Cutting standing privilege without stopping the business
Privilege accumulates because granting is easy and revoking feels risky. Somebody needs access to resolve an incident, the grant is made under pressure, and nobody removes it afterwards because nobody is certain what would break. Multiply that across a decade of incidents and the result is a set of accounts where the difference between what is held and what is actually used is very large, and completely invisible until somebody measures it. Nobody is at fault and everybody contributed.
We start by measuring rather than by cutting. Which privileges exist, which have genuinely been exercised, and what each account is for. Application accounts are the priority: an account that runs a reporting module while holding administrative rights is a real exposure with a straightforward fix. Removal is staged, made in a lower environment first, and paired with a defined route to restore access quickly if something turns out to have depended on it. That route is what makes the removal acceptable to operations.
The harder part is keeping it that way. A privilege review with no repeat is a snapshot, and grants resume the following week under the same pressure that created them. We put in a recertification cycle, a route for temporary elevated access that expires on its own rather than by memory, and a report of grants made since the previous review. Emergency access remains possible, because it must, and it becomes visible rather than routine.
- A privilege inventory built from what is held and what has actually been exercised
- Application accounts reduced to the operations they perform, starting with any holding administrative rights
- Removal staged through lower environments, with a fast and defined route to restore access
- Temporary elevated access granted with an expiry rather than with a good intention
- A recertification cycle and a report of every grant made since the previous review