By NHI Mgmt Group Editorial TeamDomain: Governance & RiskSource: Venice.ioPublished March 31, 2026

TL;DR: Stryker’s March 11 breach shows how stolen admin credentials and standing Intune access can enable a full enterprise wipe without malware, zero-days, or lateral movement, according to Venice.io. The case turns Zero Standing Privilege from a policy preference into a decisive control boundary for NHI governance and privileged access.


At a glance

What this is: This is an analysis of the Stryker wipe incident, showing how stolen admin credentials and standing Intune access enabled mass device destruction.

Why it matters: It matters because privileged access to management planes is an NHI governance problem as much as a human IAM problem, and permanent admin roles create catastrophic blast radius.

By the numbers:

  • The attack affected 79 offices and led to 50 terabytes of data exfiltrated.
  • Attackers attempted access within an average of 17 minutes after AWS credentials were exposed publicly, and as quickly as 9 minutes in some cases.

👉 Read Venice.io's analysis of the Stryker Intune wipe incident


Context

Standing privileged access to a device management plane is a governance failure, not just a security misconfiguration. When an identity can issue destructive actions without time bounds, approval gates, or step-up verification, the control plane becomes the attack surface. In this case, the primary issue is Zero Standing Privilege for high-impact admin roles.

The article describes a real-world example of why privileged access management must cover management consoles such as Intune, not only traditional servers or endpoints. The attack path relied on stolen credentials, role escalation, and a legitimate administrative action that should have been ephemeral. That is a typical failure pattern in organisations that treat admin roles as permanent entitlements rather than task-scoped access.

For identity teams, the lesson is broader than one incident. Any platform that can wipe devices, push software, or change policy needs the same lifecycle discipline as other high-risk NHI and human-admin identities. The standing access assumption is what fails first.


Key questions

Q: What breaks when standing Intune admin access is not in place?

A: The main failure is not convenience, it is destructive control removal. If no one holds permanent Intune admin access, a stolen credential cannot immediately issue fleet-wide wipe commands or other high-impact changes. The attacker loses the standing authority that makes management-plane abuse possible, which sharply limits blast radius.

Q: Why do stolen admin credentials create outsized risk in medical technology environments?

A: Because admin roles often span ordering systems, device management, and internal business applications, one compromised account can affect both operations and data. In MedTech, the risk is amplified when privileged access is broad, long-lived, and not separated by action type, allowing legitimate tools to be used for destructive tasks.

Q: How do teams know if just-in-time access is actually reducing privilege risk?

A: They should verify that temporary access has strict expiry, clear approval traceability, and dependable revocation after task completion. If users can extend access easily or reuse temporary entitlements across multiple tasks, the programme is preserving standing privilege under a different label.

Q: Who is accountable when a valid admin identity is used to wipe devices at scale?

A: Accountability sits with the organisation that allowed destructive authority to reside in a single compromised identity path. The governance question is whether privilege boundaries, approval workflows, and session controls were strong enough to stop legitimate tools from becoming a sabotage mechanism.


Technical breakdown

How standing Intune admin access becomes a destructive control-plane risk

Microsoft Intune is a management plane, which means a successful admin session can change device state at enterprise scale. If administrator roles remain permanently active, any stolen credential tied to that role inherits the full destructive power of the platform. The problem is not malware on endpoints, but valid access to a privileged control surface. In identity terms, this is a classic standing privilege issue: the entitlement exists before need, persists after need, and can be abused immediately once compromised.

Practical implication: treat Intune administrator access as high-risk privileged access and remove any permanent entitlement that can execute destructive actions.

Why stolen admin credentials bypass network-centric assumptions

This attack did not depend on network traversal or endpoint compromise. The attacker used valid credentials to access Active Directory and escalate into Intune administration, which means traditional perimeter and malware controls never had a chance to intervene. Once inside a trusted admin workflow, the action looked legitimate to the platform. That is why identity assurance and privilege lifecycle controls matter more than endpoint-only detection when management planes are involved.

