problem is not the browser itself, but the fact that it carries the same blast radius as traditional privileged channels while often bypassing PAM’s session recording, command visibility, and action-level control. Once the session is authenticated, many tools lose line of sight into what happens next, especially in SaaS and cloud consoles.

Practical implication: PAM teams need to classify browser-admin paths as privileged sessions, not ordinary application logins.

Why unmanaged endpoints and remote access widen the session gap

Browser-based privilege becomes harder to govern when access originates from third-party laptops, home networks, or BYOD devices. In those cases, endpoint control, inspection, and local isolation are inconsistent, which means credential theft, session hijacking, and data movement can occur outside the managed device boundary. The browser is effectively the last common control point, but many programmes do not treat it as such.

Practical implication: security teams should map which high-risk web apps are reachable from unmanaged endpoints and decide where session isolation is mandatory.

How browser isolation changes the control model

Browser isolation shifts execution away from the local endpoint and into a controlled remote environment, so the user views the session while malware, downloads, and clipboard abuse are contained elsewhere. Combined with recording, policy-based controls, and granular restrictions on transfer or printing, this creates a supervisory layer for web sessions that resembles classical PAM governance. The key architectural change is that control moves from perimeter inspection to in-session enforcement.

Practical implication: organisations should reserve browser isolation for the web applications where session abuse would create the largest operational or identity risk.


Threat narrative

Attacker objective: The objective is to abuse trusted web-based administrative access to alter systems, harvest data, or move laterally without triggering the controls normally applied to privileged sessions.

  1. Entry occurs through a browser session to a cloud console, admin portal, or SaaS application that is authenticated but not governed by PAM controls.
  2. Escalation happens when the attacker or malicious insider uses the web session to perform privileged actions such as configuration changes, identity manipulation, or data export without meaningful oversight.
  3. Impact follows as the organisation loses visibility into the session, enabling unauthorised exfiltration, lateral movement, or operational disruption through the very interface used for administration.

Read our 52 NHI Breaches Analysis report for a comprehensive view of breaches impacting Non-Human Identities including AI Agents.


NHI Mgmt Group analysis

Browser-based privilege is a PAM design gap, not a niche access pattern. The article describes a work reality where sensitive administration happens through web consoles, SaaS portals, and identity admin screens. That means privileged access is no longer defined by protocol alone, because the same business risk can now sit inside a browser session. Practitioners should treat browser-admin paths as first-class privileged access routes, not as incidental application traffic.

Control assumptions built around SSH and RDP no longer match the privilege surface. Traditional PAM models assume high-risk access is easy to identify because it arrives through a narrow set of protocols. That assumption fails when the browser becomes the execution layer for cloud, ERP, and identity operations. The implication is that governance needs to follow the action, not the transport.

Session visibility is the missing control plane for browser privilege. The post makes clear that many organisations have authentication without meaningful supervision once the session starts. That creates a gap between identity verification and action governance, especially when users can change configuration or move data from within a web UI. The named concept here is browser session governance, meaning policy, recording, and restriction controls applied to web-based privileged activity.

Unmanaged endpoints make privileged web sessions materially harder to trust. Third-party devices, home networks, and BYOD environments reduce the reliability of local inspection and endpoint controls. That is not just a security hygiene issue. It changes the governance model because the browser may be the only durable control point left. Practitioners should assume browser access from unmanaged devices carries a different risk class than the same application reached from a managed endpoint.

From our research:

What this signals

Browser-based privilege is becoming a control-plane issue for IAM and PAM teams, not just an endpoint-security concern. The practical shift is that web sessions now need policy, visibility, and restriction controls that were originally designed for infrastructure access, especially where cloud consoles and identity portals can alter production state.

Browser session governance: the next maturity step is to treat the session itself as the protected object. That means defining where isolation is mandatory, where recording is required, and which web applications should be reclassified as privileged workflows. For background on the governance model behind this shift, see Ultimate Guide to NHIs , Key Challenges and Risks.


