Ordering identities and access
By Redaktion techport.ai, IT-Beratung · Last updated on
Permissions grow in one direction. Whoever changes department gains the new rights while the old ones remain. Whoever once needed access as a stand-in keeps it. Whoever leaves usually loses their account, but not every access, particularly not in services outside central management.
After a few years part of the workforce has access to areas nobody deliberately granted. That is invisible in daily work and becomes visible during an attack, during an audit, or when an assistant system suddenly finds everything a person is allowed to read.
How you notice it
- Accounts of departed employees are still active.
- New employees get rights by being copied from a colleague.
- There are shared accounts whose password several people know.
- For a folder or a system nobody can say who may access it and why.
Why this happens
Permissions are granted at the moment of the request, under time pressure, with the legitimate aim of letting someone work. They are never withdrawn at the moment of a request, because nobody asks. There is no trigger for withdrawal apart from departure, and even there the list of accesses to remove is rarely complete. As long as nobody reviews regularly, the stock grows automatically.
How we go about it
- Make the current state visible. We analyse which people can access which systems and data areas, including services outside central sign-in. That analysis is usually the most persuasive part of the project.
- Roles instead of individual rights. We build roles along activities and assign rights to them, so that joiners, leavers and movers run through the role. Individual rights remain the justified exception with an expiry date.
- Secure the sign-in. We introduce multi-factor authentication, starting with everything reachable from outside and with administrator accounts, and separate administrative from normal accounts. Shared accounts get replaced or made traceable.
- Anchor processes and review. We tie joiners and leavers to a procedure with a checklist and evidence, and set up a recurring review in which the responsible areas confirm or remove their permissions.
What you gain
- A markedly smaller attack surface, because stolen credentials open less.
- Evidence of who may access what, for audits and customers.
- Faster onboarding, because rights come with the role rather than by request.
From our projects
Analysing actual access to file storage almost always produces surprises, frequently around HR, costing or contract folders readable by large parts of the workforce. The cause is usually inherited rights from a folder structure created years ago. The second recurring finding concerns administrator rights: in many companies technical staff work permanently with elevated rights, including when reading email. Separating a normal from an administrative account is one of the most effective single measures and can be done within days.
Good to know
For personal data, Article 32 GDPR requires measures ensuring a level of security appropriate to the risk, explicitly including access control. Granting permissions on a need to know basis is therefore not a recommendation but an obligation, and its implementation has to be demonstrable. For companies within the scope of the German BSI Act, access control and securing authentication are part of the risk management measures under Section 30 BSIG. Where permissions are analysed in order to assess employee behaviour, codetermination has to be observed as well.
Häufige Fragen
Is multi-factor authentication not too cumbersome for daily work?
It is barely noticeable in the right places if it is configured sensibly: longer intervals for trusted devices on the internal network, consistent enforcement for external access and for administrator accounts. Measured against the effort it is the most effective single measure against stolen credentials, and stolen credentials are one of the most common entry routes.
How often should permissions be reviewed?
Every six months for critical systems and administrator rights, annually for the rest. What matters is that the review is confirmed by the responsible business people and not by IT alone, because only the department can judge who needs which access for their work.
Let us talk about Ordering identities and access
In a thirty minute first call we work out where your biggest lever sits and whether we are the right people for it.
Further reading
Back to the field Security and Resilience