Practical implication: extend control coverage from endpoints to identity assertions, admin role elevation, and session-level monitoring in the management plane.

How JIT elevation and continuous access evaluation change the attack path

Just-in-time elevation removes the assumption that high-risk admin roles should always exist. A task-scoped role only becomes active when a legitimate request is made, and it disappears when the task ends. Continuous access evaluation then watches the active session for anomalous actions, such as mass wipe commands from an unusual context, and can revoke access before the action completes. Together, these controls compress the attacker’s usable window and reduce the damage radius of a compromised account.

Practical implication: pair JIT role elevation with continuous session evaluation for any identity that can impact fleet-wide device state.


Threat narrative

Attacker objective: The attacker’s objective was to disable enterprise operations by wiping managed devices and disrupting manufacturing, shipping, and emergency-response communications.

  1. Entry occurred when attackers obtained employee credentials, likely through infostealer malware, and used them to access enterprise identity systems.
  2. Escalation occurred when those credentials were leveraged to reach standing Intune administrator access, giving the attacker legitimate control-plane privileges.
  3. Impact occurred when the attacker issued remote wipe commands across Stryker’s device estate and automated the activity with a hidden script to sustain the destruction.

Read our 52 NHI Breaches Analysis report for a comprehensive view of breaches impacting Non-Human Identities including AI Agents.


NHI Mgmt Group analysis

Standing privilege in management planes is the real failure mode here: The breach worked because a high-impact admin role was continuously active rather than task-scoped. That assumption was designed for human-paced administration, not for attackers who can move immediately after credential compromise. The implication is that privileged access governance for Intune-like platforms must be built around elimination of standing exposure, not around detection after the fact.

Zero Standing Privilege is not a policy preference when the control plane can wipe fleets: A platform that can disable or erase 200,000 devices cannot safely rely on persistent administrator entitlements. The scale of the Stryker incident shows that one compromised admin session can become an enterprise continuity event. Practitioners should treat device management roles as high-risk blast-radius controls, not ordinary admin permissions.

Management-plane abuse is an identity problem before it is a security incident: The attacker used legitimate platform access, which means the breach path sat inside identity governance failure rather than outside it. In NHI terms, the role itself became the weapon once it remained available without lifecycle bounds. That is why access reviews alone are insufficient unless they are paired with ephemeral privilege design.

Identity blast radius: When a single admin role can reach fleet-wide destructive actions, the size of the blast radius is defined by entitlement scope, not by malware sophistication. This case sharpens the need to classify privileged console access as a separate governance domain with stronger lifecycle, approval, and monitoring controls. Security teams should reframe admin entitlements around impact, not convenience.

CAEP-style session monitoring matters because destructive actions are often still syntactically valid: The wipe command was not malformed or impossible, it was simply dangerous in the wrong hands. That means detection must evaluate context, not just command syntax. Organisations that cannot revoke a live admin session when behaviour turns anomalous are leaving the final containment step outside their identity programme.

From our research:

  • 88.5% of organisations acknowledge that their non-human IAM practices lag behind or are merely on par with their human identity and access management efforts, according to the 2024 Non-Human Identity Security Report.
  • Only 19.6% of security professionals express strong confidence in their organisation's ability to securely manage non-human workload identities, which helps explain why standing access persists.
  • See also the Guide to the Secret Sprawl Challenge for the credential lifecycle issues that often sit upstream of privileged access abuse.

What this signals

Standing privilege is now a fleet-level availability risk, not just an identity hygiene issue: Once a management plane can wipe devices, the control is effectively part of business continuity. Programmes that still separate IAM from endpoint governance will miss the point that destructive authority often sits inside identity, not outside it.

Zero Standing Privilege should be extended to every admin surface that can change device state: Intune, Entra-connected admin roles, and adjacent management consoles need the same lifecycle discipline as NHI secrets and service accounts. That shift aligns with the OWASP Non-Human Identity Top 10 and reduces the chance that a stolen credential becomes an enterprise-wide action.

