Skip to content
Artwork for The Backup Wrap-Up
The Backup Wrap-Up · Monday · 39 min

Least Privilege Best Practices: Where to Start

Least privilege best practices start with one uncomfortable question: does this person actually need this access? A hospital in Portugal answered yes for everybody, gave every employee doctor-level access to patient records, and got hit with a 400,000 euro GDPR fine. The court's read was that they hadn't even attempted the concept. Mike Saylor, Prasanna, and I get into what least privilege really means, then move straight to the part nobody wants to talk about: where you start when everybody already has domain admin. Mike lays out three approaches, from "turn everything off and see who screams" to a real analysis of job roles. We talk about why role-based administration is the vehicle that gets you there, and why role sprawl will eat you alive if you build a custom role for every human in the building. From there we get into segregation of duties, which accounting figured out decades before IT did. Your admin account should not be the account you use to check Gmail. That leads into non-repudiation, su versus sudo, and why logs have to leave the box and land in a SIEM before somebody edits them. The last third is action items. Inventory your privileged accounts, your service accounts, your support accounts, and the fire call accounts you break glass for. Track more than the name and the privilege level: who owns it, why it exists, when the password changed, when it expires. And if you run backups, split your roles apart. Editing backup configs, running backups, and doing restores should not be the same permission. Somebody quietly shortening retention is invisible to the person watching last night's job reports. A restore never trips an alarm at all. If your admins fight you on any of this, Mike has a thought about that too. 00:00 The hospital where the janitor could read your chart 04:26 The 400,000 euro fine, and the failed appeal 07:50 What least privilege actually means 08:54 Three ways to start when everyone has too much 11:17 Access that follows people as jobs change 12:57 Role-based administration is the vehicle 16:13 Role sprawl and the 80/20 rule 18:26 Segregation of duties, borrowed from accounting 20:28 Back when everybody had root: su and sudo 21:59 Non-repudiation and getting logs into a SIEM 25:31 Inventory privileged, service, and fire call accounts 27:41 The three backup roles you should separate 32:39 What your account inventory should track 35:31 Expiring accounts nobody uses 36:42 When admins push back, be concerned

0:00-39:00

transcript

No transcript — this publisher did not publish one.

show notes

Least privilege best practices start with one uncomfortable question: does this person actually need this access? A hospital in Portugal answered yes for everybody, gave every employee doctor-level access to patient records, and got hit with a 400,000 euro GDPR fine. The court's read was that they hadn't even attempted the concept.

Mike Saylor, Prasanna, and I get into what least privilege really means, then move straight to the part nobody wants to talk about: where you start when everybody already has domain admin. Mike lays out three approaches, from "turn everything off and see who screams" to a real analysis of job roles. We talk about why role-based administration is the vehicle that gets you there, and why role sprawl will eat you alive if you build a custom role for every human in the building.

From there we get into segregation of duties, which accounting figured out decades before IT did. Your admin account should not be the account you use to check Gmail. That leads into non-repudiation, su versus sudo, and why logs have to leave the box and land in a SIEM before somebody edits them.

The last third is action items. Inventory your privileged accounts, your service accounts, your support accounts, and the fire call accounts you break glass for. Track more than the name and the privilege level: who owns it, why it exists, when the password changed, when it expires. And if you run backups, split your roles apart. Editing backup configs, running backups, and doing restores should not be the same permission. Somebody quietly shortening retention is invisible to the person watching last night's job reports. A restore never trips an alarm at all.

If your admins fight you on any of this, Mike has a thought about that too.

00:00 The hospital where the janitor could read your chart

04:26 The 400,000 euro fine, and the failed appeal

07:50 What least privilege actually means

08:54 Three ways to start when everyone has too much

11:17 Access that follows people as jobs change

12:57 Role-based administration is the vehicle

16:13 Role sprawl and the 80/20 rule

18:26 Segregation of duties, borrowed from accounting

20:28 Back when everybody had root: su and sudo

21:59 Non-repudiation and getting logs into a SIEM

25:31 Inventory privileged, service, and fire call accounts

27:41 The three backup roles you should separate

32:39 What your account inventory should track

35:31 Expiring accounts nobody uses

36:42 When admins push back, be concerned