Policy Administrator (PA)
The NIST SP 800-207 zero trust component that carries out the policy engine's decision by commanding enforcement points to open or close the path between a subject and a resource.
The policy administrator is one of the core logical components of zero trust architecture in NIST SP 800-207 (August 2020). It is responsible for establishing or shutting down the communication path between a subject and a resource, which it does through commands to the relevant policy enforcement point. When the policy engine approves a request, the PA configures the PEP to let the session start; when a request is denied, or an earlier approval is withdrawn, the PA signals the PEP to close the connection. This signalling runs over a control plane kept separate from the data plane that carries application traffic.
SP 800-207 presents the policy engine and the policy administrator together as the policy decision point: the engine decides and logs, and the administrator executes. The PA is easily confused with the policy administration point of the XACML and ABAC model, which is where policies are written. The PA does not write policy; it acts on decisions for live sessions within a zero trust design.
Exam relevance: a scenario is likely to describe a session cut off when a device falls out of compliance and ask which component instructs the enforcement point. Candidates are expected to assign the decision to the policy engine and its execution to the policy administrator.