TL;DR: Enterprises still struggle to centralize privilege management, improve cloud security maturity, and eliminate standing access across multi-cloud environments, according to Britive’s 2023 survey of AWS, GCP and OCI users. The control gap is structural: time-bound access and uniform governance matter more than adding another layer of tooling.
Editorial analysis by NHI Mgmt Group, based on content published by Britive: “2023 State of Cloud Identities and Privileges Report”.
Key questions
Q: What breaks when standing access is still used for cloud administration?
A: Standing access breaks the assumption that elevated privilege is only present when it is needed.
Q: Why do multi-cloud environments make least privilege harder to maintain?
A: Multi-cloud environments multiply identity stores, role models, inheritance paths, and operational teams.
Q: How do teams know whether cloud privilege controls are working?
A: Look for whether privileged changes are reviewable, short-lived, and distinguishable from normal operations.
Practitioner guidance
- Standardize time-bound access for privileged cloud roles Replace durable administrator grants with task-scoped access for cloud operators, engineers, and break-glass use cases so privilege expires when the work ends.
- Centralize cloud privilege governance Create one policy model for entitlement approval, review, and revocation across AWS, GCP, and OCI instead of maintaining separate exception processes per cloud.
- Inventory standing access across cloud accounts Identify privileged identities that remain active without a current task owner, then classify them by business need, elevation level, and revocation priority.
Bottom line: Multi-cloud identity governance fails when privilege is handled as a local operational detail instead of a centrally governed control surface.
Explore further
View Full Forum → | NHI Foundation Course → | Our Services → | Read the full analysis →
Cloud privilege sprawl is still a governance problem, not a tooling problem. The report’s focus on AWS, GCP, and OCI users shows that multi-cloud estates create inconsistent privilege patterns even when access tooling exists. The real issue is the absence of a uniform operating model for entitlement scope, approval, and revocation. Practitioners should treat cross-cloud governance as the control layer that determines whether identity policy can actually be enforced.
A few things that frame the scale:
- 97% of NHIs carry excessive privileges, increasing unauthorised access and broadening the attack surface, according to the Ultimate Guide to NHIs.
A question worth separating out:
Q: Should organisations prioritize dynamic access over broader cloud role cleanup?
A: Dynamic access should usually come first when standing privilege is the main exposure, because it reduces the time window during which elevated access can be abused. Role cleanup still matters, but removing unused roles does not solve the core problem if active privilege remains persistent. The priority is to make elevated access temporary before trying to make it perfectly tidy.
👉 Read our full editorial: Cloud identities and privileges expose gaps in multi-cloud access control