← All work

An Australian financial services licensee · 2026

Privileged access and endpoint hardening

Privileged access sprawls quietly, because every grant had a reason at the time and none of them looks wrong on its own. Counting it is a short job. Reducing it safely is the part that needs care.

Found

97

After

5

Privileged directory role assignments on the primary administrative account. One mark per assignment. Nobody granted these deliberately, which is why nothing caught them: every one had a reason at the time and none looks wrong on its own.

How to tell whether you have this

Open your tenant and count how many accounts hold administrative roles, and how many roles the main one holds. That is a ten-minute job and you can do it without me.

Most people find more than they expected. If nobody can tell you when those assignments were last reviewed, or who reviewed them, that is the finding rather than the number itself.

Why it happens

Nobody grants ninety-odd privileged roles deliberately. They accumulate. A role to solve a problem, another for a migration, another because a vendor asked for it mid-implementation, and no step anywhere that would ever take one away again.

Privileged sprawl is invisible from the inside for exactly that reason. Every individual grant had a justification, so nothing looks wrong until somebody counts the total.

Why it usually stays that way

The honest reason firms leave it alone is not negligence. It is a well-founded fear of locking themselves out of their own tenant while tightening it, usually on a Friday, usually with nobody to call.

That fear is the actual blocker, and it is the first thing I would deal with.

How I would approach it

  1. Count what is actually assigned, before touching anything. The number is the argument for doing the rest.
  2. Build the escape hatch first. Break-glass administrator accounts with sealed credentials, a deliberate conditional access exclusion and their own sign-in alerting. Until that exists, nothing else is safe to do.
  3. Reduce, in order of risk, rather than all at once.
  4. Stage phishing-resistant MFA through report-only conditional access so the impact is measured before anything is enforced. Nobody gets locked out finding out.
  5. Review the endpoint side, since access controls on unmanaged devices are decorative. Compliance policies, settings-catalog baselines, attack-surface reduction, and BitLocker key escrow actually verified.
  6. Set the cycle that stops it drifting back, and reconcile any uplift tracker you already keep against what is genuinely deployed.

What you end up with

Accurate answers to the three questions nearly every security questionnaire asks. Is administrative access limited to those who need it. Is it reviewed, and on what cycle. Is privileged access protected by multi-factor authentication that resists phishing.

Before this kind of work the honest answers are usually no, never and no, while the compliance manual says least privilege and nobody has checked.

Control design here aligns to ISO 27001 and 27701 and to the Essential Eight. Alignment is the accurate word and I use it deliberately, because it is not the same claim as certification.

What it looked like in practice

delivered

Figures from the engagement described above, not a projection of what your estate would produce. Yours will look different.

RefFoundNowWhat the figure refers to
01975privileged directory role assignments on the primary administrative account
0277.8%tenant Microsoft Secure Score, against a 53.7 per cent all-tenant average

Is this yours?

If any of the above sounds like your estate, say so and I will tell you what checking would involve. Most of these start as a short look rather than a project.

Not sure it is this one? The rest of the work covers monitoring, identity, deployment, cost, AI use and compliance documentation.

Related work

All work