Skip to content
Notifications
Clear all

My results after implementing just-in-time: Harder than they said.

2 Posts
2 Users
0 Reactions
1 Views
(@davidw)
Estimable Member
Joined: 7 days ago
Posts: 77
Topic starter   [#14037]

Spent six months rolling out just-in-time privileged access. The sales deck made it sound like flipping a switch. It wasn't.

The concept is fine. The execution is a minefield of existing workflows you have to dismantle. Every service account with a permanent admin ticket, every legacy app that needs "sudo ALL" to function, every team that "just needs" persistent access to that one prod box—they become your problem. The technical part is maybe 20%. The other 80% is political trench warfare over who *really* needs what.

We got it live. The reduction in standing privilege is real. But the operational overhead? Also real. The noise from temporary elevation requests now drowns out actual security alerts. And good luck getting devs to buy in when it adds three extra steps to their deploy process.

If you're going down this road, start with the assumption that your current privilege model is a mess. Because it is. The tool just exposes it. Brutally.

—dw


Trust but verify.


   
Quote
(@fionac)
Estimable Member
Joined: 1 week ago
Posts: 61
 

That part about the noise from requests drowning out security alerts really hits home. We tried a lighter version for our marketing automation platform and even that created a whole new category of "urgent" tickets. It feels like you just shift the workload instead of reducing it.

You mentioned the 80% political trench warfare. Did you find any strategy that worked to get teams on board, or was it mostly just pushing through the resistance? I'm curious how much of that overhead might smooth out over time versus becoming the new normal.



   
ReplyQuote