TL;DR: AWS adding privileges that can delete anomaly detectors, suppress scraper logging, and issue web identity tokens that extend machine identities beyond AWS changes both observability and access risk, according to Sonrai Security’s November 2025 review. The lesson for identity teams is that small permission shifts can materially widen the attack surface when least privilege is not continuously enforced.
Editorial analysis by NHI Mgmt Group, based on content published by Sonrai Security: “Nov Recap: New AWS Privileged Permissions and Services”.
Key questions
Q: What breaks when cloud permissions can disable logging or anomaly detection?
A: Visibility breaks first, then attribution and containment.
Q: Why do web identity tokens create more risk than ordinary cloud roles?
A: They can extend a machine identity beyond the original platform boundary into external services, so the access path no longer ends at the cloud account.
Q: How do IAM teams know whether cloud least privilege is actually working?
A: They should look for declining counts of dormant privileges, fewer overprivileged machine identities, and a measurable shift from standing access to task-scoped access.
Practitioner guidance
- Review service permissions against current API capability Re-certify cloud roles after every provider permission expansion so the review reflects actual service behaviour, not the policy snapshot from the last cycle.
- Classify telemetry-altering privileges as high risk Separate permissions that can delete anomaly detectors, update logging configurations, or suppress scraper output into a privileged-access review queue.
- Map federated token issuance to external trust paths Identify every workload that can mint web identity tokens and document which external services will accept those tokens for authentication.
Bottom line: New AWS permissions can change the meaning of an existing role by adding telemetry tampering or external token issuance capability.
Explore further
View Full Forum → | NHI Foundation Course → | Our Services → | Read the full analysis →
Cloud privilege drift is now a governance problem, not just an IAM problem: when existing services gain new actions, the effective power of a role changes even if the role definition looks unchanged. That breaks entitlement review models that assume role names and policy intent remain stable between recertification cycles. Practitioners should treat cloud release notes as governance inputs, not just engineering updates.
A few things that frame the scale:
- 92% of organisations expose NHIs to third parties, raising concerns about supply chain security, according to the Ultimate Guide to NHIs.
- 97% of NHIs carry excessive privileges, increasing unauthorised access and broadening the attack surface, according to the Ultimate Guide to NHIs.
A question worth separating out:
Q: Should cloud identity teams review observability permissions and access tokens together?
A: Yes. When the same cloud estate can both hide activity and issue federated identity tokens, governance has to treat monitoring and authentication as one control chain. Reviewing them separately leaves a gap between what is being watched and what can still be used to authenticate elsewhere.
👉 Read our full editorial: AWS privilege changes expose gaps in cloud identity governance