惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

Microsoft Azure Blog
Microsoft Azure Blog
WordPress大学
WordPress大学
让小产品的独立变现更简单 - ezindie.com
让小产品的独立变现更简单 - ezindie.com
The Cloudflare Blog
U
Unit 42
D
Docker
Hugging Face - Blog
Hugging Face - Blog
博客园 - 聂微东
Recent Announcements
Recent Announcements
GbyAI
GbyAI
T
The Blog of Author Tim Ferriss
Last Week in AI
Last Week in AI
V
Visual Studio Blog
I
InfoQ
Google DeepMind News
Google DeepMind News
小众软件
小众软件
L
LangChain Blog
C
Check Point Blog
宝玉的分享
宝玉的分享
Martin Fowler
Martin Fowler
酷 壳 – CoolShell
酷 壳 – CoolShell
博客园 - 【当耐特】
J
Java Code Geeks
罗磊的独立博客

Forbes - Innovation

Why Do Humans Have Fingerprints? Hint: It’s Not What You Think Booking.com Confirms Data Breach, Reservation PIN Codes Changed Why Major News Sites Are Blocking The Internet Archive’s Wayback Machine iPhone Fold Release Date: New Report Details Frustrating Apple News Comet Tracker: How To See Pan-STARRS And Three Planets On Wednesday NYT Mini Crossword Today: Tuesday, April 14 Hints And Answers Today’s NYT Strands Hints, Spangram, Answers: Tuesday, April 14 (It’s A Little Unclear) Today’s Wordle #1760 Hints And Answer For Tuesday, April 14 Most Of The Microplastics In Urban Air Come From Tires Today’s Wordle #1759 Hints And Answer For Monday, April 13 NYT Mini Crossword Today: Monday, April 13 Hints And Answers NYT Pips Today: Hints, Answers And Walkthrough For Monday, April 13 The YC Chief Who Codes 10,000 Lines A Day Has A Simple Secret Samsung Expands One UI 8.5 Beta To More Galaxy Owners Why You Should Stop Using Your iPhone If It’s On This List Chamath Says Firms That Treat AI As A Strategy Hand Rivals Their Edge 3 Unexpected Habits Of Secure Couples, By A Psychologist The First Lamp That Folds Your Clothes Samsung’s Disappointing Price Update For Galaxy Phone Buyers 3 Subtle Signs Someone Is Falling In Love With You, By A Psychologist Do Mantis Shrimp See More Colors Than Humans? A Biologist Explains NYT Connections Answers Explained For Monday, April 13 (#1,037) NYT Connections Hints Today: Monday, April 13 Clues And Answers (#1,037) LEGO Luigi & Mach 8 (72050) Review: 2026’s Best Set Yet? Marc Andreessen Says AI Productivity Will Trigger A Hiring Boom 3D Printing Is The Ultimate Hack To Reduce Household Spending Apple iPhone Fold: Striking Design Revealed In Leaked Photos Apple Smart Glasses: New Leak Reveals A Major Design Twist To Beat Meta Tested: The AI Coming To The Rivian R2 Quordle Hints Today: Monday, April 13 Clues And Answers
The Hidden Risk In Access Management: How Identity Sprawl...
Praerit Garg · 2026-05-11 · via Forbes - Innovation

Praerit Garg, CEO, One Identity, trusted leader in identity security, helping enterprises protect and simplify access to digital identities.

getty

Most executives I’ve spoken with in recent months believe that access management is largely under control. Employees are given access to the systems they need when they join, with permissions typically granted based on their role, and then accounts are disabled when those employees move on to pastures new. On paper, the process appears orderly and well governed, and that inspires confidence.

However, that confidence is often misplaced and tends to fall apart when organizations are asked to take a closer look at how they manage identity and access. According to the Ponemon Institute, only 44% of organizations said they were “highly confident” in their ability to prevent identity-based security incidents, suggesting many companies still struggle to maintain comprehensive visibility when it comes to access management. In a 2025 report, Microsoft revealed that 66% of attack pathways involve compromised credentials or accounts, underscoring the importance of air-tight identity and access management (IAM).

