Alert icon Keyboard navigation enabled.
Alert icon TAB or Shift+TAB to navigate across. Down ↓ to open menu. ESC to close menu.
Alert icon Down ↓ to select section. Right → to activate. Up ↑ / Down ↓ / Tab to traverse all. ESC to exit.
BeyondTrust
Skip to content Use space or enter to skip.

What can we help you find today?

Instant Results
  • Website Results
  • Technical Documentation

Filter Options

Focus your search

Filtering by

Your recent searches:

Contact Us Chat with Sales Get Support
  • English
  • Deutsch
  • français
  • español
  • 한국어
  • português
  • Home
  • Resources
  • Blog
  • Three Overlooked Privileged Access Risks current page
Link copied

Three Overlooked Privileged Access Risks

May 18, 2020
Author:
Morey Haber Headshot 2024
Morey J. Haber
Chief Security Advisor
Blog banner default
Three Overlooked Privileged Access Risks
Morey Haber Headshot 2024
Morey J. Haber
Chief Security Advisor

Most practitioners of Privileged Access Management (PAM) tend to focus on reducing, managing, securing, and auditing the administrator and root accounts that have god-like access to their environment and assets. Some typical focuses include:

  • Managing privileged credentials (rotating passwords, certification based on access, etc.)
  • Removing administrative rights from all endpoints
  • Enforcing least privilege across all users, applications, and processes across Windows, macOS, Unix & Linux, and even network devices
  • Providing secure local and remote session monitoring capabilities (keystroke logging, etc.)
  • Reporting and auditing for privileged activity anytime privileges are invoked

However, there are plenty of other privileged activities that have abstract access within your environment that can cause a world of pain if not properly managed. Many of them are not even identity or account-based. If not properly managed for privileged access, they can actually represent a “game over” event for any organization or individual.

Don’t overlook these three privileged access risks:

  1. “All” email groups – Almost all environments have an “all” email group that allows executives or human resources to mass email all employees within an organization. This is typically used for emailing information that is relevant to all employee, such as next year’s holiday schedule, benefit enrollment information, or even unfortunate events that may affect a large group of people or the entire company.
  2. Human Interface Devices (HID) – While many of the readers may consider a printer as an old-school piece of technology that does not have modern attack vectors, this is far from the truth. Most modern printers and HIDs are “smart”. They can have access via the web, have browser interfaces, and can support multiple protocols for functions like printing and monitoring, including legacy ones like SNMP and FTP.
  3. Vendors – Ask yourself a simple question: What privileged access do your vendors have into your environment, and what privileged access do you have into your suppliers’ environments? Actually, that was a trick question and not a simple one to answer.

“All” email groups

If this “all” group is accessible externally or internally by a threat actor or disgruntled employee, the results can be devasting – for everyone. Think this is far-fetched? Some months back, I had discussions with a CEO whose company did not properly secure the “all” email group, and a threat actor sent illegal photographs to the entire company. Legally, the company did the right thing. They contacted the FBI and scrubbed every mail server, computer, laptop, and mobile phone to remove the images. This one nefarious email sent by a disgusting individual shut the business down for an extended period of time. The lesson learned—secure the “all” email group and any email group that can forward to large groups of people. This is privileged access, just in an untraditional form, within an application. As with any privileged access, it should be managed and locked down.

Human Interface Devices (HID)

Every modern HID has attack vectors, from default credentials to missing access control lists governing who can even access the device. For example, printing to a device located within the human resources or finance departments potentially allows insiders to access any other documents that may be unintentionally left on the printer. Default credentials, even for network management, can provide access to duplicate print jobs to a malicious destination, including storing them on the device’s internal storage for later retrieval via protocols like FTP. Each of these is a form of privileged access to a potentially sensitive device. These devices should be hardened for management and usage. In fact, just as a matter of reference, any device that is being deployed in your environment that is considered “smart” HID, like TVs and projectors, can suffer from similar types of privilege flaws, including monitoring a screen when a meeting may be considered private.

