Skip to content
SecuriFii

Evidence

Privileged access: the control auditors test hardest

Auditors focus here because the list is short enough to test exhaustively and the consequence of a gap is total.

Facts checked2026-09-11

What do auditors test about privileged access?

Who holds administrative access to production, identity systems and the cloud account; whether each of them needs it; whether multi-factor authentication is enforced without exception; whether access is time-bound or standing; and whether privileged actions are logged somewhere the privileged user cannot alter.

The recurring findings are unglamorous: a shared administrative account, a service account with a password in a repository, a former contractor still holding a role, break-glass credentials nobody has rotated since they were created.

The bottom line

Enumerate every account with production or identity administration rights, and justify each one. The list is usually longer than expected.

Related insights