Join our Newsletter — 33% off our NHI Course

Notifications
Clear all

Browser-based privileged access: are PAM controls keeping up?


(@nhi-mgmt-group)
Member Moderator
Joined: 1 year ago
Posts: 19630
Topic starter  

TL;DR: Browser-based admin work is now a privileged access problem, not just a usability issue, because many critical actions happen in web consoles and portals without the monitoring, recording, or granular control PAM teams expect, according to Wallix and a 2025 industry survey. The security model still assumes high-risk access lives in SSH and RDP sessions, but the browser has become a governed workspace that most programmes have not instrumented.

NHIMG editorial — based on content published by Wallix: Browser-based privileged access and the web session security gap PAM programs miss

By the numbers:

Questions worth separating out

Q: How should security teams implement privileged session oversight without forcing engineers into a browser-only workflow?

A: Security teams should separate access brokering from user experience.

Q: Why do browser-based admin sessions create a PAM gap?

A: Because many PAM programmes still focus on SSH and RDP, while real administrative work increasingly happens inside web applications.

Q: What breaks when privileged access is not continuously governed?

A: When privileged access is not continuously governed, standing privilege persists, dormant accounts remain usable, and the attack surface expands across human and machine identities.

Practitioner guidance

  • Classify browser admin paths as privileged sessions Inventory cloud consoles, SaaS admin portals, ERP interfaces, and industrial dashboards that permit configuration or identity changes.
  • Isolate high-risk sessions from unmanaged endpoints Use controlled remote browsing or equivalent isolation for third-party, contractor, and BYOD access where the local endpoint cannot be trusted to enforce policy.
  • Record and restrict privileged web activity Apply session recording, action logging, and granular restrictions on clipboard use, file transfer, printing, and download paths for browser-based administrative workflows.

What's in the full article

Wallix's full article covers the operational detail this post intentionally leaves for the source:

  • A clearer breakdown of how Web Session Manager fits inside a broader PAM deployment for browser-based administration.
  • Specific examples of which web applications and user groups the vendor expects to benefit most from browser session controls.
  • The vendor's own explanation of session isolation, auditability, and deployment choices for unmanaged devices.
  • Context on how the article positions browser access relative to existing privileged access workflows.

👉 Read Wallix's analysis of browser-based privileged access and PAM gaps →

Browser-based privileged access: are PAM controls keeping up?

Explore further

View Full Forum →  |  NHI Foundation Course →



   
Quote
(@mr-nhi)
Member Moderator
Joined: 4 months ago
Posts: 19221
 

Browser-based privilege is a PAM design gap, not a niche access pattern. The article describes a work reality where sensitive administration happens through web consoles, SaaS portals, and identity admin screens. That means privileged access is no longer defined by protocol alone, because the same business risk can now sit inside a browser session. Practitioners should treat browser-admin paths as first-class privileged access routes, not as incidental application traffic.

A few things that frame the scale:

  • 67% of organisations still rely heavily on static credentials despite the risks they pose to agentic AI deployments, according to The 2026 Infrastructure Identity Survey.
  • The same survey found that only 44% of organisations have implemented any policies to manage their AI agents, even though 92% agree that governing AI agents is critical to enterprise security.

A question worth separating out:

Q: Should organisations use browser isolation for all privileged access?

A: No. Use it where the browser is the only practical control point and the impact of session abuse is high, such as third-party access, unmanaged endpoints, or sensitive admin portals. For lower-risk workflows, lighter policy controls may be sufficient, but privileged web sessions should never be left outside governance entirely.

👉 Read our full editorial: Browser-based privileged access leaves a PAM governance gap



   
ReplyQuote
Share: