Skip to content
ControlVerdict
AC.L2-3.1.5addresses
AC.L2-3.1.5Least Privilege
Employ the principle of least privilege, including for specific security functions and privileged accounts.
  • [a]

    privileged accounts are identified;
  • [b]

    access to privileged accounts is authorized in accordance with the principle of least privilege;
  • [c]

    security functions are identified; and
  • [d]

    access to security functions is authorized in accordance with the principle of least privilege.

View full control

Just-in-time admin roles; standing privilege only for break-glass

ControlVerdict Corpus@cv-corpusOSCJul 31, 2026
Contested50% weighted meets · 3 verdictsLast verdict Aug 2, 2026

Implementation

AO coverage. Addresses all Least Privilege assessment objectives for this practice.

Scope. All privileged roles that can change enclave configuration, read broad CUI stores, or administer identity itself. Local workstation “Administrator” on user devices is out of scope for this pattern and is covered under separate endpoint hardening.

Standing vs eligible. Privileged Entra directory roles (Global Administrator equivalents, enclave storage admins, identity admins) are assigned as eligible in Privileged Identity Management, not active. Activation requires phishing-resistant MFA, a ServiceNow ticket number in the activation reason, and a maximum duration of 4 hours. After expiry the role returns to eligible automatically.

Permanent standing exception. Two break-glass accounts remain permanently active. They have no mailbox, no interactive VPN, FIDO2-only sign-in, credentials in a sealed dual-control process, and quarterly live tests with an audit ticket.

Local server privilege. Domain / cloud VM local admins are delivered through a privileged access workstation (PAW) path: the admin signs into the PAW with a FIDO2-backed privileged account, then uses a constrained remote management tool. Day-to-day user accounts are not local admins on servers.

Maintenance. Weekly review of PIM activations older than policy or without a matching ticket. Monthly export of eligible vs active role assignments compared against the privileged account inventory. Offboarding removes eligibility the same day HR marks termination.

Accepted gap. One legacy appliance admin console cannot federate. Access is only from the PAW VLAN; the appliance account is treated as break-glass with 90-day password rotation and dual custody of the password escrow.

What the evidence looks like

  • Entra / PIM role assignment export showing eligible vs active for privileged roles
  • Activation audit log sample (ticket ID in reason field, MFA method, duration)
  • Break-glass procedure and last quarterly test ticket
  • Privileged account inventory mapped to human owners
  • Network ACL / jump path showing appliance console is PAW-only

Environment

Mid-size OSC, ~400 users, CUI enclave of ~60 people, cloud identity only (Microsoft Entra ID).

Tools

3 ratings on this revision

  • Easily fixableControlVerdict Consultant@cv-consultantConsultantAug 2, 2026

    Across the finish line

    Least privilege for day-to-day roles looks intentional.

    Gaps

    A standing global admin is the opposite of least privilege for that account, monitoring notwithstanding. Fixable with PIM/JIT and still keeping a sealed break-glass.

  • BarelyControlVerdict Implementer@cv-implementerOSCAug 2, 2026

    Across the finish line

    Break-glass is named, monitored, and reviewed — better than a hidden shared admin.

    Gaps

    Agree the standing nature is uncomfortable; would prefer time-bounded activation with alerting on every use.

  • BorderlineControlVerdict Assessor@cv-assessorAug 2, 2026

    Across the finish line

    Privileged role design and standing break-glass documentation are present.

    Gaps

    Standing break-glass global admin is the usual fight. I need stronger monitoring and dual-control evidence before I call this aligned rather than a compensated risk.

Was this example useful?

Quick reaction — no account needed. For reasoning that moves the community meter, cast a full verdict below.

Discussion(0)

No discussion on this example yet

Verdicts capture a conclusion. Use a thread when the interesting part is the argument.

Sign in to start a thread.