By NHI Mgmt Group Editorial TeamDomain: Best PracticesSource: P0 SecurityPublished July 28, 2026

TL;DR: Windows RDP still often relies on shared admin accounts and static credentials, while P0 Security’s video shows a time-bound access model tied to corporate identity with approval history, session recording and real-time revocation. The practical issue is not remote access itself but whether runtime control, auditability and zero standing privilege can keep pace with agents, users and machines.


At a glance

What this is: This is a video walkthrough of just-in-time RDP access that highlights the shift from shared, standing admin access to time-bound access with revocation and audit context.

Why it matters: It matters because IAM and PAM teams need runtime controls that cover humans, machines and AI agents without leaving persistent credentials behind.

👉 Watch P0 Security's video on just-in-time RDP access and runtime control


Context

Windows RDP remains a problem when it is built around shared admin accounts and static credentials, because the access path outlives the task that justified it. In practice, that creates a governance gap between who can connect and who should still be able to connect after the work is done.

The article frames just-in-time RDP as a runtime access control problem, not a remote desktop feature problem. For IAM and PAM programmes, the question is whether access is tied to real identity, time boxed, recorded and revoked before it becomes standing privilege again.


Key questions

Q: What breaks when Windows RDP still depends on shared admin accounts?

A: Shared admin accounts break accountability and make access reviews almost useless, because no one can reliably prove who used the session or why. They also extend the life of privilege beyond the task that needed it, which turns remote access into standing access. The control failure is not remote desktop itself, but the absence of named ownership and time-bounded entitlement.

Q: Why do static credentials create more risk than short-lived access tokens?

A: Static credentials create more risk because they remain valid until someone finds and removes them, which gives attackers a durable entry path. Short-lived tokens reduce exposure time, but they still need scope limits and revocation. The real control is the combination of short lifetime, least privilege, and continuous review.

Q: What are the signs that RDP access controls are not working as intended?

A: Warning signs include repeated failed logins, simultaneous access from different locations, unexpected session counts, and access attempts from machines outside the expected network boundary. These patterns suggest brute force activity, shared credentials, or weak session governance. Security teams should monitor for those anomalies and be ready to lock sessions, block users, or force immediate review.

Q: How should teams govern just-in-time access across users, machines and AI agents?

A: Treat just-in-time access as a runtime governance pattern, not a human-only convenience. Define who or what can request access, require proof of identity at issuance, record the approval chain and make revocation available while the session is still active. The same rules should apply whether the actor is a person, a workload or an AI agent.


Technical breakdown

Just-in-time RDP and the end of standing admin access

Just-in-time RDP issues access only for the duration of a task, then removes the ability to reconnect without a fresh approval or policy decision. That changes RDP from a persistent channel into an ephemeral entitlement tied to identity, time and recorded justification. The control value is not the remote desktop itself, but the way the session is constrained, observed and revoked. This matters most where shared admin accounts used to blur ownership and make after-the-fact reconciliation the only control.

Practical implication: replace persistent RDP entitlements with time-bound issuance and revocation tied to named identities.

Approval history, session recording and audit-ready access evidence

Approval history and session recording turn privileged access from a black box into an evidentiary trail. Approval history shows who authorised the session and why, while session recording captures what happened during the access window. Together, they address the audit gap created when privileged access is granted outside normal ticketing or change control. In PAM terms, this is less about approving access and more about proving that access was justified, bounded and reviewable after the fact.

Practical implication: require every elevated RDP session to produce an immutable approval and session record.

Runtime revocation across users, machines and AI agents

Runtime revocation is the enforcement point that matters once access is no longer static. In environments that now include users, machines and AI agents, the access decision has to remain revocable while the session is active, not only after it ends. That is a different model from traditional credential cleanup, which assumes a stable account lifecycle and a human-paced review cycle. The governance challenge is preserving control across the full action chain, especially when non-human actors can move faster than manual review.

Practical implication: design revocation so it can interrupt active access across human, machine and agent sessions.


Threat narrative

Attacker objective: The objective is to retain durable remote access that outlives the operational need for it, increasing the chance of misuse or unauthorized reuse.

  1. Entry occurs through shared admin accounts or long-lived remote access credentials that let a user or actor connect to Windows RDP without task-scoped limits.
  2. Credential abuse follows when those static credentials are reused across sessions, making it difficult to separate legitimate access from persistent privilege.
  3. Impact is the accumulation of cleanup, audit pain and uncontrolled access exposure, especially when auditors arrive after the fact and the original justification is no longer visible.
  • Azure Key Vault Contributor escalation 2024: Datadog found Azure Key Vault Contributor could add itself to access policies and read every secret, key and certificate in a vault.
  • BeyondTrust breach 2024: A stolen BeyondTrust Remote Support API key let a China state-sponsored actor reset accounts and reach US Treasury workstations in 2024.

Read our 52 NHI Breaches Analysis report for a comprehensive view of breaches impacting Non-Human Identities including AI Agents.


NHI Mgmt Group analysis

Standing RDP access is the wrong default for runtime work. The article reinforces a simple point: if remote access is not time boxed, it becomes governance debt. Shared admin accounts and static credentials turn every later audit into a reconstruction exercise instead of a control check, so the core programme question is whether access can expire as quickly as the task that created it.

Runtime access control is now a cross-domain identity problem, not just a PAM problem. The vendor’s framing includes agents, users and machines, which is the right way to think about modern access paths. When AI agents and workloads can touch the same sensitive systems as humans, the access model has to govern action chains, not just accounts, otherwise entitlement boundaries collapse under operational speed.

