What are zero standing privileges?
Zero standing privileges (ZSP) is the end state in which no account in an environment holds administrative rights while it is idle. Privilege exists only inside an approved, time-bounded window, and the account returns to ordinary rights when the window closes.
It is a property of the environment, not a product feature. You reach it through a set of mechanisms, and you verify it by asking a simple question: if an attacker took over any single account right now, what would they immediately be able to do?
What "standing" means
A standing privilege is one that persists without an active request. The common forms:
| Form | Example |
|---|---|
| Group membership | An account permanently in Domain Admins or local Administrators |
| A shared password someone knows | A local administrator password used on every workstation |
| A long-lived key | An SSH key or cloud access key with no expiry |
| A service account with interactive rights | An account that can be used by a person, not only by a service |
| An orphaned account | A departed employee's account still enabled |
Each one is a credential that an attacker can use the moment they obtain it, with no approval step in the way.
How an environment gets there
Zero standing privileges is reached by combining four things, not one.
- Remove standing membership. Accounts come out of privileged groups. This is the step that actually produces the property.
- Grant on request. Just-in-time access replaces the membership with a bounded grant.
- Broker the sessions. The person never handles the credential, so there is nothing to retain. See privileged access management.
- Rotate what remains. Credentials that must exist are changed on a schedule and propagated to everything that depends on them, so a leaked value expires. See password management.
Step one is the one organizations skip, and skipping it means the other three are layered over an environment that is still exposed.
Practical limits
Full zero standing privileges is a goal that very few environments reach completely. Some systems cannot be brokered. Some vendors require a permanent account. Emergency access must exist and must work when the approval path is down.
The question that matters is not "did we reach zero" but "what is the list of remaining standing privileges, who owns each one, and what compensating record exists for it." That list is an auditable artifact. A claim of zero is usually not.
What the kit does
Item
- Discover privileged group membership, password age, SSH keys, and cloud access keys, so the standing-privilege list can be built from evidence rather than memory
- Report how many hosts and services each shared credential reaches, and reduce it by rotating and propagating or by splitting the account per host
- Just-in-time elevation. Windows is the most complete today. Apple Mac and Unix/Linux are expanding.
- Brokered SSH, RDP, and VNC sessions where the credential is never handled by the person
- Account lifecycle and periodic access review for kit accounts. Governance across other applications is planned.
- Privileged-action and session records, with forwarding to a Security Information and Event Management (SIEM) platform
Common questions
Is zero standing privileges achievable?
As a direction, yes. As an absolute, rarely. Treat the remaining exceptions as a maintained list, not as a failure to hide.
Does this break emergency access?
It should not. Design a break-glass path that works when the approval system is unavailable, and make it produce the loudest audit record in the environment.
How is this different from least privilege?
Least privilege is about how much authority an account has. Zero standing privileges is about when it has it. An account can hold minimal rights and still hold them permanently.
Where do service accounts fit?
A service account that only a service uses is a different risk from one a person can log in with. Separate the two, remove interactive rights from the first, and rotate both.
Related pages
- What is just-in-time access
- What is least privilege
- What is privileged access management
- What is password management
- What is identity governance and administration
- Privileged identity management
- Privileged user management
- Privileged access requirements checklist
- Capabilities and pricing
- Glossary