When it comes to access management, the risk rarely sits at the beginning or end of the employee life cycle. It sits right in the middle, where day-to-day work actually happens. Modern organizations are fluid environments where people move between teams, take on new responsibilities, participate in temporary initiatives and interact with a mushrooming ecosystem of applications and services. Each change often requires new access, and those permissions tend to accumulate over time.

What happens far less frequently is the systematic removal of access that is no longer needed. As a result, many employees gradually carry far more privilege than their current role requires, often without even realizing it. So, at a time when identity has become the primary gateway to enterprise systems, the quiet accumulation of access can create an attack surface that few organizations are actively monitoring.

And that’s a breach waiting to happen.

The Insidious Nature Of Access Sprawl

It’s not like a business gets going one morning and realizes they have an identity sprawl problem. It develops gradually as employees move through the natural rhythm of their careers inside an organization. Someone joins a project team and receives access to a new application. Later, they transfer to another role but retain the permissions from the previous one. A new system is deployed, and access is granted broadly so teams can get started quickly. Months or years later, those same permissions remain, even though the work that required them has long since been completed.

It’s important to note that none of this typically happens because of negligence or bad intent. It happens because organizations are complex and fast-moving. Granting access is easy, but removing it requires time, coordination and visibility that many teams don’t have.

One of the reasons access sprawl is so difficult to fix is that it’s often a conscious trade-off rather than a simple oversight. I recently spoke with a CEO who described how access is rarely revoked cleanly when employees get promoted or switch roles. Managers frequently request extended permissions during “transition periods” to avoid disrupting work, but those temporary measures often become permanent.

This reflects our temptation in access management toward low friction, but in reality, some friction is essential. Without it, there is no reliable way to validate whether access is still needed. As AI agents begin to act on behalf of users, often at speeds and scales that humans can’t match, the situation becomes even more critical. There have already been instances where AI agents have deleted entire calendars, folders or batches of emails—not because of any maliciousness from a third party, but because too much leeway was given to the technology.

When Overprovisioned Access Becomes A Serious Security Risk

It’s easy to frame overprivileged access as “unused access,” and in that context it seems fairly harmless. If an employee is no longer interacting with a particular system or account, there doesn’t appear to be any urgent risk. But these “unused permissions” can actually be the biggest vulnerability inside an organization today.

When an account is compromised through phishing, credential theft or session hijacking, attackers inherit whatever access that identity already holds, and if privileges have accumulated over time, the attacker suddenly gains a much wider path through the environment than anybody realizes. In effect, every unnecessary permission increases the blast radius of a breach.

That risk is even more pronounced as cybersecurity has shifted away from defending a single network perimeter. With cloud platforms, SaaS applications, APIs, mobile devices and distributed workforces, the traditional concept of a corporate network with clearly defined boundaries has disappeared. Access is now governed through identity and credentials rather than physical or network location, so privileged accounts have become one of the most valuable entry points for attackers. When identities become the control plane for modern infrastructure, overprovisioned access translates to a direct security vulnerability.

Reining In The Sprawl​​

One of the most effective ways to remedy this problem is to treat access as something that must be continuously validated rather than periodically checked. Organizations need visibility into who—or what—has access to services across their environment, and whether that access is actually being used.

While AI is contributing to this challenge, it’s also part of the solution. It can continuously monitor usage patterns, identify dormant permissions and flag access that no longer aligns with business needs. In many cases, simply identifying unused access can significantly reduce the potential impact of a compromised account.

The challenge, as the CEO referenced above confirmed to me, is that access is often left in place out of caution rather than necessity. Teams hesitate to remove permissions for fear of breaking workflows or disrupting productivity. But in practice, access that has not been used for an extended period of time is rarely critical, and revoking that access shouldn’t be seen as a risk.

If access is genuinely required, it can be requested again. That kind of “friction” isn’t a failure of the system, and with the right access management tools in place, it can feel like just another part of any seamless workflow.​


Forbes Technology Council is an invitation-only community for world-class CIOs, CTOs and technology executives. Do I qualify?