Over-provisioned standing access
Privilege escalation
Privilege escalation is gaining more access than an account was meant to have, such as moving from a standard user to an administrator or granting an app broad new permissions. Attackers do it after getting in, by exploiting software flaws, abusing misconfigured roles or taking over accounts and apps that already hold high privileges.
How it works
After an initial foothold, the attacker maps which accounts, groups and applications hold powerful rights. They then exploit a vulnerability, reuse a harvested admin credential or use an over-permissioned identity to grant themselves new roles. Each step widens what they can read, change or delete, often ending with control of the directory or cloud tenant.
A real example
Microsoft said in January 2024 that Midnight Blizzard compromised a legacy test OAuth application with elevated access to its corporate environment and used it to grant the Office 365 Exchange Online full_access_as_app role, which allows access to mailboxes.
Source: Midnight Blizzard: Guidance for responders on nation-state attack — Microsoft Security, 2024-01-25
How to stop it
Grant admin rights just in time and only for the task, require approval for new high-privilege roles and app permissions, and alert whenever one is assigned.
Related terms
Threat actors that use it
- Akira
Profile with government sources
- Black Basta
Profile with government sources
- Volt Typhoon
Profile with government sources
Sources
- Midnight Blizzard: Guidance for responders on nation-state attack — Microsoft Security, 2024-01-25
Last reviewed Oct 2, 2026