{"id":4159,"date":"2019-01-15T12:14:47","date_gmt":"2019-01-15T16:14:47","guid":{"rendered":"https:\/\/solutionsreview.com\/identity-management\/?p=4159"},"modified":"2019-01-15T12:14:47","modified_gmt":"2019-01-15T16:14:47","slug":"want-better-identity-management-remove-your-orphaned-accounts","status":"publish","type":"post","link":"https:\/\/solutionsreview.com\/identity-management\/want-better-identity-management-remove-your-orphaned-accounts\/","title":{"rendered":"Want Better Identity Management? Remove your Orphaned Accounts"},"content":{"rendered":"<p><img loading=\"lazy\" decoding=\"async\" class=\"alignleft size-full wp-image-3375\" src=\"https:\/\/solutionsreview.com\/identity-management\/files\/2018\/07\/privileged-access-management-MOD.jpg\" alt=\"Want Better Identity Management? Remove your Orphaned Accounts\" width=\"800\" height=\"425\" srcset=\"https:\/\/solutionsreview.com\/identity-management\/files\/2018\/07\/privileged-access-management-MOD.jpg 800w, https:\/\/solutionsreview.com\/identity-management\/files\/2018\/07\/privileged-access-management-MOD-300x159.jpg 300w, https:\/\/solutionsreview.com\/identity-management\/files\/2018\/07\/privileged-access-management-MOD-768x408.jpg 768w, https:\/\/solutionsreview.com\/identity-management\/files\/2018\/07\/privileged-access-management-MOD-545x290.jpg 545w, https:\/\/solutionsreview.com\/identity-management\/files\/2018\/07\/privileged-access-management-MOD-508x270.jpg 508w, https:\/\/solutionsreview.com\/identity-management\/files\/2018\/07\/privileged-access-management-MOD-152x81.jpg 152w, https:\/\/solutionsreview.com\/identity-management\/files\/2018\/07\/privileged-access-management-MOD-339x180.jpg 339w\" sizes=\"(max-width: 800px) 100vw, 800px\" \/><\/p>\n<p style=\"text-align: justify\"><span style=\"font-weight: 400\">While the name may appear adorable &#8211; like a digital Oliver Twist &#8211; orphaned accounts resemble Bill Sikes more than a ruddy-cheeked street urchin. <\/span><\/p>\n<p style=\"text-align: justify\"><div class=\"widget\"><div class=\"aside-card\">\t\t\t<div class=\"textwidget\"><p><a class=\"iam-inject\" href=\"https:\/\/solutionsreview.com\/identity-management\/get-a-free-privilieged-access-management-solutions-buyers-guide\/\" target=\"_blank\" rel=\"noopener\"><img loading=\"lazy\" decoding=\"async\" class=\"alignleft size-full wp-image-1682\" title=\"\" src=\"https:\/\/solutionsreview.com\/identity-management\/files\/2020\/01\/PAM_BG_SB_800.gif\" alt=\"Download Link to Privileged Access Management Buyer's Guide\" width=\"800\" height=\"100\" \/><\/a><\/p>\n<\/div>\n\t\t<\/div><\/div><\/p>\n<p style=\"text-align: justify\"><span style=\"font-weight: 400\">You shouldn\u2019t consider orphaned accounts as just another contributor to your enterprise\u2019s network and active directory clutter. They could, can, and do represent potentially damaging attack vectors into your enterprise\u2019s IT environment. Orphaned accounts could allow hackers or insider threats to conceal their malicious activities for months, if not years.<\/span><\/p>\n<p style=\"text-align: justify\"><span style=\"font-weight: 400\">Why do orphaned accounts pose such a threat? What can you and your IT security team do to find and remove them? <\/span><\/p>\n<p style=\"text-align: justify\"><span style=\"font-weight: 400\">Here are some of our favorite suggestions: <\/span><\/p>\n<h3 style=\"text-align: justify\"><b>How Accounts Become Orphaned Accounts<\/b><span style=\"font-weight: 400\"> \u00a0<\/span><\/h3>\n<p style=\"text-align: justify\"><span style=\"font-weight: 400\">Understanding how orphaned accounts come into being must serve as the first step to preventing them from damaging your network and databases. What distinguishes accounts from orphaned accounts. \u00a0\u00a0<\/span><\/p>\n<p style=\"text-align: justify\"><span style=\"font-weight: 400\">The account forms the core of all of your users\u2019 identities. These accounts contain all the necessary identifying and supplemental data your network needs to authenticate your users in their day-to-day capacities. As such, accounts can contain usernames, legal names, passwords, phone numbers, emails, and more. The diversity of information embodied in an account can pose a threat on its own. <\/span><\/p>\n<p style=\"text-align: justify\"><span style=\"font-weight: 400\">Your IT team creates new accounts every time an employee or administrator joins your enterprise. This should come as no surprise; \u00a0without a relevant account, your employees wouldn\u2019t be able to perform their everyday digital