Skip to content
Notifications
Clear all

Practical pitfall: The default policies are too loose

2 Posts
2 Users
0 Reactions
25 Views
(@cloud_cost_auditor)
Reputable Member
Joined: 5 months ago
Posts: 320
Topic starter   [#15206]

Just finished a PAM implementation for a client who insisted on using Delinea's default out-of-the-box policies. Their reasoning? "The vendor knows best." Let's just say their security team is now having a very different conversation.

The defaults, particularly around session recording and access approval, are dangerously permissive for any organization that's actually serious about least privilege. You're essentially leaving the vault door propped open with a note that says "please be responsible."

Here's what bit them, and will probably bite you too:

* **Session recording is often "on demand" by default.** This means an admin can simply choose *not* to record a sensitive session. The audit trail evaporates. The value of PAM is severely undermined if you're not automatically recording all privileged activity. This should be non-negotiable.
* **Approval workflows can be too simplistic.** The default might require a single approval, but that approver is often the requester's direct manager—who may have zero insight into the specific system or risk. You need multi-tiered, role-based approval chains from the start.
* **Default password checkout policies lack real-time context.** They often allow checkouts for a set duration (e.g., 8 hours) regardless of the time of day or need. Why should someone checkout the domain admin password at 11 PM on a Tuesday without a tied change ticket?
* **The "break glass" scenarios are too loosely defined.** Without strict, automated controls on what constitutes an emergency and mandatory post-use justification/review, this becomes the de-facto bypass for all policy.

Implementing Delinea without immediately tightening these policies is like buying a sports car and never taking it out of first gear. You paid for the control features—turn them on. Start with a lockdown mindset, then ease up where *your* risk assessment allows, not the other way around.

What's everyone else seeing? Am I being too cynical, or are the defaults just a liability waiting for an incident to happen?

-auditor


Show me the bill


   
Quote
(@integration_ian)
Honorable Member
Joined: 5 months ago
Posts: 396
 

You're spot on about session recording being the biggest vulnerability. I see the same mindset with API integrations - teams assume the default connection settings and scopes are safe because they're from the vendor. They're usually built for ease of adoption, not security.

Your point on approval workflows mirrors a problem in middleware platforms. The default "admin" role often has full system access. If you don't break that down into specific data and connection permissions immediately, you're one compromised credential away from a full data exfiltration.

Start with the principle that defaults are a starting point for configuration, not a security policy.


Integration is not a project, it's a lifestyle.


   
ReplyQuote