Configuration Review
Configuration Review of IAM and PAM
Identity is the control plane. Most organisations can describe how an account is created and almost none can describe how entitlements are removed when someone changes role, which is why long-serving staff accumulate access nobody would grant them today. This review measures that accumulation, and assesses whether privileged access is genuinely brokered or merely documented.
Methodology
- 01
Identity source and lifecycle review
Authoritative sources, how identities are created, and whether joiner, mover and leaver processes are automated or depend on someone remembering to raise a ticket.
- 02
Entitlement analysis
Current entitlements compared against role definitions, with accumulation measured by tenure and by role change history. Entitlement creep is quantified rather than described.
- 03
Orphan and dormant account review
Accounts with no owner, no recent authentication, or belonging to people who have left, across every connected system rather than only the directory.
- 04
Privileged account inventory
Every privileged account across directory, infrastructure, database, application and cloud, and how many are outside the vault.
- 05
PAM platform review
Vault coverage, credential rotation, session brokering and recording, break-glass procedures, and whether privileged access can still be obtained by bypassing the platform.
- 06
Access review and certification
Whether periodic access reviews happen, what evidence they produce, and whether reviewers actually revoke anything or approve everything.
- 07
Segregation of duties
Toxic combinations of entitlements, particularly in finance and procurement systems where a single identity can both create and approve.
- 08
Reporting and retest
Technical report and executive summary together, with a remediation plan, then a retest confirming closure.
Approach to testing
- Entitlement creep is measured, not asserted. Access held by staff with five or more years' tenure is compared against access held by recent joiners in the same role, and the difference is the accumulation.
- Leaver process is tested against reality: a sample of people who left in the last year is traced through every connected system, not just the directory.
- PAM is assessed on bypass, not on deployment. A vault covering 80% of privileged accounts means an attacker uses the other 20%.
- Access certification is assessed on outcome. A campaign with a 99% approval rate is a rubber stamp, and reporting it as a working control is misleading.
- The review covers systems outside the identity platform — local accounts, application-native users and service accounts are where the ungoverned access lives.
Types of assessment
Full IAM and PAM review (default)
Lifecycle, entitlements, privileged access and certification across the estate.
Privileged access focus
PAM platform coverage, bypass routes and privileged account inventory only. The highest-risk subset.
Joiner-mover-leaver audit
Process tested against a sample of real identity events, tracing each through every connected system.
Segregation of duties review
Toxic entitlement combinations in financial and operational systems. Often driven by audit rather than security.
Frameworks and standards
- NIST SP 800-63
- Digital identity guidelines for authentication assurance levels and lifecycle.
- ISO/IEC 27001 Annex A.5.15 to A.5.18
- Access control, identity management and access rights, where the client maintains an ISMS.
- CIS Controls v8 Controls 5 and 6
- Account and access control management maturity.
- Microsoft Enterprise Access Model
- Tiering reference where the estate is Microsoft-centric.
- SOX / ITGC
- Where the client is in scope, access provisioning, review and segregation of duties are assessed against audit expectations.
Tools used
Tooling is where testing starts, not where it ends. Every automated result is reproduced by hand before it reaches a report.
Directory export and analysis tooling
Entitlement extraction and comparison across users, groups and roles.
BloodHound
Effective privilege and escalation paths where the estate is Active Directory or Entra ID.
PAM platform reporting (read-only)
CyberArk, Delinea, BeyondTrust and similar — coverage, rotation compliance and session records.
Custom entitlement diff scripts
Comparing access by role and tenure to quantify accumulation.
Cloud IAM analysers
Effective permission computation where cloud platforms are in scope.
Checklist approach
The checklist is the floor, not the ceiling. It guarantees coverage so nothing standard is missed; the findings that matter usually come from what a tester does after it is complete.
