Glossary
Privileged access workstation (PAW)
A privileged access workstation is a hardened, dedicated device used only for administrative tasks, isolated from email, browsing and daily work.
A privileged access workstation (PAW) is a device reserved for sensitive administration — typically of Tier 0 systems such as domain controllers, PKI or identity synchronisation servers. It runs a hardened, locked-down image with application allowlisting, no local admin rights for the user, no email client and no general internet browsing, and it is managed only from within its own tier. Administrators use a separate, ordinary device for everything else. A jump server alone is not a PAW: if the device used to reach the jump server is compromised, the keystrokes and session are too.
It matters because the device an administrator types on is part of the security boundary. Phishing, malicious browser content and compromised helpdesk tooling routinely land on everyday workstations; if a Domain Admin signs in from there, the attacker inherits that access. A PAW removes the most common entry point for credential theft. Combine it with authentication policies that only allow Tier 0 accounts to sign in from PAWs, so stolen credentials are useless elsewhere.
See Building privileged access workstations and Tier 0 and privileged access.