Wealth management

Standing admin rights turn one phished employee into a full breach

In May, Microsoft published the breakdown of a breach that didn't involve a single piece of malware.

1 min readOriginally posted on LinkedIn

In May, Microsoft published the breakdown of a breach that didn't involve a single piece of malware.

The attacker called employees pretending to be internal IT support, talked them into approving an MFA prompt, then used the self-service password reset to take over the account and strip out the old sign-in methods. From there it moved fast: those accounts happened to carry standing administrator rights, and the attacker pulled dozens of stored credentials out of the company's vault in four minutes.

Four minutes. Not four days.

Here's why that matters for a 20-person wealth management firm. Nothing in that attack was clever. It worked because ordinary day-to-day accounts were carrying admin privileges around permanently — the equivalent of everyone on staff walking around with the master key on their keyring. The moment one person gets fooled, whoever fooled them inherits every door that key opens.

Admin rights should be something you check out when you need them and hand back when you're done, on a separate account that never touches email. Most firms I look at have three or four permanent global admins, and nobody can remember approving two of them.

Pull your admin list this week. If the names surprise you, that's your finding.

Worth doing before your next cyber renewal, not after.

ShareLinkedInEmail

Want the next one in your inbox?

One practical Microsoft 365, Copilot, Azure, or security move per week — plain English, no pitch.

Subscribe via email

All editions