Who can do what.
WHAT ROLES PROVIDE
Defined sets of administrative permissions.
WHAT TO AVOID
Assigning the highest role broadly.
WHY
It grants control over everything, including the ability to remove others.
WHAT TO ASSIGN INSTEAD
The narrowest role that permits the work.
WHAT ROLES EXIST FOR COMMON NEEDS
User administration Helpdesk functions, such as password resets Service-specific administration Security and compliance reading
WHAT TO ESTABLISH
How many holders of the highest role exist.
WHAT A REASONABLE NUMBER IS
Few, and more than one.
WHY MORE THAN ONE
A single administrator who becomes unavailable leaves the organisation locked out.
WHAT PRIVILEGED IDENTITY MANAGEMENT PROVIDES
Roles activated temporarily when needed, with approval and justification, rather than held permanently.
WHY THAT MATTERS
A compromised account holds no standing privilege.
WHAT TO MONITOR
Role assignments and changes to them Use of privileged roles
WHAT TO REVIEW
Every assignment, periodically.
WHAT TO REQUIRE FOR ADMINISTRATORS
Separate accounts from daily use, with the strongest authentication.