---
title: Policy Management
slug: kronpam-reference-guide-3-5-0/policy-management
description: Learn how the Kron PAM role-based management system utilizes realms to connect groups, enabling admins to efficiently manage users, devices, and policies. Explore the realm structure diagram to gain insights into user authentication and policy authorizati
docTags: 
createdAt: 2022-08-02T21:10:25.000Z
---

The Kron PAM role-based management (user/device/policy) concept is based on realms. Individual creations are collected under a group and groups are connected to each other. Realms connect the groups together so that users can connect to devices by using policies. The diagram below illustrates Kron PAM's realm structure, which allows admins to manage specific users to authenticate on specific devices and authorize specific policies.

::Image[]{src="https://api.archbee.com/api/optimize/g9cApVza9NIhSh0pjZYtA/xMyu02zy3EB0uVxompWmo_image.png" size="78" width="839" height="394" caption="Role-Based Management Concept" position="center" showCaption="true"}

Policies are applied to SSH/Telnet connections. RDP and SFTP connections do not require policies.&#x20;

Please refer to section [Policy Management](docId\:gSjyPzaH2INRDCBcgsiJs) for policy definitions, policy tracking, and approval mechanism configurations.