For practitioners

  • Classify browser admin paths as privileged sessions Inventory cloud consoles, SaaS admin portals, ERP interfaces, and industrial dashboards that permit configuration or identity changes. Route them into the same governance model used for other high-risk privileged access flows, rather than leaving them as ordinary web application logins.
  • Isolate high-risk sessions from unmanaged endpoints Use controlled remote browsing or equivalent isolation for third-party, contractor, and BYOD access where the local endpoint cannot be trusted to enforce policy. Prioritise applications where data export, identity changes, or infrastructure changes are possible inside the browser.
  • Record and restrict privileged web activity Apply session recording, action logging, and granular restrictions on clipboard use, file transfer, printing, and download paths for browser-based administrative workflows. Focus first on the applications where a single session can alter production systems or expose regulated data.
  • Reconcile PAM scope with real user workflows Review which teams now manage infrastructure, identities, and business systems through browsers instead of terminal access. Where PAM still stops at the browser boundary, extend governance to include the session itself rather than only the upstream authentication event.

Key takeaways

  • Browser-based administration is now part of the privileged access surface, which means PAM scope has to extend beyond SSH and RDP.
  • Unmanaged endpoints and uninspected sessions create a visibility gap that traditional access controls do not close.
  • Security teams should classify web consoles and admin portals as privileged workflows and apply isolation, recording, and granular session controls.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

OWASP Non-Human Identity Top 10 address the attack and risk surface, while NIST CSF 2.0, NIST SP 800-53 Rev 5 and NIST Zero Trust (SP 800-207) set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
OWASP Non-Human Identity Top 10NHI-03Browser-based privileged access creates session governance gaps adjacent to credential and secret handling.
NIST CSF 2.0PR.AC-4Privileged browser access depends on permissions being managed with least privilege and session oversight.
NIST SP 800-53 Rev 5AC-6Least privilege is the core control challenged by uncontrolled web administration sessions.
NIST Zero Trust (SP 800-207)Zero Trust assumes continuous verification across every access path, including browser sessions.

Map browser-admin workflows to NHI-03 and extend governance to the full privileged session, not just authentication.


Key terms

  • Browser Session Governance: Browser session governance is the discipline of controlling and auditing what happens after authentication inside a live browser session. It matters because modern work often continues well past login, where data movement, AI prompts, and extension use create the real risk.
  • Privileged Access: Privileged access is any elevated entitlement that can change systems, data, or security settings. When privilege is excessive or poorly scoped, a single compromised identity can create outsized blast radius across environments.
  • Session Isolation: Session isolation is the separation of one user’s prompts, memory, and retrieved context from another’s. In AI systems, weak isolation can cause cross-user leakage, especially in multi-tenant platforms or shared assistant workflows where previous data remains reachable.
  • PAM — Privileged Access Management: Solutions that control, monitor, and audit privileged access for both human and non-human identities. Traditional PAM tools are being extended to cover machine identities, service accounts, and agentic AI workloads.

What's in the full article

Wallix's full article covers the operational detail this post intentionally leaves for the source:

  • A clearer breakdown of how Web Session Manager fits inside a broader PAM deployment for browser-based administration.
  • Specific examples of which web applications and user groups the vendor expects to benefit most from browser session controls.
  • The vendor's own explanation of session isolation, auditability, and deployment choices for unmanaged devices.
  • Context on how the article positions browser access relative to existing privileged access workflows.

👉 The full Wallix article covers browser session isolation, auditability, and privileged web access controls in more detail.

Deepen your knowledge

NHI governance, agentic AI identity, and machine identity security are core topics in our NHI Foundation Level course, the industry's only accredited NHI security programme. If you are responsible for identity security strategy or programme maturity, it is worth exploring.
NHIMG Editorial Note
Published by the NHIMG editorial team on August 26, 2026.
NHI Mgmt Group — the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org