Field notes ยท 2 September 2025

Privilege creep in hybrid directories

How standing groups accumulate rights over years of mergers, projects, and temporary admin grants that never expire.

Privilege creep in hybrid directories

Hybrid directories collect history. Nested groups from a 2016 migration still grant mailbox rights; project security groups from a short-lived ERP cutover still nest under Domain Admins; contractors remain in VPN groups long after their last invoice.

Privilege creep rarely arrives as a dramatic misconfiguration. It arrives as small favours: temporary elevation that becomes permanent, a nested group that seemed harmless, a shared break-glass account whose password is known by half the operations team.

Reviews that only count the number of admin accounts miss the nesting. Effective sampling follows membership chains until a human identity โ€” or a service account with no owner โ€” appears at the end.

Remediation starts with ownership. Until every high-privilege group has a named business and technical owner, cleanup campaigns stall. Owners need a simple question: does this membership still match a current job?

Time-bound elevation and just-enough access programmes work only when the review has already shown where standing access is concentrated. Without that map, new tooling simply automates the same sprawl.