Since initial installation, the BeyondTrust solution has automated the process of correlating all identity-related data into a single view.
Identity Security Insights provided enhanced visibility, enabling the team to understand which of their over 477K accounts and 60K human identities were not under the purview of existing solutions.
During the initial discovery phase, the solution identified critical privilege escalation paths within the client's Azure environment. Multiple applications were configured with excessive API permissions, creating direct escalation paths for Application Administrators to elevate their privileges to Global Administrator roles. These over-privileged app registrations bypassed normal role boundaries and presented significant security risks.
Once Identity Security Insights uncovered this escalation path, the agency’s team was able to remediate it by implementing the principle of least privilege across all application API permissions. The BeyondTrust team worked with the client to audit permissions for each application, removing unnecessary elevated privileges and ensuring Application Admins could no longer leverage these permissions to gain Global Administrator access.
Additionally, the solution revealed the following data on other hidden risk within the agency’s environment:
17,000 compromised passwords that were not considered directly privileged and, therefore, were not subject to controls such as frequent rotation because the accounts were not recognized as highly privileged
31,000 password collisions (multiple accounts with the same password)
9 logins from Tor nodes
124,000 dormant accounts
84 accounts that allowed blank passwords
45 accounts that were vulnerable to Kerberoasting
These discoveries revealed other significant privileged pathways connected to accounts that the agency did not consider as highly-privileged, and therefore weren’t protected as such.
By adding a discovery and visibility dimension to the agency’s overall identity security strategy, Identity Security Insights has enhanced the depth of existing solutions. It has enabled the team to understand the True Privilege™ of every account—including low-privilege accounts with hidden escalation paths. It also offers the team pertinent next steps for improving overall identity hygiene and shrinking the attack surface and enables them to ensure appropriate security controls are applied wherever needed.