Lesson 1 of 4
Identity as the perimeter
Enumerating accounts, factors, exclusions and the machine identities nobody counts.
15 min 3-question quiz 3 guides to read next
Most intrusions now begin with a valid credential rather than an exploit. That makes the directory, not the firewall, the thing to enumerate first.
What to count
Human accounts. Active, dormant, shared, break-glass, and the ones belonging to people who left. Dormant accounts with valid credentials are free entry points.
Privileged accounts. Who holds standing administrative rights, in the directory and in every platform — and whether anyone reviews the list. Count roles granted permanently versus requested when needed.
Machine identities. Service accounts, API keys, personal access tokens, workload identities, certificates. In most organisations these outnumber humans several times over, are older, and are reviewed never.
Authentication methods. Which accounts can authenticate with a password alone, where legacy protocols bypass second factors, and which conditional access policies carry exclusions.
Exclusions are where the risk lives
Every policy has them: a service account that could not do modern authentication, a conference room device, an executive who travels, a legacy application. They are added for a week and stay for years. List every exclusion, name an owner, and give each an expiry date — this single exercise finds more real exposure than most assessments.
The questions worth answering
How many accounts could sign in from anywhere with a password alone? How many keys are older than a year? How many privileged accounts have no second factor? How many accounts belong to people who left, and what is the gap between leaving and losing access?
Each is a number you can produce today and improve next quarter, and together they describe the perimeter far better than a network diagram.
Check your understanding
3 questions · pass with 2 correct
Enrol for free to save your progress, unlock every lesson and earn a certificate.
Sign in to enrolFurther reading
Guides that go deeper on this lesson.
-
Identity as the Attack Surface
When the perimeter is a token, the attack surface is every account, key and consent in the directory.
2 min read
-
Access Control for AI Assistants and RAG
Making sure AI assistants only reveal information each user is allowed to see.
1 min read
-
Attack Surface Discovery: DNS, Certificates and Cloud
Finding the internet-facing things you own, including the ones nobody remembers creating.
2 min read