Skip to content

Identity as the Attack Surface

When the perimeter is a token, the attack surface is every account, key and consent in the directory.

Editorial team 2 min read

Network boundaries matter less each year; identity has absorbed their role. The practical consequence is that the attack surface includes every credential, token, key and grant that can authenticate.

What to enumerate

Accounts. Human, service, break-glass, legacy, and those belonging to people who left. Count the ones with privileged roles, and the ones that have never been used.

Authentication methods. Which accounts can sign in with a password alone, where legacy protocols bypass multi-factor, and which conditional access policies have exclusions — exclusions are where the real risk lives.

Keys and tokens. Long-lived API keys, personal access tokens, service account keys and their age. A ten-year-old key with broad scope is a perimeter nobody is watching.

Consents and grants. OAuth applications granted access to mail and files, and who approved them. Malicious consent is a quiet, effective route into a tenant.

Federation and trust. Trusts between directories, external collaboration settings and anything that lets another organisation's identity assert itself in yours.

Reducing it

Short-lived credentials wherever possible, privileged access that is requested rather than held, strong factors everywhere with the exclusions reviewed monthly, and a joiner-mover-leaver process that actually removes access on the leaving date.

Then test it: given a single compromised standard account, map every path to privilege. That map is your real attack surface, and it is usually shorter than anybody expects.

More in Cyber security

All Cyber security guides →
Cyber security Guide · 2 min

What a Penetration Test Is, and Is Not

A penetration test is a time-boxed, authorised attempt to reach a defined objective — not a full inventory of every weakness you have.

Cyber security 2 min read 25 May 2025

Cyber security Guide · 2 min

Rules of Engagement and Authorisation

What to agree before any testing starts: scope, timing, data handling, escalation and the single document that makes the work lawful.

Cyber security 2 min read 24 May 2025

Cyber security Guide · 2 min

Writing a Finding People Will Fix

Severity, evidence, reproduction, impact in business terms, and a fix the team can actually make.

Cyber security 2 min read 23 May 2025

Cyber security Guide · 2 min

Vulnerability Scanning Done Properly

Credentialed scans, asset coverage, tuning out noise, and why scan counts are a bad metric.

Cyber security 2 min read 22 May 2025