Bailey Bercik, a Senior Product Manager on Microsoft Security's Identity Team, dives into the evolving landscape of least privilege and permission management in 2025. He discusses how Entra Permissions Management can streamline unused permissions, making security more manageable. The impact of AI on permissions—both its risks and potential benefits—is explored, emphasizing the need for careful oversight. Bailey also details strategies for refining permissions in AI contexts and advocates for robust monitoring to prevent misuse, ensuring effective privilege management.
The integration of AI in managing permissions necessitates a proactive approach, ensuring effective oversight to minimize overprivileged access and security risks.
Organizations should focus on tailored permission management through advanced tools like Entra Permissions Management, balancing security and usability in multi-cloud environments.
Deep dives
Understanding Least Privilege
Recognizing the significance of least privilege is critical in modern cybersecurity. The conversation highlights that achieving a perfect security setup is unrealistic, as both administrators and users are prone to mistakes. Instead of striving for perfection, organizations should focus on practical security measures that balance protection with usability. Emphasizing defense in depth and the use of compensating controls can lead to more effective security without the unrealistic pressure for flawless execution.
The Challenges of Granular Permissions
Granular permissions remain challenging to implement, exacerbated by past tool limitations that either offered very few privileges or too many to administrators. Recent advancements in tools, particularly in Cloud Infrastructure Entitlement Management (CIEM), provide better visibility into the permissions assigned versus those actually utilized. This ability allows for more tailored management of administrative privileges across multi-cloud environments, ensuring organizations can monitor and adjust permissions effectively. Such tools can reveal discrepancies between assigned and used permissions, enabling a shift towards a least privilege model.
Role of AI in Permission Management
AI tools are increasingly integrated into security processes, particularly for managing permissions and identifying risks. The conversation emphasizes the importance of using AI to oversee permissions assigned to both human and non-human identities, especially in the context of AI applications. By analyzing how often and which permissions are used, organizations can minimize the risk of overprivileged access. This proactive approach can safeguard against threats while empowering effective use of AI technologies across various roles within a company.
Navigating Organizational Change and Security
The integration of AI into workflows highlights the necessity for organizations to adapt their security strategies accordingly. It's discussed that simply denying access to AI tools isn't sufficient; organizations must provide alternative solutions that meet both security and user productivity needs. As employees increasingly turn to AI applications for efficiency, IT and security professionals have the responsibility to ensure data security while promoting engagement with these tools. By implementing robust monitoring systems and training, organizations can ensure safe usage of AI, thereby preventing unauthorized data sharing or exposure.
How is least privilege different in 2025? Richard talks to Bailey Bercik about the ongoing efforts to minimize users, administrators, and applications' privileges in 2025. Bailey talks about the power of Entra Permissions Management to help you see what permissions are going unused on various accounts so that you can tailor rights to individual accounts without things becoming unmanageable. Artificial intelligence is a forcing function for many permission issues, with these new tools potentially creating problems when given unnecessary rights. But those same tools can help you understand where permissions are being underutilized and help protect your systems!