Vendors

Privileged access can actually mean anything from physical access to remote access that a vendor or supplier can have in order to maintain or provide some form of service into your, or their, environment. Many times, these are in the form of accounts that can be managed with an identity governance or privileged access management solution, but, often, organizations create an account in their domain, and then email or text the credentials (including the password) to the third party in order to grant access. The security of this is questionable at best. If you think this not an issue, think again. I personally closed an account in a major software vendor that was created almost 20 years ago and that still allowed me to gain access to license keys and software from my old employer. Access was still granted via my old email address, a compromised weak password, and a vendor and company that did not bother to clean up vendor access—even when employees left the organization. Obviously, the access was not administrative or root, but I did have enough access into material I should not have had. This is a privileged activity and should be managed. Certifying access for your vendors is critical to helping ensure that no inappropriate access occurs.

​Take an Expansive View to Securing Your Universe of Privileges

White chain icon to symbolize the ability to copy a link
Link copied
Check mark to visually show text has been copied

The universe of privileges encompasses much more than administrator and root credentials. It can even apply to abstract concepts, like email groups, human interface devices, and vendor access.

The three privilege risks I detailed above are present in most organizations and need to be properly addressed. If you think you may be at risk, just start asking a few questions. Who has access to large email groups, does everyone have access to a printer or projector, and how do you manage vendor access, especially during employee or vendor turnover and transitions? This simple exercise may lead you down a more comprehensive privilege discovery process, helping you uncover all the places unmanaged privileged access lurks across your organization. With the knowledge of where privilege resides in hand, you can then implement mitigations to close backdoors into your environment and limit lateral passageways between assets—reducing your threat surface and eliminating security weak links.

BeyondTrust has the industry’s most expansive approach to securing privileged access. Via our Privilege Access Management (PAM) solutions, we secure every user, session, and asset across your IT environment. Contact us today to learn more.

Latest Posts
  • The Most Common & Most Dangerous Types of Shadow IT
    Jun 5, 2026 The Most Common & Most Dangerous Types of Shadow IT
    Blog
    19m
  • 14 Password Management Best Practices
    May 28, 2026 14 Password Management Best Practices
    Blog
    12m
  • A Security Researcher’s Guide to Understanding Copilot Studio AI Agents
    May 26, 2026 A Security Researcher’s Guide to Understanding Copilot Studio AI Agents
    Blog
    3m
  • How to Secure Cloud-Native Infrastructure at Scale and Speed: A Conversation with Madhu Adireddi
    May 21, 2026 How to Secure Cloud-Native Infrastructure at Scale and Speed: A Conversation with Madhu Adireddi
    Blog
    5m
  • Cybersecurity as a Boardroom Priority for Major African TelCos
    May 12, 2026 Cybersecurity as a Boardroom Priority for Major African TelCos
    Blog
    8m
Related
  • AI Agent Identity Governance: Why Least Privilege is the Non-Negotiable Security Control
    Mar 23, 2026 AI Agent Identity Governance: Why Least Privilege is the Non-Negotiable Security Control
    Blog
    9m
  • BeyondTrust Expands Cloud Leadership with Password Safe v7.2
    Oct 7, 2020 BeyondTrust Expands Cloud Leadership with Password Safe v7.2
    Blog
    1m
Share this Article
  • Link
Tags
  • Admin Rights
  • Administrative Rights
  • Least Privilege
  • PAM
  • Privileged Access
  • Privileged Access Management
  • Privileged Access Management (PAM)
  • Privileged Credentials
  • Risks Mitigation
  • Root Access
Stay up to Date
Get the latest news, ideas, and tactics from BeyondTrust. You may unsubscribe at any time.

Keep up with BeyondTrust

Customer Support Get Started
  • LinkedIn
  • X
  • Facebook
  • Instagram
  • Add BeyondTrust as a preferred source on Google
  • Privacy
  • Security
  • Manage Cookies
  • Do Not Sell My Data
  • WEEE Compliance

Copyright © 2003 — 2026 BeyondTrust Corporation. All rights reserved. Other trademarks identified on this page are owned by their respective owners. BeyondTrust Corporation is not a chartered bank or trust company, or depository institution. It is not authorized to accept deposits or trust accounts and is not licensed or regulated by any state or federal banking authority.

Prefers reduced motion setting detected. Animations will now be reduced as a result.