EXECUTIVE BRIEF
Identity risk is a business-control problem, not just an account problem.
The scenario begins with a bank facing excessive privilege, weak authentication, stale access, unmanaged guests, direct role assignments, credential risk, poor logging and absent ownership. The objective is to consolidate evidence, determine which weaknesses create the greatest exposure and propose a practical target state.
CURRENT-STATE ASSESSMENT
Start with what exists, who owns it and what cannot yet be proven.
The assessment consolidates the identity inventory, baseline controls, existing evidence and gaps. Risks are evaluated through likelihood, impact, control weakness, accountable owner and proposed treatment.
Users, privileged roles, guests, groups, service principals and workload identities.
MFA coverage, Conditional Access, exceptions and legacy authentication exposure.
Standing privilege, direct assignments, role scope and just-in-time opportunities.
Access lifecycle, attestations, guest reviews, logging and evidence accountability.
PRIORITY RISKS
Prioritise the control failures that can compound.
- Excessive privilege: broad or standing access increases blast radius after compromise.
- Weak authentication: inconsistent MFA or weak policy coverage increases account takeover risk.
- Stale access: inactive users and outdated entitlements undermine least privilege.
- Unmanaged guests: external identities without owners or review cycles create persistent access paths.
- Direct assignments: access granted outside governed group structures makes review and removal harder.
- Poor evidence: control effectiveness cannot be defended when ownership, logging and attestation are absent.
TARGET DESIGN
Move from permanent access to governed, contextual access.
The target state uses group-based RBAC, stronger authentication, Conditional Access, Privileged Identity Management, recurring access reviews, better workload identity practices and clear evidence ownership.
Reduce direct role assignment and make entitlement management more reviewable.
Protect sign-ins with policy based on user, device, risk and application context.
Replace unnecessary standing administrative access with eligible, time-bound activation.
Require owners to periodically confirm whether access is still justified.
IMPLEMENTATION ROADMAP
Sequence remediation so high-risk access is controlled first.
The roadmap begins with inventory and emergency privilege controls, then strengthens authentication, restructures assignments, introduces access reviews and PIM, improves logging, formalises ownership and moves towards measurable identity governance.
ETHICAL PORTFOLIO PRESENTATION
Demonstrate capability without inventing employment history.
Every screenshot, artefact and interview explanation connected to this project should retain the fictional-project disclosure. The value is in showing how the assessment was performed, what decisions were made, what was produced and what was learned.