---
title: How to reduce privileged access
description: Highly privileged accounts can cause a lot of damage & do a lot of good.  It is a balancing act between users with too much privileged access..
image: https://blog.empowerid.com/hs-fs/file-18496184-jpg/images/how_to_reduce_privileged_access.jpg
---

[![empowerID-logo](https://blog.empowerid.com/hubfs/empowerID-logo.svg "empowerID-logo")](http://www.empowerid.com)

**![phone](https://blog.empowerid.com/hubfs/images/phone.svg)   1-877-996-4276   **or**  +1 (614) 652-6825**

[![Share on facebook](https://7528309.fs1.hubspotusercontent-na1.net/hub/7528309/hubfs/raw_assets/public/mV0_d-web-default-modules_hubspot/img/facebook-color.png?width=24&name=facebook-color.png) ](https://www.facebook.com/220903377569) [![Share on linkedin](https://7528302.fs1.hubspotusercontent-na1.net/hub/7528302/hubfs/raw_assets/public/mV0_d-web-default-modules_hubspot/img/linkedin-color.png?width=24&name=linkedin-color.png) ](https://www.linkedin.com/company/85780) [![Share on twitter](https://7528304.fs1.hubspotusercontent-na1.net/hub/7528304/hubfs/raw_assets/public/mV0_d-web-default-modules_hubspot/img/twitter-color.png?width=24&name=twitter-color.png) ](https://twitter.com/EmpowerID) [![Share on pinterest](https://7528311.fs1.hubspotusercontent-na1.net/hub/7528311/hubfs/raw_assets/public/mV0_d-web-default-modules_hubspot/img/pinterest-color.png?width=24&name=pinterest-color.png) ](http://www.youtube.com/user/empowerID)

# All-In-One Identity Management and Cloud Security

Emerging technologies are challenging old paradigms and unveiling new ways of approaching the security discipline that enables the right individuals to access the right resources at the right times for the right reasons.

EmpowerID has embedded innovative technologies in every aspect, providing flexible and mature IAM capabilities in the cloud, on premise and in hybrid environments, addressing the mission-critical need across increasingly heterogeneous technology environments, and meeting increasingly rigorous compliance requirements.

# How to reduce privileged access

Posted by [Edward Killeen](https://blog.empowerid.com/blog-1/author/edward-killeen) on Thu, Sep 06, 2012

- [Tweet](https://twitter.com/share)

Highly privileged accounts can cause a lot of damage and do a lot of good.  There is a tricky balancing act between having IT users with too much privilege and not enough.  On one hand, do their job and on the other, perform *mischief* (such as accidentally delete an OU which is a real example).

![how to reduce privileged access](https://blog.empowerid.com/hs-fs/file-18496184-jpg/images/how_to_reduce_privileged_access.jpg)I have seen extremes from one out of business retailer who let every user have access to Active Directory Users & Computers (ADUC) to minimize help desk calls to a very successful international bank who has pretty much shut down ADUC in favor of a granular rights based self service delegation through empowerID.

That second use case is the one I want to talk about.  Not just for ADUC but for all resources that you want to control access through RBAC (role based access control) or ABAC (attribute based access control).  One of my go-to sayings is: "what you can't automate, delegate."

Let's start with Active Directory.  IT needs to create accounts, groups, computers and other objects in AD.  The problem with AD and ADUC is that one size fits all.  The same user who can create a group can also create a user or delete an OU.  You have to shut that thing down. 

With a [delegated Active Directory self service system](http://www.empowerid.com/solutions/aducreplacement), you can have specific roles have access to create, modify or delete only certain AD objects.  You can get granular enough that a user can even manage their direct reports or only certain attributes in their own profile.  And, you can put workflow approvals on any changes made depending on who made the request ([rights based approval routing](http://www.empowerid.com/learningcenter/technologies/rbar)).

