TL;DR: Stryker’s March 11 breach shows how stolen admin credentials and standing Intune access can enable a full enterprise wipe without malware, zero-days, or lateral movement, according to Venice.io. The case turns Zero Standing Privilege from a policy preference into a decisive control boundary for NHI governance and privileged access.
NHIMG editorial — based on content published by Venice.io covering the Stryker Intune wipe incident: Zero Standing Privileges 200,000 Devices Wiped. No Malware Required
By the numbers:
- The attack affected 79 offices and led to 50 terabytes of data exfiltrated.
- Attackers attempted access within an average of 17 minutes after AWS credentials were exposed publicly, and as quickly as 9 minutes in some cases.
Questions worth separating out
Q: What breaks when standing Intune admin access is not in place?
A: The main failure is not convenience, it is destructive control removal.
Q: Why do stolen admin credentials create outsized risk in medical technology environments?
A: Because admin roles often span ordering systems, device management, and internal business applications, one compromised account can affect both operations and data.
Q: How do teams know if just-in-time access is actually reducing privilege risk?
A: They should verify that temporary access has strict expiry, clear approval traceability, and dependable revocation after task completion.
Practitioner guidance
- Eliminate standing Intune administrator access Move all high-impact device management roles to task-scoped elevation so no account holds permanent destructive authority in the console.
- Classify management-plane roles as privileged blast-radius controls Inventory every identity that can push software, change policy, or wipe devices, then require stronger approval and review than for ordinary admin access.
- Pair JIT elevation with continuous session evaluation Monitor active admin sessions for unusual wipe, policy, or bulk-change behaviour and revoke access when the activity deviates from the expected task.
What's in the full article
Venice.io's full blog post covers the operational detail this post intentionally leaves for the source:
- How Venice's JIT role elevation flow removes permanent Intune administrator access in practice.
- How CAEP-based monitoring evaluates unusual admin behaviour during a live elevated session.
- What the control design looks like when one account can reach wipe, policy, and software deployment actions.
- How the attack would have failed if the admin role did not exist as a standing permission.
👉 Read Venice.io's analysis of the Stryker Intune wipe incident →
Standing Intune admin access: are your controls keeping up?
Explore further
Standing privilege in management planes is the real failure mode here: The breach worked because a high-impact admin role was continuously active rather than task-scoped. That assumption was designed for human-paced administration, not for attackers who can move immediately after credential compromise. The implication is that privileged access governance for Intune-like platforms must be built around elimination of standing exposure, not around detection after the fact.
A few things that frame the scale:
- 88.5% of organisations acknowledge that their non-human IAM practices lag behind or are merely on par with their human identity and access management efforts, according to the 2024 Non-Human Identity Security Report.
- Only 19.6% of security professionals express strong confidence in their organisation's ability to securely manage non-human workload identities, which helps explain why standing access persists.
A question worth separating out:
Q: Who is accountable when a valid admin identity is used to wipe devices at scale?
A: Accountability sits with the organisation that allowed destructive authority to reside in a single compromised identity path. The governance question is whether privilege boundaries, approval workflows, and session controls were strong enough to stop legitimate tools from becoming a sabotage mechanism.
👉 Read our full editorial: Standing Intune admin access turned Stryker into a wipe event