|
The need to know who is delegated what administrative access at any point in time is paramount to operating a secure IT infrastructure.
In most organizations, administrative delegations seldom stay constant because changing business needs, dynamic operational requirements and administrative churn causes them to change more often than expected.
As a result, while numerous IT personnel are delegated varying levels of administrative access in different scopes, at any one point in time, no one really knows who is precisely delegated what administrative access.
This constitutes a security risk as it results in a situation where numerous IT personnel end up in possession of administrative privileges in excess of their authority, constituting a violation of organizational security policies.
Organizations thus absolutely need to assess and manage delegated administrative access grants in Active Directory on a periodic basis.
This section helps IT administrators and managers understand the challenges associated with assessing delegated access in Active Directory and shows them how to accurately assess delegations.
|