Identity lifecycle
- Authoritative source and its accuracy
- Joiner provisioning: automated or manual, and time to access
- Mover process and whether prior entitlements are removed
- Leaver process and time to full deprovisioning across all systems
- Contractor and third-party identity lifecycle
- Shared and generic accounts, and their ownership
Entitlements
- Entitlement creep measured by tenure and role change
- Role definitions against actual assigned access
- Nested group membership and its effective result
- Standing access that should be time-bound
- Access granted by exception and never reviewed
Dormant and orphan accounts
- Accounts with no authentication in 90 days
- Accounts belonging to departed staff, across every system
- Service accounts with no documented owner
- Accounts in connected applications not governed by the identity platform
- Disabled accounts retaining group membership and licences
Privileged access
- Complete privileged account inventory across all platforms
- Vault coverage as a percentage, and what sits outside it
- Credential rotation frequency and verification
- Session brokering, recording and review
- Break-glass account procedure, storage and monitoring
- Routes to privileged access that bypass the PAM platform
Governance
- Access review cadence, scope and approval statistics
- Evidence produced by certification campaigns
- Segregation of duties rules and detected violations
- Exception process and outstanding exception age
- Reporting to management and what action follows
How findings are scored
Every finding is scored on CVSS 3.1 and placed in one of five levels. The executive summary adds a sixth band — Compliant — so components that passed appear on the same chart as those that did not.
- Critical
- Immediate measures must be taken. These vulnerabilities can allow an attacker to take complete control of the application or server — stealing user data, tricking users into supplying sensitive information, or defacing the site.
- High
- Maximum risk associated with a specific vulnerability instance. May enable an attacker to compromise the application and its data, partially or completely, or to modify application behaviour beyond its intended purpose. To be handled with utmost priority.
- Medium
- Considerable risk. May enable an attacker to exploit the application to a particular level, gaining low-level information that can be used to craft more specific attacks.
- Low
- Lowest risk. May allow an attacker to gain some information about the application that was not intended to be known, without an exploitation technique currently available at that instance.
- Informational
- A functionality or component is missing best-practice implementation. Not a risk today, but may become one as the application changes or as exploitation techniques, policy or legal requirements evolve.
Scan types selected
- Safe Checks
- Standard / OWASP Top 10
- Destructive
- SANS Top 25
- Business Logic Vulnerability Testing
Standard toolset by stage
- OSINT
- Datasploit, Google Dorks, Shodan
- Enumeration & Scanning
- Nmap, Wfuzz, Unicornscan
- Domain Enumeration
- Nikto, DnsRecon, Knock
- Crawling & Fuzzing
- Burp Suite, Acunetix, Netsparker
- Vulnerability Analysis
- OpenSSL, sqlmap, CVE-Details
- Exploitation
- Metasploit, Netcat, Exploit-DB
How CSS tests
A unified swarm of agents, for blind spot detection
AI agents drive several testing tracks against the same target at once, then cross-check each other. A single tester works one hypothesis at a time; parallel agents cover the space a sequential pass leaves behind.
Entitlement creep is a comparison across every user, role and tenure band. Computing it exhaustively is the only way to distinguish genuine role requirements from accumulation.
Leaver deprovisioning gaps hide in systems outside the identity platform. Diffing a departed-staff list against every connected system's user table is mechanical work that manual audit samples.
Toxic entitlement combinations are pairwise or three-way across thousands of permissions; enumerating them is computation, not judgement.
Privileged accounts outside the vault are found by diffing every system's privileged group against the vault inventory, rather than by asking the PAM team what they cover.
Every agent finding is validated by a human reviewer before it reaches the report, and entitlement recommendations are confirmed with the business owner — an account that looks dormant may belong to a quarterly process. The assessment is read-only: nothing is disabled or revoked during the review.
Why this differs
What CSS does that most vendors do not
Every one of these is checkable. Ask any vendor for the same and compare the answers.
Creep is measured
Most reviews report that entitlement creep exists. CSS quantifies it by comparing access across tenure bands in the same role, which turns an abstract risk into a number the business can act on.
PAM assessed on bypass
Coverage percentage is the headline; the routes around the platform are the finding. An attacker uses the accounts that are not vaulted.
Certification assessed on outcome
A campaign approving 99% of access is reported as a rubber stamp rather than as a working control, which is uncomfortable and correct.