Identity blast radius becomes measurable when you map who can do what from a live session: If a single role can wipe 200,000 devices, the question is no longer whether access exists, but how quickly it can be granted, observed, and removed. Teams that cannot answer that are operating with hidden operational risk.


For practitioners

  • Eliminate standing Intune administrator access Move all high-impact device management roles to task-scoped elevation so no account holds permanent destructive authority in the console.
  • Classify management-plane roles as privileged blast-radius controls Inventory every identity that can push software, change policy, or wipe devices, then require stronger approval and review than for ordinary admin access.
  • Pair JIT elevation with continuous session evaluation Monitor active admin sessions for unusual wipe, policy, or bulk-change behaviour and revoke access when the activity deviates from the expected task.
  • Harden credential theft recovery paths Assume infostealer-exposed credentials will be used quickly, and shorten the time between compromise detection, credential invalidation, and role removal.
  • Test destructive-action containment in management tools Run tabletop exercises for mass wipe, policy push, and enrollment abuse so identity and endpoint teams can verify the revocation path before an incident.

Key takeaways

  • The Stryker incident shows that standing admin access can turn a stolen credential into a destructive enterprise control-plane event.
  • The scale was severe: 200,000 devices were wiped, 79 offices were affected, and 50 terabytes of data were exfiltrated.
  • Removing standing privilege and adding live session revocation are the controls that would have constrained or broken this attack path.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

OWASP Non-Human Identity Top 10 and MITRE ATT&CK address the attack and risk surface, while NIST CSF 2.0, NIST Zero Trust (SP 800-207) and NIST SP 800-53 Rev 5 set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
OWASP Non-Human Identity Top 10NHI-03The article centers on standing privilege and privileged NHI access.
NIST CSF 2.0PR.AC-4Privileged access governance is central to the incident.
NIST Zero Trust (SP 800-207)The incident shows why continuous verification matters for privileged sessions.
NIST SP 800-53 Rev 5AC-6Least privilege failures enabled the wipe action.
MITRE ATT&CKTA0006 , Credential Access; TA0004 , Privilege Escalation; TA0040 , ImpactThe attack chain moved from stolen credentials to destructive impact.

Map credential theft and privilege escalation paths to impact-focused detection and containment controls.


Key terms

  • Standing Privilege: Standing privilege is access that remains active even when no immediate task requires it. For NHI programmes, it is a common failure mode because long-lived credentials and persistent roles create unnecessary exposure. Reducing standing privilege usually means tighter expiry, on-demand access, and clearer review of who or what still needs access.
  • Just-in-Time Elevation: A temporary access pattern that grants a user or system elevated permissions for a limited period. It reduces exposure compared with always-on privilege, but it does not necessarily remove the underlying role or account from the environment, so governance must still address the residual entitlement path.
  • Management Plane: The administrative layer used to configure, govern, and enforce behaviour across many endpoints or services. A management plane is not the workload itself. It is the control layer above it, which makes it especially sensitive to privileged misuse and delegated automation.
  • Identity Blast Radius: The amount of damage a compromised identity can cause across systems, data, and infrastructure. In NHI environments, it is shaped by permissions, network reach, and administrative capability rather than by the credential alone. Reducing blast radius is a containment strategy that limits lateral movement and data exposure.

What's in the full article

Venice.io's full blog post covers the operational detail this post intentionally leaves for the source:

  • How Venice's JIT role elevation flow removes permanent Intune administrator access in practice.
  • How CAEP-based monitoring evaluates unusual admin behaviour during a live elevated session.
  • What the control design looks like when one account can reach wipe, policy, and software deployment actions.
  • How the attack would have failed if the admin role did not exist as a standing permission.

👉 Venice.io's full post covers the JIT access model, CAEP response path, and the destructive role sequence.

Deepen your knowledge

NHI governance, agentic AI identity, and machine identity lifecycle are core topics in our NHI Foundation Level course, the industry's only accredited NHI security programme. If you are building or maturing an IAM programme, it is worth exploring.
NHIMG Editorial Note
Published by the NHIMG editorial team on August 20, 2026.
NHI Mgmt Group — the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org