duties. Logically, your IT team would remove these accounts once the employees or administrators in question leave the enterprise for whatever reason. <\/span><\/p>\n<p style=\"text-align: justify\"><span style=\"font-weight: 400\">Except, in reality, you can\u2019t always rely on your IT security team to remove the accounts at the end of their life-cycles. Everyday cybersecurity demands, constant workloads, and professional burnout combine to allow accounts to remain long after the deprovisioning process. Sometimes, the size of the enterprise network conceals old accounts from discovery. <\/span><\/p>\n<p style=\"text-align: justify\"><span style=\"font-weight: 400\">In short, these accounts linger on, abandoned both by their original owner and any other valid user. These become orphaned accounts. <\/span><\/p>\n<h3 style=\"text-align: justify\"><b>Why Orphaned Accounts Pose a Serious Risk<\/b><\/h3>\n<p style=\"text-align: justify\"><span style=\"font-weight: 400\">Orphaned accounts have no valid user, but they still exist in the network and have valid credentials. <\/span><\/p>\n<p style=\"text-align: justify\"><span style=\"font-weight: 400\">Therefore, they can still access resources like email and application logins. In cases of orphaned accounts from privileged users, these rogue credentials could continue to access proprietary or private data. <\/span><\/p>\n<p style=\"text-align: justify\"><span style=\"font-weight: 400\">Thus. if an external or internal threat actor was so inclined and could find the accounts lingering on the network, they could weaponize these orphaned accounts. In fact, with a legitimate but unclaimed account, the possibilities of what a hacker could do on your network prove overwhelming. A threat actor could, with orphaned accounts: <\/span><\/p>\n<ul style=\"text-align: justify\">\n<li style=\"font-weight: 400\"><span style=\"font-weight: 400\">Send a legitimate-looking email for their phishing attack, bypassing typical email security. <\/span><\/li>\n<li style=\"font-weight: 400\"><span style=\"font-weight: 400\">Access valuable databases or assets without raising security alerts or even suspicion, allowing for easy theft, transcription, or illicit interference.<\/span><\/li>\n<li style=\"font-weight: 400\"><span style=\"font-weight: 400\">Allow a dwelling threat onto the network like a cryptojacking malware.<\/span><\/li>\n<li style=\"font-weight: 400\"><span style=\"font-weight: 400\">Use the supplemental information in an account to intercept two-factor authentication protocols via SMS message.<\/span><\/li>\n<li style=\"font-weight: 400\"><span style=\"font-weight: 400\">Disrupt your business processes or change your digital policies without raising immediate suspicion. \u00a0\u00a0<\/span><\/li>\n<\/ul>\n<p style=\"text-align: justify\"><span style=\"font-weight: 400\">Individuals aware of their own orphaned accounts\u2014perhaps former employees who left in bad terms with your enterprise\u2014could maliciously use their former credentials even more easily. <\/span><\/p>\n<h3 style=\"text-align: justify\"><b>Do Orphaned Accounts Exist On Your Network? <\/b><\/h3>\n<p style=\"text-align: justify\"><span style=\"font-weight: 400\">Most likely, yes. According to the privileged access management solution provider Thycotic report \u201c2018 Global State of Privileged Access Management (PAM) Risk &amp; Compliance,\u201d 70% of enterprises fail to discover all of the privileged access accounts in their networks. 40% never even bother to look for all their network\u2019s privileged accounts. Moreover, 55% fail to revoke permissions after a privileged employee is removed.<\/span><\/p>\n<p style=\"text-align: justify\"><span style=\"font-weight: 400\">Most importantly, these findings only apply to <\/span><i><span style=\"font-weight: 400\">privileged accounts<\/span><\/i><span style=\"font-weight: 400\">, the most powerful credentials in your network. Obviously, the more insidious question follows: how many regular, workaday accounts receive this neglect as well? <\/span><\/p>\n<h3 style=\"text-align: justify\"><b>What Can You Do? <\/b><\/h3>\n<p style=\"text-align: justify\"><span style=\"font-weight: 400\">If your enterprise wants to remove the threat of orphaned accounts, it first needs to find them. Selecting and deploying an effective <a href=\"https:\/\/solutionsreview.com\/identity-management\/understanding-privileged-access-management-in-2019\/\" target=\"_blank\" rel=\"noopener\">privileged access management solution<\/a> must be your next step. <a