By NHI Mgmt Group Editorial TeamBased on StrongDM: “What is Zero Standing Privilege (ZSP)? (And How They Work)” (February 20, 2026)

TL;DR: Zero standing privilege replaces always-on access with just-in-time credentials that expire after the task, reducing standing privilege and limiting lateral movement risk, according to StrongDM. The governance issue is that access review, audit, and accountability all weaken when privileged access persists by default instead of existing only for a task-bound window.


At a glance

What this is: This is a StrongDM explainer on zero standing privilege and just-in-time access, arguing that removing persistent privileged access reduces exposure but changes how teams govern approval, logging, and accountability.

Why it matters: It matters because IAM, PAM, and NHI programmes increasingly have to control access at issuance time, not just manage standing entitlements after the fact.


Context

Zero standing privilege is a privileged access model that removes baseline access and grants permissions only for a specific task window. In practice, that means identity security moves from managing durable access rights to governing request, approval, and expiry flows across systems, applications, and administrative accounts.

The governance gap is not whether least privilege is desirable. It is whether existing PAM and access review models can handle access that appears, is used, and disappears before the next review cycle. For IAM teams, this is as much a lifecycle problem as a control design problem.


Key questions

Q: What breaks when privileged access is still standing instead of task-scoped?

A: Standing privilege gives attackers immediate value the moment a credential is stolen. They can move from access to control without waiting for approval, because the account already carries elevated rights between sessions. That is why modern PAM shifts privileged access to just-in-time, session-scoped credentials that expire automatically after the task ends.

Q: Why does just-in-time access reduce lateral movement risk?

A: Just-in-time access limits how long a credential is valid and ties it to a specific request, so stolen access is less reusable. If an attacker captures the credential, the window for pivoting across systems is much smaller than with standing access. The control reduces opportunity, but only if requests, approvals, and expiry are tightly enforced.

Q: How do teams know whether zero standing privilege is actually working?

A: Teams should look for evidence that privileged access is time-bound, fully revoked, and impossible to reuse outside the approved session. If old secrets remain valid, break-glass accounts stay active, or administrators can operate without a fresh grant, ZSP is only partially implemented.

Q: How should security teams replace least privilege with zero standing access?

A: Start by identifying where access persists after the task ends, then convert those paths to just-in-time grants with automatic expiry. The goal is not to make entitlements look more precise. It is to ensure no privilege remains usable without a current business reason. That approach works across humans, service accounts, and operational workflows.


Technical breakdown

How zero standing privilege changes privileged access governance

Zero standing privilege (ZSP) is not just a tighter permission set. It removes permanent access entirely, so the identity starts with no standing entitlement and receives access only when a request is approved for a defined task. That makes the control boundary shift from assignment time to issuance time. In a ZSP model, policy logic, approval workflow, and credential expiry become the core governance objects, not static group membership. The article also notes that this applies to both human and non-human users, which means the same access issuance pattern can govern admins, services, and other machine-style identities when the environment supports it.

Practical implication: treat access issuance and expiry as governed events, not just entitlement changes.

Why standing privileges widen breach impact

Standing privileges are always-on permissions tied to role, department, or job level rather than immediate need. Once credentials are exposed, the attacker inherits whatever that identity can reach, which can include multiple systems and opportunities for lateral movement. The article’s core mechanism is that the credential becomes a reusable access path instead of a task-bound grant. That matters because traditional vaulting can hide secrets without changing the underlying assumption that the secret remains valid long enough to be abused. ZSP reduces that reuse window by replacing durable access with ephemeral credentials tied to a specific request.

Practical implication: map which privileged identities can still traverse multiple systems if a secret is stolen.

How JIT access supports zero trust and auditability

Just-in-time access is the enabling pattern for ZSP. Instead of pre-provisioning access, the system creates ephemeral credentials at request time and destroys them when the task ends or the time limit expires. The article also ties JIT to role-based and attribute-based controls, plus approval workflows and session records. That combination matters because zero trust is not only about verifying the user once; it is about continuously constraining access to the minimum needed for the current action. JIT makes the access event observable, but it also concentrates governance at the moment of request, when policy decisions have to be right.

Practical implication: align approval logic, session logging, and expiry rules so every privileged request leaves an auditable trail.


Threat narrative

Attacker objective: The attacker wants to turn one privileged credential into broad internal access and use it to expand reach across the environment.

  1. Entry occurs when a privileged account or its credentials are exposed, giving an attacker a valid starting identity rather than forcing exploitation of a technical vulnerability.
  2. Escalation happens because standing privilege lets that identity reach additional systems without a fresh authorisation step, expanding the set of reachable assets.
  3. Impact follows when the attacker moves laterally through the environment or abuses administrative reach to access data, systems, or secrets beyond the original task scope.
  • BeyondTrust breach 2024: A stolen BeyondTrust Remote Support API key let a China state-sponsored actor reset accounts and reach US Treasury workstations in 2024.
  • Azure Key Vault Contributor escalation 2024: Datadog found Azure Key Vault Contributor could add itself to access policies and read every secret, key and certificate in a vault.

Read and download The State of NHI & AI Agent Breach Report 2026, covering 150+ breaches impacting Non-Human Identities including AI Agents.


NHI Mgmt Group analysis

Zero standing privilege is a control redesign, not a permission cleanup. The article shows that ZSP changes the security unit from a durable entitlement to a short-lived access event. That is a meaningful shift for IAM and PAM programmes because policy now has to govern request, approval, and expiry as one lifecycle. For practitioners, this means the real control surface is access issuance, not just access inventory.

