Identity sprawl is the breach path nobody budgets for

Every organization knows its endpoint count. Almost none can state, on demand, how many accounts hold standing privilege, and that gap is where incidents start.

Ask a CIO how many laptops the company owns and the answer arrives in seconds. Ask how many accounts hold standing administrative privilege across the environment, including service accounts, break-glass accounts, and the ones created for a migration in 2019, and the answer is usually a meeting, then a spreadsheet, then a follow-up meeting.

That asymmetry is not a documentation failure. It is structural. Endpoints are procured, so they land in an asset register. Identities accrete: a contractor onboards, a project spins up a service account, an application gets an integration user, a team is reorganized and the old group membership is never revoked. Nobody signs a purchase order for an entitlement.

What sprawl actually costs

The direct cost is licensing, and it is the least interesting part. The real cost shows up in three places.

Blast radius. Every account with standing privilege is a viable first step for an attacker. Once credential access is achieved, the question is only how far that credential reaches. An environment with 40 genuine administrators and 400 accidental ones has a blast radius ten times larger than its architecture diagram suggests.

Audit drag. When an auditor asks who can access a regulated data set, the honest answer for most organizations requires reconstruction: pull group memberships, resolve nested groups, cross-reference resource-level ACLs, then discover that three of the groups are themselves nested into a fourth that was created for a decommissioned application. Weeks of senior engineering time, repeated annually.

Change paralysis. Teams stop cleaning up entitlements because nobody can confidently say what a given group does. The safest action is always to leave it alone, so the sprawl compounds, and each year the cleanup gets more expensive than the year before.

The organizations that handle this well are not the ones with the best tooling. They are the ones that decided entitlements have owners, and then enforced it.

Why the usual fixes stall

Two approaches dominate, and both tend to stall for predictable reasons.

The first is the big-bang role redesign: model every job function, map every entitlement, migrate everyone at once. It stalls because role modeling done in the abstract produces roles that do not match how people actually work. The moment the first exception is granted outside the model, the model starts decaying. And exceptions always arrive.

The second is the annual access review as the primary control. It stalls because of what we call the rubber-stamp problem. A manager handed 180 entitlements to certify, each named something like APP-FIN-RW-PROD-EMEA, will approve all of them in one click, because the tooling gives them no way to distinguish the four that matter. The review completes. The evidence is filed. Nothing was actually reviewed.

What works instead

The pattern we see succeed is narrower and more boring, and it starts from the risk rather than from completeness.

  • Eliminate standing privilege before modeling roles. Privileged access management delivers more risk reduction per week of effort than any role redesign. Time-bound, approved, logged elevation removes the standing target entirely, and it does not require you to understand every entitlement in the environment first.
  • Give every non-human account a human owner. Service accounts and integration users are where sprawl concentrates and where reviews are weakest. An account without a named owner should be a finding, not a footnote.
  • Review by exception, not by inventory. Surface the entitlements that changed, that are unused, or that grant access to regulated data. A manager given twelve meaningful decisions will make them. Given 180, they will make none.
  • Automate the leaver path first. Joiner and mover automation is more visible, but leaver is where the risk sits. If deprovisioning depends on a manager remembering to file a ticket, it will not happen reliably.

Where to start this quarter

Run a standing-privilege census. Not a full entitlement inventory, just an answer to one question: which accounts, human and non-human, currently hold privileged access that does not expire? Most organizations we work with find a number two to five times higher than their estimate, and the first cleanup pass is usually measured in days rather than quarters.

That census gives you something a role redesign never does: a number you can move, report on, and defend to a board. It also tells you exactly where privileged access management should land first, which turns an abstract identity program into a sequenced piece of work with a visible finish line.

Related practice

Secure Identity

Directory design and migration, identity governance, RBAC, privileged access, and B2B/B2C, built to survive an audit and a bad Tuesday.