Both reports, always
Technical report and executive summary together, plus a remediation plan the identity team can sequence.
Reporting
Two documents, two audiences
Both are produced for every engagement. They are not the same document at two lengths — they answer different questions and are written separately. The structure below is the one CSS actually issues.
Technical assessment report
For the engineers who will fix it
- Disclaimer, and Limitations on Disclosure and Use
- Risk Level & Description — the five levels above, scored on CVSS 3.1
- Scan Type — which of the five assessment types were selected
- Assessment Scope — the control areas covered
- Assessment Date — the exact testing window
- Objective of the Assessment — objectives listed against completion status
- Tools Utilization — manual and automated tooling by stage
- Summary of the Assessment
- Overall Recommendations, split into Must Have and Should Have
- Vulnerability Overall Classifications as per Organization
- Security Issues Highlighted
- The Key Findings — each with evidence and detailed recommendation
- Summary of Findings & Conclusion
For this assessment specifically
- Scope: systems, identity platforms, PAM platform and the review date
- Lifecycle findings with sampled evidence from real joiner, mover and leaver events
- Entitlement creep quantified by role and tenure band
- Dormant and orphan account inventory across every connected system
- Privileged account inventory with vault coverage percentage and the gap listed
- PAM bypass routes identified
- Segregation of duties violations with the entitlement combinations named
- Retest results appended against each original finding
Executive summary
For the people who will fund the fix
- Objectives, each against a completion status
- Overall Finding of the Assessment — total threats identified, broken down by component and severity
- Summary of the Assessment
- Artefacts of the Assessment — the key findings as a numbered register with severity
- Observation of the Assessment — the major attacks the organisation should be prepared for, given what was found
- Overall Recommendation, including a Business Enabling Recommendation sequence
- Must Have and Should Have actions
For this assessment specifically
- How many accounts belonging to departed staff are still active, and what they can reach
- Privileged account count, and how many are outside the vault
- Entitlement creep as a figure the business can act on
- Audit and regulatory position where ITGC or an ISMS applies
- The three changes that most reduce standing privilege
- One page
Case studies
What this finds in practice
Representative engagement patterns. Sector and scale only — no client is named, and no detail is included that could identify one.
A financial services firm of roughly 1,400 staff with a mature PAM deployment.
- Finding
- The PAM platform covered 94% of privileged accounts, which the team reported as strong. The remaining 6% were 71 local administrator accounts on application servers, created during deployments and excluded because rotating them was believed to break the applications. They shared four distinct passwords across all 71 hosts.
- Recommendation
- Bring the local accounts under vault management with per-host unique credentials, testing rotation against each application in a pilot group before estate-wide rollout.
- Outcome
- All 71 onboarded over two months. Two applications did break on rotation, which is exactly why the exclusion had existed, and both were fixed rather than re-excluded.
A retail group with high seasonal staff turnover.
- Finding
- Directory deprovisioning was automated and worked. Tracing 40 leavers through connected systems found 31 still active in the warehouse management system, 18 in the payroll portal and 9 with VPN certificates, because none of those were integrated with the identity platform.
- Recommendation
- Integrate the three systems with the identity platform, and where integration is not possible, add a monthly reconciliation against the leaver list as a compensating control.
- Outcome
- Two systems integrated within the quarter. The third was legacy and got the reconciliation control instead, which closed the gap without waiting for a replacement programme.
A manufacturer preparing for its first SOX audit.
- Finding
- Access certification ran quarterly with a 99.4% approval rate. Sampling the evidence showed reviewers approving entire lists in a single action within seconds. Separately, 14 identities in the ERP could both create a vendor and approve a payment to it.
- Recommendation
- Restructure certification to present entitlements in business language with a required justification for retention, and remediate the toxic combinations before the audit rather than disclosing them during it.
- Outcome
- Certification redesigned; the following campaign revoked 11% of reviewed access. All 14 segregation of duties conflicts were resolved before the audit window opened.
Next
Scope this assessment
Most scopes are settled in one call. Tell us what the application does and who uses it, and we will tell you what testing it properly involves.