← All case studies

Healthcare SaaS · 600 employees

Privileged access redesign for an Azure landing zone

Replaced standing Owner/Contributor assignments with a PIM-backed, JIT model across 14 subscriptions without disrupting platform teams.

9 weeks

  • PIM
  • Azure
  • Privileged Access

Problem

A platform engineering team operated with permanent Owner on every subscription in an Azure landing zone. The pattern was convenient and exactly the finding a recent penetration test flagged as the highest-impact risk.

The team had real operational needs — break-fix, capacity changes, IAM exceptions — and any redesign that introduced friction would be abandoned within a month.

Solution

Mapped every privileged action the team performed over a 30-day window using activity logs, and grouped them into five operational personas.

Replaced standing Owner with eligible role assignments through PIM. Each persona received the minimum set of roles required to perform its workflow, with an approval flow only for Owner-equivalent actions.

Built a short, opinionated runbook for each persona — what to activate, for how long, and what to log in the change ticket on activation.

Outcome

Zero standing privileged role assignments in the landing zone post-rollout.

Mean activation time under 90 seconds; team adoption was full within two sprints.

Pen-test re-run six months later: the original finding was closed and no equivalent privilege escalation path was identified.