Join our Newsletter — 33% off our NHI Course

OCI just-in-time access: how do teams avoid standing privilege?

 

(@nhi-mgmt-group)
Member Moderator
Joined: 1 year ago
Posts: 20707
Topic starter  

TL;DR: OCI teams often drift into standing access because manual role creation is faster in the moment, while just-in-time provisioning keeps permissions short-lived, scoped and auditable, according to P0 Security. The practical issue is not authentication alone, but whether least privilege survives real operational pressure without becoming permanent by default.

NHIMG editorial: based on content published by P0 Security: Resource | Video Five minutes to secure OCI access with least privilege just-in-time provisioning

Questions worth separating out

Q: What breaks when OCI access is not granted just in time?

A: When OCI access is pre-provisioned and left standing, engineers can keep permissions long after the task that justified them.

Q: Why do standing cloud permissions increase risk in OCI environments?

A: Standing permissions turn a one-off operational need into always-on access, which means attackers or insiders inherit more capability than the task requires.

Q: How do security teams know if just-in-time access is actually working?

A: Look for short-lived sessions, automatic revocation, and complete request-to-access logs.

Practitioner guidance

  • Enforce zero standing access for OCI work Require engineers to request scoped OCI permissions at the moment they need them, rather than pre-assigning permanent roles and groups.
  • Tie approval to task duration and resource scope Capture a reason, a finite expiry, and the exact OCI resource set in every access request so the approval maps to the job being performed.
  • Automate expiry and revocation Remove the granted OCI membership and associated permissions automatically when the time window ends, with manual revocation available for exceptions.

What's in the full article

P0 Security's full video covers the operational detail this post intentionally leaves for the source:

  • The step-by-step OCI request flow, including approval handoff and session refresh behaviour
  • The exact workflow for mapping an existing SSO identity into OCI without pre-provisioning users and groups
  • The automatic revocation process that removes group membership and permissions when the access window ends
  • The live user experience showing how engineers keep working without switching accounts or credentials

👉 Watch P0 Security's video on just-in-time OCI access and least privilege →

OCI just-in-time access: how do teams avoid standing privilege?

Explore further

View Full Forum →  |  NHI Foundation Course →  |  Our Services →



   
Quote
(@mr-nhi)
Member Moderator
Joined: 5 months ago
Posts: 20298
 

Standing access is a governance failure, not an authentication failure. The article makes clear that users can sign in through SSO and still be forced into over-broad permissions because the operational path of least resistance is to make access permanent. That pattern creates privilege creep by design, not accident. The practitioner lesson is to treat convenience-driven permanence as a control defect in the entitlement model.

A few things that frame the scale:

A question worth separating out:

Q: Should teams use just-in-time access instead of permanent OCI roles?

A: Yes, when the role exists only to complete a bounded task. Permanent roles make sense only when the business function truly requires continuous authority. For most operational cloud work, just-in-time access gives a better balance of usability, auditability, and privilege control.

👉 Read our full editorial: Just-in-time OCI access reduces standing privilege in cloud operations



   
ReplyQuote
Share: