Identity Governance and Access Certification
Identity governance (Access Reviews, entitlement, cross-tenant) that prevents privilege creep and unmonitored external access.
ZT: least privilegeIGA / Access ReviewWindowsCloudIdentity
Loading…
Lateral movement within the network
Identity governance (Access Reviews, entitlement, cross-tenant) that prevents privilege creep and unmonitored external access.
PIM that makes privileged roles eligible rather than permanent, used via approved and time-limited activation.
Keep the number and use of privileged accounts to a minimum: Domain Admins hygiene, LAPS, JIT/PIM.
Account lifecycle management: proper creation, assignment with least privilege, timely disabling, and periodic access reviews.
A least-privilege architecture that rejects the assumption of a trusted internal network and verifies every access request by identity, device, and context.