Privilege creep in hybrid directories
How standing groups accumulate rights over years of mergers, projects, and temporary admin grants that never expire.
Hybrid directories collect history. Nested groups from a 2016 migration still grant mailbox rights; project security groups from a short-lived ERP cutover still nest under Domain Admins; contractors remain in VPN groups long after their last invoice.
Privilege creep rarely arrives as a dramatic misconfiguration. It arrives as small favours: temporary elevation that becomes permanent, a nested group that seemed harmless, a shared break-glass account whose password is known by half the operations team.
Reviews that only count the number of admin accounts miss the nesting. Effective sampling follows membership chains until a human identity โ or a service account with no owner โ appears at the end.
Remediation starts with ownership. Until every high-privilege group has a named business and technical owner, cleanup campaigns stall. Owners need a simple question: does this membership still match a current job?
Time-bound elevation and just-enough access programmes work only when the review has already shown where standing access is concentrated. Without that map, new tooling simply automates the same sprawl.