Start with dormant-account cleanup when the estate contains large numbers of stale identities, because unused accounts are easier to revoke quickly and often expose the fastest attack opportunities. Then move to privilege-path review for nested groups and inherited admin rights so the remaining access model can be certified accurately.
Why dormant-account cleanup comes first in most estates
Dormant-account cleanup usually delivers the quickest risk reduction because stale accounts are easy to find, easy to justify for revocation, and often represent the fastest route an attacker can exploit. If an account has no current business owner, no active use, or no recent authentication history, the control decision is normally straightforward: disable, remove, or force revalidation before spending time on deeper path analysis.
This is especially true where the environment has accumulated legacy VPN users, orphaned contractors, test accounts, or accounts left behind after role changes. A clean-up pass reduces the number of exploitable entry points and gives you a smaller, more credible identity baseline before you inspect inherited rights and nested group structures.
When privilege-path review should take priority instead
Privilege-path review becomes the first move when the estate is already well maintained but the access model is complex. Nested groups, inherited administrator rights, delegated role chains, and cross-domain trust can hide effective privilege even when the named account list looks tidy. In that case, the main issue is not account age, it is whether an apparently ordinary account can reach sensitive systems through a hidden path.
The practical reason to review privilege path early is that these relationships can create broad blast radius without looking unusual in a standard recertification report. A user can appear low risk on paper while still inheriting rights that let them manage workloads, reset credentials, or reach sensitive admin interfaces.
How to sequence both without wasting effort
The best sequence is usually cleanup first, then path review, because the first pass removes obvious noise and lowers the amount of access you need to analyse. Once dormant identities are removed, the remaining population is more meaningful, and privilege certification becomes more accurate.
After that, focus on the access chains that matter most: admin inheritance, group nesting, cross-environment rights, break-glass exposure, and any role that combines broad reach with weak ownership. That is where dormant-account cleanup and privilege-path review intersect with least privilege, access review, and PAM practice, so the work should be staged rather than treated as a single undifferentiated backlog.
Risk and Threat Considerations
Stale accounts and hidden privilege paths are different failure modes, but both can create easy attacker opportunities. Dormant identities are attractive because they are often overlooked, while privilege inheritance is dangerous because it can turn an ordinary account into an effective administrative foothold.
Failure mechanism: Unused accounts persist with valid authentication material, or active accounts inherit rights through group nesting and delegated administration, allowing a compromise to bypass the expected access model.
Impact: Attackers gain a low-friction entry point or a wider lateral-movement path, and defenders lose confidence that their certification output reflects actual privilege.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
OWASP Non-Human Identity Top 10 addresses the attack and risk surface, while NIST SP 800-53 Rev 5 sets the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| NIST SP 800-53 Rev 5 | AC-2 — Account Management | Dormant-account cleanup directly depends on account lifecycle governance and revocation. |
| AC-6 — Least Privilege | Privilege-path review is about reducing inherited and excessive effective access. | |
| IA-5 — Authenticator Management | Dormant accounts often retain usable credentials that must be rotated or revoked. | |
| Recommendation — Disable or remove inactive accounts on a defined review cadence. Restrict effective permissions to the minimum needed for each role. Expire, rotate, or revoke authenticators tied to stale identities. | ||
| OWASP Non-Human Identity Top 10 | NHI-01 — Improper Offboarding | Dormant-account cleanup addresses identities left behind after role or ownership changes. |
| NHI-05 — Overprivileged NHI | Privilege-path review targets excessive effective access and inherited admin rights. | |
| NHI-07 — Long-Lived Secrets | Dormant accounts often persist because their secrets remain valid too long. | |
| Recommendation — Remove access promptly when an identity is no longer needed. Right-size effective privileges and eliminate unnecessary inheritance. Set short credential lifetimes and enforce timely rotation. | ||
Practitioner Guidance
What to prioritise: Start with the cleanup queue that has the clearest revocation signal, such as accounts with no owner, no recent use, or no justified business purpose. That is the fastest way to shrink exposure before you spend time untangling inherited entitlements.
What to verify: For the privilege-path review, verify effective permissions rather than just named group membership. Nested groups, transitive membership, and inherited admin rights are where the false sense of safety usually appears, especially in IAM and IGA Basics style review workflows.
What good looks like: dormant account are removed or revalidated on a fixed cadence, privilege paths are mapped to actual effective access, and the remaining high-risk accounts are visible enough to support Privileged Access Management Guide controls and periodic certification.
Practitioner takeaway: Clean up what is obviously dead first, then certify what is still alive, because revoking stale access reduces immediate exposure while path review prevents you from underestimating the real privilege model.
Related resources from NHI Mgmt Group
- Should organisations prioritise external exposure or internal credential governance first?
- Should organisations prioritise AI agent settings or service account cleanup first?
- Should organisations prioritise secret rotation or access review first
- Should organisations prioritise Zero Trust or least privilege first for NHI risk?