You have a privileged access tool. Maybe two. Possibly three, if you count the one the last team bought and nobody remembers configuring. None of them have touched your Domain Admins group in eight months.
Privileged access creep happens the same way every time. Someone needs elevated permissions for a project, a migration, a vendor engagement. They get access. The work ends. Nobody removes them.
This is not negligence. It is physics. Adding someone to a privileged group has a trigger: a ticket, a request, an approval. Removing someone has no trigger. So membership grows, the group gets noisier, and nobody questions it until something forces the issue.
Every practitioner I have spoken with knows their privileged groups are bloated. That is not the problem. The problem is that "we should clean this up" lives permanently on the backlog, parked somewhere below the next tool evaluation and the next compliance deadline.
Most teams treat least privilege as an architecture problem. Get the right PAM solution, build the joiner-mover-leaver workflows, integrate with your IdP. The result is often a beautifully documented provisioning system with clean onboarding and six years of stale accounts in every privileged group it predates.
Least privilege is not an architecture problem. It is a habit problem.
The tool shows you who has access. The habit is the part where someone reads that list, makes a judgment call, and removes a person from it. No platform automates that. A practitioner has to do it.
So, here's the MondayMove
Pick one privileged group: Domain Admins, root in your cloud account, or the keys to your customer database. List every member. Find one person who should not still be there and remove them today. Then put it on your calendar for next month.
No tool required. Just the list and five minutes.
Discussion