What Is a Privileged Access Workstation?
If you ask ten IT professionals what a Privileged Access Workstation (PAW) is, you’ll probably receive ten different answers.
Some will describe it as a dedicated laptop for administrators.
Others will tell you it’s simply a highly secured Windows device.
Some organisations deploy physical workstations, while others use Windows 365 Cloud PCs or Azure Virtual Desktop.
While all of these answers contain some truth, they miss the real purpose of a Privileged Access Workstation.
A PAW isn’t simply another device.
It’s a security control designed to increase the level of assurance around privileged administration.
Understanding that distinction is fundamental to understanding why PAWs have become an important part of modern identity security.
The Problem PAWs Are Trying to Solve
Privileged identities are among the most valuable assets within any organisation.
Whether it’s a Global Administrator, Security Administrator, Privileged Role Administrator, Exchange Administrator or another highly privileged role, these identities have the ability to make changes that can affect an entire Microsoft 365 tenant.
For an attacker, compromising one of these identities can provide access to sensitive information, security controls, administrative services and, ultimately, complete control of the environment.
Microsoft has invested heavily in protecting these identities through technologies such as passkeys, Authentication Strengths, Conditional Access, Microsoft Entra ID Protection and Privileged Identity Management (PIM).
These technologies significantly reduce the risk of credential theft and standing privilege.
However, authentication is only one part of the equation.
The environment from which privileged administration is performed is equally important.
The Device Is Part of the Trust Boundary
Imagine an administrator signs in using phishing-resistant authentication.
Conditional Access confirms they’re using a compliant device.
Privileged Identity Management activates their Global Administrator role.
Everything appears secure.
But what happens if the workstation itself has already been compromised?
Perhaps there’s information-stealing malware running in the background.
A malicious browser extension.
Clipboard monitoring software.
Session token theft.
Screen capture malware.
In these scenarios the attacker isn’t bypassing authentication.
They’re compromising the trusted environment after authentication has already succeeded.
This is why the administrative workstation forms part of the trust boundary.
It’s not enough to trust the identity.
You must also trust the environment from which that identity operates.
More Than Just a Dedicated Laptop
One of the biggest misconceptions surrounding Privileged Access Workstations is that they’re simply dedicated laptops reserved for administrators.
The physical device is only one component.
A true Privileged Access Workstation is a dedicated administrative environment.
Its purpose is to separate privileged administration from everyday productivity activities.
That typically means avoiding activities such as:
- Reading email
- Browsing the internet
- Microsoft Teams conversations
- Document creation
- General web browsing
- Personal productivity
Instead, the workstation is reserved exclusively for privileged administration.
Typical activities might include:
- Managing Microsoft Entra
- Administering Exchange Online
- Managing Microsoft Intune
- Reviewing Microsoft Defender incidents
- Managing Azure resources
- Performing privileged operational tasks
By reducing unnecessary exposure, organisations reduce opportunities for privileged sessions to be compromised.
A Jump Box Is Not a Privileged Access Workstation
Another misconception is that a Jump Box or Bastion Host is the same thing as a Privileged Access Workstation.
It isn’t.
Although they often appear together in privileged access architectures, they solve different security problems.
A Jump Box exists to provide controlled access into a protected network or administrative environment.
Its purpose is to protect access to systems.
A Privileged Access Workstation exists to provide a trusted environment from which privileged administration is performed.
Its purpose is to protect the administrator and the administrative session.
These are complementary security controls, not interchangeable ones.
A compromised administrator connecting through a Jump Box is still a compromised administrator.
The Jump Box doesn’t automatically make the administrative session trustworthy.
Should a Jump Box Be Used to Access a PAW?
This is another area where architecture becomes important.
A design I occasionally encounter is a standard corporate device connecting to a Jump Box before launching a Privileged Access Workstation or administrative environment.
While this may provide network isolation, it also extends the trust chain.
If the initial workstation has already been compromised, the attacker may be able to intercept or hijack the privileged session before it ever reaches the PAW.
Ideally, the Privileged Access Workstation should represent the beginning of the trusted administrative session, not simply another hop in a chain of increasingly trusted systems.
This is one of the reasons dedicated physical PAWs continue to provide the highest level of assurance.
Trust begins at the endpoint itself.
That’s not to say Jump Boxes or Azure Bastion aren’t valuable.
Far from it.
They remain excellent controls for protecting administrative access to servers and infrastructure.
They simply shouldn’t be mistaken for a replacement for a Privileged Access Workstation.
Security Controls Work Together
One misconception I still hear is that organisations no longer need PAWs because they have deployed passkeys or phishing-resistant authentication.
In reality, each security control addresses a different part of the administrative journey.
Passkeys protect authentication.
Conditional Access evaluates access requests.
Privileged Identity Management reduces standing privilege.
Microsoft Defender helps detect malicious activity.
Jump Boxes protect access to administrative infrastructure.
A Privileged Access Workstation protects the environment in which privileged administration takes place.
None of these technologies replace one another.
They complement one another.
Effective security comes from combining multiple layers of protection rather than relying on a single control.
Modern Privileged Access Workstations
Historically, a PAW meant a dedicated physical workstation.
For many organisations, this still represents the highest level of assurance.
Today, however, organisations have more options available.
These include:
- Dedicated physical Privileged Access Workstations
- Dedicated Windows 365 Cloud PCs
- Azure Virtual Desktop administrative environments
- Highly hardened managed devices for lower-risk administrative roles
Each provides different levels of assurance, operational flexibility and cost.
Choosing the right solution depends on the level of trust required, the risks being managed and the operational needs of the organisation.
We’ll explore each of these options throughout this series.
It’s About Assurance, Not Hardware
Perhaps the biggest mistake organisations make is focusing on the hardware itself.
The workstation is simply the platform.
The real objective is to create an administrative environment that provides an appropriate level of assurance for the identity using it.
A dedicated physical workstation may provide the highest level of assurance.
A Windows 365 Cloud PC may provide the right balance between security and operational simplicity.
A shared Azure Virtual Desktop environment may be appropriate for certain administrative teams.
The technology may differ.
The principle remains exactly the same.
Increase confidence in the environment from which privileged administration is performed.
Key Takeaways
A Privileged Access Workstation isn’t defined by the device it runs on.
It’s defined by the trust boundary it creates around privileged administration.
Likewise, a Jump Box isn’t a Privileged Access Workstation.
It protects access to systems, while a PAW protects the administrative environment itself.
As organisations continue adopting Zero Trust and phishing-resistant authentication, protecting privileged identities requires looking beyond authentication alone.
The workstation is no longer just another endpoint.
It’s a fundamental component of a modern privileged access strategy.
What’s Next?
Now that we’ve explored what a Privileged Access Workstation actually is, the next question becomes even more important.
Do you actually need one?
Not every administrator requires the same level of workstation assurance.
In the next article we’ll explore how to determine when a PAW is justified, which administrative roles benefit most from dedicated administrative environments and how these decisions should be driven by business risk rather than a one-size-fits-all approach.
Comments
No comments yet — be the first to leave one below.