Identity assurance · IAM-001

Standing privileged access in Microsoft Entra ID: detect it, classify it and prove the result

Permanent privileged access is easy to find and easy to oversimplify. A useful enterprise control must distinguish unnecessary standing privilege from PIM eligibility, emergency access and approved exceptions—and it must prove what happened after remediation.

Why a list of Global Administrators is not enough

A role export answers who has privilege now. It does not answer whether the privilege is appropriate, whether it should be eligible instead of permanently active, whether the account is a controlled emergency identity, whether an exception is still valid or whether a previous remediation actually stayed in place.

The assurance problem is therefore broader than inventory. The control needs classification, ownership, exception handling, change approval, verification and evidence.

A production-oriented control workflow

DiscoverInventory active and eligible privileged role assignments in the agreed Entra scope.
EvaluateSeparate standing human privilege from JIT/PIM eligibility, emergency access and legitimate temporary exceptions.
ApproveRequire an accountable decision before changing privileged access.
RemediateRemove unnecessary access, reduce privilege or move appropriate assignments to controlled eligibility/JIT.
VerifyRe-collect the configuration and confirm that the intended state actually changed.
EvidenceLink the control result to timestamped source data, exception records and change evidence.

What should be classified

An IAM-001-style review should at minimum distinguish:

  • Permanent active human privilege — usually the primary review population.
  • PIM eligible privilege — not standing access, but still subject to separate activation-quality controls.
  • Emergency access accounts — legitimate permanent privilege may exist when the account is explicitly designated, monitored and periodically tested.
  • Approved temporary exceptions — must have an owner, rationale, compensating controls and review/expiry date.
  • Workload identities — should be evaluated separately from human privileged access because remediation patterns differ.

PASS/FAIL alone creates false confidence

Enterprise assurance needs at least four practical states: PASS, FAIL, REVIEW and EXEMPTED. A permanent administrator without an approved rationale may be a FAIL. A current emergency-access identity may be EXEMPTED. A recent PIM activation may require REVIEW under a different control rather than failing the standing-access control.

Remediation must be supervised

Automatically removing or converting privileged access can create an outage or lock out the organisation. Before remediation, validate emergency access, dependencies, last-admin conditions, authentication readiness and the client change process. The change plan should state the intended target state and the rollback path before execution.

The evidence package is part of the product

A completed control should link the conclusion to retrievable evidence: privileged role inventory, eligibility state, exception or emergency-access record, approved change, post-change collection and collection timestamps. Where useful, an integrity manifest can make the evidence bundle easier to trace and reproduce.

From one-time review to continuous assurance

The recurring value appears when the same control is re-run against the approved baseline. New standing privilege, expired exceptions and unexpected changes become drift that can be assigned, remediated and re-verified rather than rediscovered during the next audit.