What about users wanting to join groups?  Same thing, create a form for users to request access to a group and send it through appropriate approvals.  Depending on the group or user requesting access, maybe even auto-approve it. 

Why even stop there?  Most users are joining groups to have [access to a file or folder](http://www.empowerid.com/products/filesharemanager).  Use a self service page to request access to that resource and have empowerID map what group that user needs to be in.

But that's not the key here.  The key is that when privileged access to a role or group is requested, don't just give it for an eternity.  Temporary privileged access keeps that user from having permanent access to the role or resource.  Put a time limit on the user's privileged access.  Limit the exposure.

Other useful tools is to require multi-factor authentication (MFA) when the user attempts to use the access.  Before you allow it, require them to authenticate with an SMS text to a known device or identity proofing with something that only they will know.

The idea is that privileged access is needed for many users to do their job.  But give them this access only when they need it.  If they have it permanently, ensure it is really them by utilizing MFA upon usage.  Try to shut down any systems with all or nothing access and create an identity policy and system that gives users another more secure route to access.

And, lastly, track this stuff.  If you know when and for how long a user had privileged access and what user or policy granted this access, you have the audit trail to prove that you are keeping your corporate valuables safe and secure.

Take a look at our [whitepaper on replacing ADUC](https://blog.empowerid.com/replacing-ADUC/) and/or [request a demonstration on how to reduce privileged access](https://blog.empowerid.com/scheduledemo/) in your environment.

[![Click me](https://no-cache.hubspot.com/cta/default/174819/78130fd0-f91c-4c09-a06e-d36f46121f11.png)](https://cta-redirect.hubspot.com/cta/redirect/174819/78130fd0-f91c-4c09-a06e-d36f46121f11)

[![Demo & Evaluate EmpowerID](https://no-cache.hubspot.com/cta/default/174819/024476a0-b606-4ba9-ab27-810732373183.png)](https://cta-redirect.hubspot.com/cta/redirect/174819/024476a0-b606-4ba9-ab27-810732373183)

 Tags: [Identity and Access Management (IAM)](https://blog.empowerid.com/blog-1/topic/identity-and-access-management-iam)

### About EmpowerID

EmpowerID is the all-in-one Identity Management and Cloud Security platform designed for people.  Globally managing millions of identities in diverse enterprises, EmpowerID offers comprehensive provisioning, single sign-on and access governance coupled with an industry leading user experience. 

Built on a single codebase for manageability and scalability, EmpowerID ships with a powerful API, a visual workflow designer and over 400 ready-to-use workflows for rapid deployment.

 

[![Free Evaluation of EmpowerID](https://no-cache.hubspot.com/cta/default/174819/daebe087-5275-487d-bf53-bb1d39fb9dc4.png)](https://cta-redirect.hubspot.com/cta/redirect/174819/daebe087-5275-487d-bf53-bb1d39fb9dc4)

