Rethinking Privileged Access: RBAC and JIT that works for humans and machines
Details
Azure gives teams strong building blocks for privileged access. Azure RBAC defines what an identity can do and where it can do it, and Entra PIM has made just-in-time activation standard practice for human admins.
The hard part comes at scale. Role assignments pile up across subscriptions, broad roles get granted because they're the fastest way to unblock someone, and most identities end up holding privileged permissions they never use. Fixing it is daunting - what permissions can and can't be safely removed without breaking anything is unclear.
Meanwhile, most of the growth in a typical tenant isn't people. Service principals, managed identities, CI/CD pipelines, and AI agents often carry the most privilege, and they can't open a portal and ask for elevation when they need it.
This session looks at privileged access from the permission side instead of the identity side. We'll cover how to use activity data to find unused RBAC assignments and right-size over-privileged roles without breaking workloads. We'll also show how to extend JIT to machine identities by treating the attempted action itself as the access request. You'll leave with a practical way to get to zero standing privilege in Azure, one your developers won't push back on.
Speaker: Sandy Bird, Co-founder & CTO, Sonrai Security
PARKING: For free parking please park across the street on the third and fourth floors of the parking garage at 12711 Queensbury; parking in the Microsoft building is not free.
In-person: 750 Town and Country Blvd #1000 · Houston, TX
Recording: https://www.youtube.com/@HoustonAzureUserGroup
