Audit real over-grants - and the privileged controls that only look like defects
Most intrusions are won on identity: a permanent admin, a service account nobody rotates, a credential the vault never saw, a wildcard policy, an approval that approves itself. Each scenario hands you a real access review and asks the two questions that matter: which grants give more than the business intends, and which controls are deliberately privileged and must be left alone. Getting the second one wrong is how a review loses its audience.
A hybrid directory's privileged-account inventory: a daily-use account that is permanently Domain Admin, a service account that logs on interactively, a stale admin from a closed project, a 41-person MFA exemption, and two accounts that look wrong and are exactly right.
A privileged access management deployment reports every credential as vaulted, and the auditor still gets to a server without touching the vault. Find the bypass paths - a shared local admin, a hardcoded credential, a recording the recorded user can pause - and the two controls that are exactly right.
A cloud account with 214 roles and no idea who can do what. Read the policy documents to separate a wildcard grant, a PassRole escalation path and eighteen months of privilege creep from the two roles that are scoped exactly as they should be.
Zero standing privilege on paper, standing privilege in practice. Read the activation logs and role settings to find the self-approving workflow, the 24-hour elevation activated by script, the emergency path nobody reviews, and the one role configured the way all of them should be.