### Latest Posts

### Posts by category

- [2-Factor (2)](https://blog.empowerid.com/blog-1/topic/2-factor)
- [Access Governance (36)](https://blog.empowerid.com/blog-1/topic/access-governance)
- [Active Directory (46)](https://blog.empowerid.com/blog-1/topic/active-directory)
- [Attestation (4)](https://blog.empowerid.com/blog-1/topic/attestation)
- [authentication (6)](https://blog.empowerid.com/blog-1/topic/authentication)
- [authorization (2)](https://blog.empowerid.com/blog-1/topic/authorization)
- [azure (1)](https://blog.empowerid.com/blog-1/topic/azure)
- [Azure security (2)](https://blog.empowerid.com/blog-1/topic/azure-security)
- [azuread (1)](https://blog.empowerid.com/blog-1/topic/azuread)
- [Cisco (1)](https://blog.empowerid.com/blog-1/topic/cisco)
- [Citrix (1)](https://blog.empowerid.com/blog-1/topic/citrix)
- [cloud (1)](https://blog.empowerid.com/blog-1/topic/cloud)
- [cloud security (28)](https://blog.empowerid.com/blog-1/topic/cloud-security)
- [consumers (2)](https://blog.empowerid.com/blog-1/topic/consumers)
- [Data Governance (5)](https://blog.empowerid.com/blog-1/topic/data-governance)
- [dataprivacy (1)](https://blog.empowerid.com/blog-1/topic/dataprivacy)
- [DirSync (1)](https://blog.empowerid.com/blog-1/topic/dirsync)
- [eic (1)](https://blog.empowerid.com/blog-1/topic/eic)
- [Federation (6)](https://blog.empowerid.com/blog-1/topic/federation)
- [Gartner (1)](https://blog.empowerid.com/blog-1/topic/gartner)
- [GDPR (2)](https://blog.empowerid.com/blog-1/topic/gdpr)
- [Governance and Regulatory Compliance (4)](https://blog.empowerid.com/blog-1/topic/governance-and-regulatory-compliance)
- [GRC (3)](https://blog.empowerid.com/blog-1/topic/grc)
- [Group Management (12)](https://blog.empowerid.com/blog-1/topic/group-management)
- [IAG (4)](https://blog.empowerid.com/blog-1/topic/iag)
- [IAM (34)](https://blog.empowerid.com/blog-1/topic/iam)
- [IDaaS (1)](https://blog.empowerid.com/blog-1/topic/idaas)
- [Identity and Access Management (IAM) (68)](https://blog.empowerid.com/blog-1/topic/identity-and-access-management-iam)
- [Identity Management (6)](https://blog.empowerid.com/blog-1/topic/identity-management)
- [iga (1)](https://blog.empowerid.com/blog-1/topic/iga)
- [M365 security (1)](https://blog.empowerid.com/blog-1/topic/m365-security)
- [Magic Quadrant (1)](https://blog.empowerid.com/blog-1/topic/magic-quadrant)
- [O365 (1)](https://blog.empowerid.com/blog-1/topic/o365)
- [Office 365 (3)](https://blog.empowerid.com/blog-1/topic/office-365)
- [open policy agent (1)](https://blog.empowerid.com/blog-1/topic/open-policy-agent)
- [Palo Alto (1)](https://blog.empowerid.com/blog-1/topic/palo-alto)
- [Password management (13)](https://blog.empowerid.com/blog-1/topic/password-management)
- [Privacy and EU-US Data Transfers (1)](https://blog.empowerid.com/blog-1/topic/privacy-and-eu-us-data-transfers)
- [Privacy Shield (1)](https://blog.empowerid.com/blog-1/topic/privacy-shield)
- [Radius (1)](https://blog.empowerid.com/blog-1/topic/radius)
- [RBAC (2)](https://blog.empowerid.com/blog-1/topic/rbac)
- [Role Based Access Control (RBAC) (40)](https://blog.empowerid.com/blog-1/topic/role-based-access-control-rbac)
- [SAML (4)](https://blog.empowerid.com/blog-1/topic/saml)
- [Separation of Duties (2)](https://blog.empowerid.com/blog-1/topic/separation-of-duties)
- [SharePoint (8)](https://blog.empowerid.com/blog-1/topic/sharepoint)
- [siemens (1)](https://blog.empowerid.com/blog-1/topic/siemens)
- [Single Sign-on (1)](https://blog.empowerid.com/blog-1/topic/single-sign-on)
- [Single Sign-on (SSO) (26)](https://blog.empowerid.com/blog-1/topic/single-sign-on-sso)
- [social media (1)](https://blog.empowerid.com/blog-1/topic/social-media)
- [SSO (3)](https://blog.empowerid.com/blog-1/topic/sso)
- [User provisioning (28)](https://blog.empowerid.com/blog-1/topic/user-provisioning)
- [VDS (1)](https://blog.empowerid.com/blog-1/topic/vds)
- [Virtual Directory (28)](https://blog.empowerid.com/blog-1/topic/virtual-directory)
- [WS-Fed (2)](https://blog.empowerid.com/blog-1/topic/ws-fed)