Approval without revocation is incomplete control. This article highlights that evidence of permission is not the same as evidence of containment. Approval history and recording matter, but they only close the loop if revocation is built into the same runtime flow, otherwise the organisation creates a signed record of an access decision it still cannot reliably unwind.

Zero standing privilege is the decisive operating assumption for modern privileged access. Persistent privilege was designed for a slower, more human access model. That assumption fails when access is invoked dynamically by humans, machines or agents, because the actor may need privilege only for a short runtime window. The implication is that governance has to move from periodic review to issuance-time control.

From our research library:

What this signals

Zero standing privilege: the real issue is not whether RDP can be opened safely, but whether access can be made to disappear as soon as the task ends. That shifts the governance burden from periodic review to issuance-time control, which is the only point where standing privilege can be prevented rather than discovered later.

Runtime access governance now has to cover humans, machines and agents together, because the same session patterns can be consumed by all three. Teams that still design PAM around human operators will miss the speed and autonomy of non-human access paths, and their review cycles will trail the actual privilege window.

Access recording and revocation are no longer separate hygiene steps. They form the minimum evidence chain for proving that privileged work was both authorised and contained, and without both, audit readiness becomes a documentary exercise rather than an access-control outcome.


For practitioners

  • Audit shared RDP paths for standing privilege Inventory every Windows RDP path that still depends on shared admin accounts or long-lived credentials, then classify which ones can be converted to time-bound access.
  • Tie privileged sessions to named corporate identity Require each RDP session to resolve to a real corporate identity with explicit approval history before access is granted.
  • Enable session recording for privileged access Capture privileged RDP sessions so every administrative action has reviewable context for audit and incident reconstruction.
  • Build runtime revocation into access workflows Ensure access can be revoked while the session is active, not only during post-session cleanup or certificate expiry.
  • Extend PAM governance to machines and agents Apply the same issuance, recording and revocation logic to non-human actors that reach sensitive systems through RDP or adjacent control paths.

Key takeaways

  • Windows RDP built on shared admin accounts and static credentials still leaves organisations with standing privilege, weak attribution and after-the-fact cleanup.
  • The article’s runtime access model matters because it binds access to real identity, approval history, session recording and immediate revocation.
  • PAM and IAM teams need to govern privileged access as a live control problem across users, machines and agents, not as a post-session audit problem.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

OWASP Non-Human Identity Top 10 and MITRE ATT&CK address the attack and risk surface, while NIST SP 800-53 Rev 5 and NIST CSF 2.0 set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
OWASP Non-Human Identity Top 10NHI-01 — Improper OffboardingTime-bound RDP access depends on revocation after use, which is the core offboarding problem here.
NHI-05 — Overprivileged NHIShared admin RDP paths and standing access create excessive privilege for non-human and human actors alike.
NHI-07 — Long-Lived SecretsStatic credentials are the enabling condition behind persistent RDP access in the article.
Recommendation — Apply NHI-01 to revoke RDP entitlements as soon as the task ends. Use NHI-05 to remove persistent RDP privilege and scope sessions to the task. Treat long-lived RDP credentials as a lifecycle failure and replace them with ephemeral access.
NIST SP 800-53 Rev 5IA-5 — Authenticator ManagementThe article is about controlling credentials and revoking them at runtime, which maps directly to authenticator lifecycle.
Recommendation — Use IA-5 to govern issuance, rotation and revocation of privileged authenticators.
NIST CSF 2.0PR.AA-05 — Access Permissions, Entitlements and AuthorizationsThe article focuses on who can access what, under what conditions and for how long.
Recommendation — Apply PR.AA-05 to make privileged access time-bound and identity-specific.
MITRE ATT&CKTA0006;TA0008 — Credential Access; Lateral MovementStatic admin credentials and remote access paths are classic enablers of credential abuse and movement.
Recommendation — Map shared RDP credentials to TA0006 and TA0008 when hunting for misuse and spread.

Key terms

  • Just-in-Time Access Request: Just-in-Time Access Request is a pattern that grants access only when it is needed and only for the duration required. It reduces standing privilege by making access temporary, policy driven, and task scoped. This approach is especially useful for contractors, sensitive systems, and short-lived operational work.
  • Zero Standing Privilege: A control model in which an identity does not keep persistent access unless it is actively needed. For NHIs, this means credentials and permissions are issued for a narrow task and then removed. It reduces the time window and reuse value of stolen access.
  • Session Recording: Session recording is the capture of user activity during a privileged session, such as commands, queries, or administrative actions. It gives security and audit teams a verifiable record of what happened after authentication, which is essential when access itself is not enough to prove control.
  • Runtime Access Control: Policy enforcement that evaluates an identity's action at the moment it tries to do something, rather than only at login or provisioning time. For AI agents, this is critical because they can chain actions dynamically and exceed their intended scope without a new authentication event.

What's in the full article

P0 Security's full video covers the operational detail this post intentionally leaves for the source:

  • A walkthrough of time-bound RDP issuance tied to real corporate identity
  • Approval-history and session-recording workflow detail for privileged sessions
  • How real-time revocation is handled during an active access window
  • The runtime access platform view across users, machines and AI agents

👉 The full P0 Security video shows how approval history, session recording and real-time revocation fit into runtime RDP access.

Deepen your knowledge

NHI governance, agentic AI identity, and machine identity lifecycle are core topics in our NHI Foundation Level course, the industry's only accredited NHI security programme. If you are building or maturing an IAM programme, it is worth exploring.
NHIMG Editorial Note
Published by the NHIMG editorial team on September 30, 2026.
NHI Mgmt Group, the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org