Standing privilege creates identity blast radius by design. When one credential can reach many resources, compromise of that identity becomes a multiplier rather than a single access loss. That is why ZSP aligns so naturally with zero trust thinking: it reduces the number of paths an attacker can reuse after credential theft. Practitioners should treat standing administrative access as an architectural risk, not merely an operations inconvenience.

Access review processes assume privilege persists long enough to be reviewed. That assumption holds for static entitlements but weakens when access exists only for a task window and is destroyed on completion. The implication is not merely that reviews need better tooling; it is that certification cadence cannot be the primary safety net for ephemeral access. Practitioners need governance that validates issuance conditions before the session begins.

Zero standing privilege exposes a governance gap between least privilege and no privilege. Least privilege still accepts baseline access, while ZSP removes baseline access entirely. That distinction matters because many organisations believe they have solved privileged access when they have only reduced it. For identity teams, the hard question is whether their controls can operate in a world where no access is the default state.

Named concept: ephemeral privilege window. The article’s core governance pattern is a privilege grant that exists only for the duration of a task and then self-destructs. That concept sharpens the real security question: not who has access over time, but what access must exist long enough to be useful. Practitioners should measure privileged exposure in minutes, not just in entitlements.

From our research library:

What this signals

Access review programmes can still leave a large blind spot when the real control is issuance time, not recertification time. Ephemeral privilege window: once access exists only for a task and disappears immediately after, governance has to move from certifying held privileges to validating the conditions under which access was granted.

For IAM and PAM teams, the practical question is whether their current model can distinguish between durable access and task-scoped access across both human admins and non-human identities. The more access is granted on demand, the more the programme needs policy, approval evidence, and session logging to replace standing entitlement as the control anchor.


For practitioners

  • Define zero standing privilege as a governance target Classify which privileged roles still have baseline access and set a programme objective to remove standing permissions wherever task-bound issuance is feasible.
  • Move privileged access to request-time issuance Require ephemeral credentials for administrative work so access is created only after request approval and expires when the task ends.
  • Audit where standing credentials still enable lateral movement Map admin accounts, shared accounts, and secrets that can reach multiple systems without reauthorisation, then prioritise the highest blast radius first.
  • Make approval and session records audit-ready Capture who requested access, why it was needed, how long it was granted, and what actions occurred during the session.
  • Reduce reliance on static shared accounts Eliminate standing shared credentials where possible and replace them with per-request access flows backed by role or attribute policy.

Key takeaways

  • Zero standing privilege changes privileged access from a persistent entitlement model to a governed, task-bound access event.
  • The main security benefit is reduced exposure if credentials are stolen, because the access window is shorter and less reusable.
  • Teams that keep standing privileged accounts in place have not fully shifted from entitlement management to issuance control.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

OWASP Non-Human Identity Top 10 addresses the attack and risk surface, while NIST CSF 2.0, NIST SP 800-53 Rev 5 and NIST Zero Trust (SP 800-207) set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
OWASP Non-Human Identity Top 10NHI-05 — Overprivileged NHIZSP directly targets persistent excessive privilege in privileged identities.
NHI-07 — Long-Lived SecretsThe article centres on ephemeral credentials replacing long-lived privileged access paths.
Recommendation — Remove standing access from privileged identities and force time-bound issuance for every request. Shorten privileged credential lifetime and destroy access immediately after the task completes.
NIST CSF 2.0PR.AA-05 — Access Permissions, Entitlements and AuthorizationsZSP is fundamentally about governing entitlements and authorizations at access time.
Recommendation — Rework entitlement governance so privileged authorizations are granted only for approved, task-specific use.
NIST SP 800-53 Rev 5IA-5 — Authenticator ManagementJIT access depends on controlled authenticator issuance, use, and destruction.
Recommendation — Apply authenticator lifecycle controls to issue, expire, and revoke privileged credentials on demand.
NIST Zero Trust (SP 800-207)Zero Trust ArchitectureThe article explicitly frames ZSP as a zero trust access pattern.
Recommendation — Align privileged access with zero trust by verifying and constraining every access request.

Key terms

  • Zero Standing Privilege: A control model in which an identity does not keep persistent access unless it is actively needed. For NHIs, this means credentials and permissions are issued for a narrow task and then removed. It reduces the time window and reuse value of stolen access.
  • Just-in-Time Access Request: Just-in-Time Access Request is a pattern that grants access only when it is needed and only for the duration required. It reduces standing privilege by making access temporary, policy driven, and task scoped. This approach is especially useful for contractors, sensitive systems, and short-lived operational work.
  • Standing Privilege: Standing privilege is access that remains active even when no immediate task requires it. For NHI programmes, it is a common failure mode because long-lived credentials and persistent roles create unnecessary exposure. Reducing standing privilege usually means tighter expiry, on-demand access, and clearer review of who or what still needs access.
  • Ephemeral Credentials: Ephemeral credentials are short-lived access artefacts issued for a limited task or session. They reduce the window for abuse, but they only improve security when paired with strong scope limits, telemetry, and automatic revocation at task completion.

Deepen your knowledge

NHI governance, agentic AI identity, and machine identity lifecycle are core topics in our NHI Foundation Level course, the industry's only accredited NHI security programme. If you are responsible for identity security strategy or NHI governance in your organisation, it is worth exploring.
NHIMG Editorial Note
Published by the NHIMG editorial team on June 7, 2026.
Updated on October 7, 2026.
NHI Mgmt Group, the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org