### Subscribe via E-mail

Share This Page

[![Share on facebook](https://7528309.fs1.hubspotusercontent-na1.net/hub/7528309/hubfs/raw_assets/public/mV0_d-web-default-modules_hubspot/img/facebook-color.png?width=24&name=facebook-color.png) ](http://www.facebook.com/share.php?u=https%3A%2F%2Fblog.empowerid.com%2Fblog-1%2Fbid%2F215918%2FHow-to-reduce-privileged-access%3Futm_medium%3Dsocial%26utm_source%3Dfacebook) [![Share on linkedin](https://7528302.fs1.hubspotusercontent-na1.net/hub/7528302/hubfs/raw_assets/public/mV0_d-web-default-modules_hubspot/img/linkedin-color.png?width=24&name=linkedin-color.png) ](http://www.linkedin.com/shareArticle?mini=true&url=https%3A%2F%2Fblog.empowerid.com%2Fblog-1%2Fbid%2F215918%2FHow-to-reduce-privileged-access%3Futm_medium%3Dsocial%26utm_source%3Dlinkedin) [![Share on twitter](https://7528304.fs1.hubspotusercontent-na1.net/hub/7528304/hubfs/raw_assets/public/mV0_d-web-default-modules_hubspot/img/twitter-color.png?width=24&name=twitter-color.png) ](https://twitter.com/intent/tweet?original_referer=https%3A%2F%2Fblog.empowerid.com%2Fblog-1%2Fbid%2F215918%2FHow-to-reduce-privileged-access%3Futm_medium%3Dsocial%26utm_source%3Dtwitter&url=https%3A%2F%2Fblog.empowerid.com%2Fblog-1%2Fbid%2F215918%2FHow-to-reduce-privileged-access%3Futm_medium%3Dsocial%26utm_source%3Dtwitter&source=tweetbutton&text=) [![Share on email](https://7528311.fs1.hubspotusercontent-na1.net/hub/7528311/hubfs/raw_assets/public/mV0_d-web-default-modules_hubspot/img/email-color.png?width=24&name=email-color.png) ](mailto:?subject=Check%20out%20https%3A%2F%2Fblog.empowerid.com%2Fblog-1%2Fbid%2F215918%2FHow-to-reduce-privileged-access%3Futm_medium%3Dsocial%26utm_source%3Demail%20&body=Check%20out%20https%3A%2F%2Fblog.empowerid.com%2Fblog-1%2Fbid%2F215918%2FHow-to-reduce-privileged-access%3Futm_medium%3Dsocial%26utm_source%3Demail)

![](https://blog.empowerid.com/hubfs/images/logo-empowerid.svg)

4393 Tuller Road  
Dublin OH

EmpowerID is a registered trademark and  
trade name of The Dot Net Factory, LLC.  
EmpowerID

© 2021 EmpowerID

```json
{
  "@context" : "https://schema.org",
  "@type" : "BlogPosting",
  "author" : {
    "@type" : "Person",
    "name" : "Edward Killeen",
    "url" : "https://blog.empowerid.com/blog-1/author/edward-killeen"
  },
  "datePublished" : "2012-09-06T17:37:00.000Z",
  "headline" : "How to reduce privileged access",
  "image" : [ "https://blog.empowerid.com/hs-fs/file-18496184-jpg/images/how_to_reduce_privileged_access.jpg" ],
  "mainEntityOfPage" : {
    "@id" : "https://blog.empowerid.com/blog-1/bid/215918/How-to-reduce-privileged-access",
    "@type" : "WebPage"
  },
  "publisher" : {
    "@type" : "Organization",
    "logo" : {
      "@type" : "ImageObject",
      "url" : "https://blog.empowerid.com/hubfs/Asset%201.svg"
    },
    "name" : "EmpowerID"
  }
}
```