Skip to content

Home Expertise / Audits & assessments

AUD / AUD-03

Identity and privilege audit

A review of who has which access, how accounts are protected and how a compromised identity could affect sensitive resources.

WHEN IT HELPS

A focused response
to a defined need.

IAM or IT manager; dormant accounts, too many administrators, directory mergers or weak offboarding.

AT A GLANCE

Family
Audits & assessments

Engagement
Assessment

Reference
AUD-03

SCOPE & OUTCOMES

What the engagement covers.

Scope

  • Human and service accounts
  • groups and delegated rights
  • authentication, conditional access and joiner/leaver processes

Deliverables

  • Privilege matrix
  • lifecycle gaps
  • least-privilege and access-control recommendations

Acceptance evidence

Sampled sensitive privileges have an owner, a justification and a keep, reduce or remove decision.

DELIVERY

How the work is structured.

Approach

Scope assets and criteria; gather evidence and interviews; validate gaps; present priorities and limitations.

Prerequisites & responsibilities

Customer: inventory, read access, documents and business contacts. Provider: assessment and debrief. Production changes are not included by default.

Scope factors

Sites, assets, technologies and interviews; assessment depth; inventory quality; access constraints; required reporting. One-off project with optional follow-up.

Questions to clarify

Which directory is authoritative? Who approves access? How do you revoke a contractor’s access?

IMPORTANT BOUNDARIES

Discovering excessive access does not prove abuse; compromise assessment is a separate engagement.

Sampling and observation date are explicit. No assessment certifies the absence of flaws; remediation, penetration testing and recurring follow-up are separate scopes.

IN PRACTICE

Illustrative situations.

These examples describe possible engagements and target outcomes. They are not customer references or achieved results.

Scenario 01

A consultancy has former contractors with cloud access. Project: reconcile directories, contracts and groups. Target outcome: an approved revocation list and corrected offboarding, without blindly deleting a required service account.

Scenario 02

A manufacturer uses administrator accounts for everyday email. Project: analyse privileged use. Target outcome: separate accounts, logon restrictions and a PAM roadmap subject to business approval.

Technology and reference context

Active Directory, Entra ID, LDAP/FreeIPA and cloud IAM: confirm scope and delivery expertise.

The final technology set is agreed during scoping, based on interoperability, licensing, access rights and operating requirements.

CONNECTED SERVICES

Build the next step.

These services can complement the engagement. They are not automatically included.

START A CONVERSATION

Make the scope clear.

We will clarify the objective, dependencies and responsibilities of this service before proposing delivery.