An attacker does not need to hack a system if they can simply log in.
Compromised credentials, a forgotten account or overly broad permissions can open the door to sensitive data and critical systems. At the same time, the attacker’s activity may look like the routine work of a legitimate user.
Reactive protection of networks, devices and infrastructure is therefore not enough. Organisations also need control over who or what is allowed to access their systems, what permissions they use and why those permissions were granted.
This is precisely the area addressed by Identity Governance & Administration (IGA). It builds on Identity Management (IDM), which provides the practical administration of identities and accounts throughout their lifecycle — from creation and modification to deactivation. IGA complements identity lifecycle management with rules and control mechanisms such as access approvals, role management, access reviews and audit trails. It helps ensure that the right identities have the right permissions, for the right reasons and only for as long as necessary.
Identity management does not end when an account is created
A single employee may have accounts in a directory service, an enterprise system and multiple cloud applications. In addition to a standard account, they may also use an administrator identity or a separate account for remote access.
Organisations do not manage employee identities alone. The identities of contractors and suppliers, service accounts, applications, automated processes, AI agents and other machine identities all require the same level of governance.
For every identity, an organisation needs to know:
- who or what it belongs to,
- which resources it can access,
- what permissions it uses and why,
- who approved the access,
- how long the access should remain valid,
- when and how it will be removed.
If this information cannot be retrieved, the organisation does not have full control over access.
IGA connects identity lifecycle management with the governance, approval and regular review of permissions. It ensures that accounts and permissions reflect the identity’s current role or purpose, a genuine need and the organisation’s internal policies.
Where the most common risks arise
Identity and permission issues usually accumulate gradually during day-to-day operations.
Excessive permissions arise when people change positions and receive new access while retaining permissions from previous roles. A compromised account may then give an attacker access to systems the user no longer needs for their work.
Forgotten accounts remain active after an employee or contractor leaves. These are often accounts in applications outside standard processes or accounts without a clearly defined owner.
Overly broad privileged permissions increase the impact of an error or account compromise. The risk grows further when the same accounts are used for both routine and administrative work.
Unmanaged technical identities may operate for years with broad permissions and long-lived passwords, keys or tokens. Applications and service accounts therefore also need a known owner, a clearly defined purpose and a managed lifecycle.
When weaknesses in identity governance become visible in practice
Security incidents usually involve a combination of causes. The following examples do not suggest that an IGA solution alone would automatically have prevented the entire attack. They do, however, show how weaknesses in identity lifecycle and permission management can increase its impact.
Cash App: access by a former employee
In 2022, Block announced that a former employee had downloaded Cash App Investing reports containing information about certain customers. The company contacted approximately 8.2 million current and former customers in connection with the incident.[1]
The public disclosure does not describe the precise access method. The case nevertheless shows why offboarding must cover all accounts, permissions and other means of access, rather than a single central account alone.
Twitter: too many people with sensitive access
During the 2020 attack on Twitter, attackers used social engineering to gain access to internal tools used to manage user accounts.
According to an investigation report by the New York State Department of Financial Services, more than one thousand employees had access to these tools. Twitter reduced the number further after the incident.[2]
The case shows that approving sensitive access once is not enough. Organisations need to review regularly which users still require it, whether it reflects their current role and whether the number of authorised individuals can be reduced.
Microsoft: a legacy application with elevated permissions
At the end of 2023, the Midnight Blizzard group compromised a legacy account in Microsoft’s non-production environment. It subsequently used a legacy test OAuth application with elevated permissions to gain access to email mailboxes.[3]
The incident is a reminder that identity lifecycles do not apply only to employees. Legacy applications and technical accounts can retain permissions long after their original purpose has ceased to exist.
What effective IGA changes
IGA brings together information about identities, systems, roles and permissions into a unified and controllable governance model.
Keeps identities and their permissions up to date
Onboarding, role changes or the end of a relationship with the organisation can automatically trigger the corresponding changes to accounts and permissions.
Enforces the principle of least privilege
A user or system receives only the permissions required for the current activity. Sensitive permissions can be approved, time-limited and reviewed regularly.
Helps govern privileged and technical identities
IGA makes it possible to record the owners of privileged and technical identities, govern the assignment of their permissions and review regularly whether those permissions are still required. Service accounts, applications and other machine identities can therefore have a clearly defined owner, purpose and limited scope of permissions.
Creates an audit trail
An organisation can demonstrate who requested access, who approved it, why it was granted and when it was removed. During an incident, it can determine the scope of a compromised identity’s permissions more quickly and remove or block related access.
IGA and regulatory requirements
The importance of access governance is also reflected in the European NIS2 Directive, which lists access control policies, human resources security and asset management among the measures for managing cyber security risks. IGA helps translate some of these requirements into specific, auditable processes through access approvals, role management, regular access reviews and the timely removal of unnecessary access.[4]
Regulation is not, however, the main reason to focus on identity governance and administration. Well-governed identities reduce the likelihood of an incident, limit its potential impact and help demonstrate that the organisation genuinely controls access. They also simplify day-to-day operations, reduce manual work and improve operational efficiency.
Do you truly have identities and permissions under control?
Warning signs include situations where:
- IT cannot quickly identify all accounts associated with a particular person,
- removing access after someone leaves takes several days,
- people retain permissions from previous positions,
- administrative or service accounts have no known owner,
- access reviews are performed manually in spreadsheets,
- approvers confirm access without sufficient context,
- no one can explain why a particular identity has a specific permission.
When these problems recur across an organisation, manual administration is no longer secure or sustainable.
IGA brings control, traceability and clearly defined accountability to the governance of identities and permissions. It influences whether a compromised account gives an attacker access to a single application or a significant part of the organisation. It also helps determine the scope of a compromised identity’s permissions more quickly and restrict related access.
At Orchitech, we help medium-sized and large organisations govern identities, their permissions and their lifecycles. We begin by understanding the client’s actual environment, processes and risks. On that basis, we design solutions that are secure, auditable and sustainable over the long term.
Start with a simple question: can you identify all accounts and permissions associated with a specific employee, contractor or application within a few minutes?
Sources
[1] Block, Inc.: Current Report, Form 8-K, 4 April 2022. Official notification of the Cash App Investing incident submitted to the US Securities and Exchange Commission.
[2] New York State Department of Financial Services: Twitter Investigation Report, 14 October 2020.
[3] Microsoft Threat Intelligence: Midnight Blizzard: Guidance for Responders on Nation-State Attack, 25 January 2024.
[4] European Parliament and Council of the European Union: Directive (EU) 2022/2555 — NIS2, Article 21, 14 December 2022.