href=\"https:\/\/solutionsreview.com\/identity-management\/key-findings-2018-privileged-access-management-magic-quadrant\/\" target=\"_blank\" rel=\"noopener\">PAM<\/a> solutions almost always come with tools to help you improve your identity visibility, helping your IT security team to locate and remove orphaned accounts still lingering in the network. <\/span><\/p>\n<p style=\"text-align: justify\"><span style=\"font-weight: 400\">Additionally, a <a href=\"https:\/\/solutionsreview.com\/identity-management\/centrify-magic-quadrant-privileged-access-management-2018\/\" target=\"_blank\" rel=\"noopener\">PAM solution<\/a> will also help relieve some of the burdens on your IT security team in the first place by automating the provisioning and deprovisioning process, preventing the birth of orphaned accounts in the first place. <\/span><\/p>\n<p style=\"text-align: justify\"><span style=\"font-weight: 400\">In conclusion, don\u2019t let your orphaned accounts become a pickpocket living in the alleys of your network. Keep a watchful eye out with a privileged access management solution. \u00a0\u00a0\u00a0\u00a0\u00a0<\/span><\/p>\n<p style=\"text-align: justify\"><br \/>Widget not in any sidebars<br \/><\/p>\n","protected":false},"excerpt":{"rendered":"<p>While the name may appear adorable &#8211; like a digital Oliver Twist &#8211; orphaned accounts resemble Bill Sikes more than a ruddy-cheeked street urchin. You shouldn\u2019t consider orphaned accounts as just another contributor to your enterprise\u2019s network and active directory clutter. They could, can, and do represent potentially damaging attack vectors into your enterprise\u2019s IT [&hellip;]<\/p>\n","protected":false},"author":41,"featured_media":3375,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"inline_featured_image":false,"footnotes":""},"categories":[5],"tags":[142,125,16,112,76,70,124,90,25,179],"acf":[],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v23.5 - https:\/\/yoast.com\/wordpress\/plugins\/seo\/ -->\n<title>Want Better Identity Management? Remove your Orphaned Accounts<\/title>\n<meta name=\"description\" content=\"While the name may appear adorable - like a digital Oliver Twist - orphaned accounts resemble Bill Sikes more than a ruddy-cheeked street urchin.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/solutionsreview.com\/identity-management\/want-better-identity-management-remove-your-orphaned-accounts\/\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Ben Canner\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"4 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\/\/schema.org\",\"@graph\":[{\"@type\":\"WebPage\",\"@id\":\"https:\/\/solutionsreview.com\/identity-management\/want-better-identity-management-remove-your-orphaned-accounts\/\",\"url\":\"https:\/\/solutionsreview.com\/identity-management\/want-better-identity-management-remove-your-orphaned-accounts\/\",\"name\":\"Want Better Identity Management? Remove your Orphaned Accounts\",\"isPartOf\":{\"@id\":\"https:\/\/solutionsreview.com\/identity-management\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\/\/solutionsreview.com\/identity-management\/want-better-identity-management-remove-your-orphaned-accounts\/#primaryimage\"},\"image\":{\"@id\":\"https:\/\/solutionsreview.com\/identity-management\/want-better-identity-management-remove-your-orphaned-accounts\/#primaryimage\"},\"thumbnailUrl\":\"https:\/\/solutionsreview.com\/identity-management\/files\/2018\/07\/privileged-access-management-MOD.jpg\",\"datePublished\":\"2019-01-15T16:14:47+00:00\",\"dateModified\":\"2019-01-15T16:14:47+00:00\",\"author\":{\"@id\":\"https:\/\/solutionsreview.com\/identity-management\/#\/schema\/person\/357f925262827fcf840b4341920a1541\"},\"description\":\"While the name may appear adorable - like a digital Oliver Twist - orphaned accounts resemble Bill Sikes more than a ruddy-cheeked street urchin.\",\"breadcrumb\":{\"@id\":\"https:\/\/solutionsreview.com\/identity-management\/want-better-identity-management-remove-your-orphaned-accounts\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\/\/solutionsreview.com\/identity-management\/want-better-identity-management-remove-your-orphaned-accounts\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/solutionsreview.com\/identity-management\/want-better-identity-management-remove-your-orphaned-accounts\/#primaryimage\",\"url\":\"https:\/\/solutionsreview.com\/identity-management\/files\/2018\/07\/privileged-access-management-MOD.jpg\",\"contentUrl\":\"https:\/\/solutionsreview.com\/identity-management\/files\/2018\/07\/privileged-access-management-MOD.jpg\",\"width\":800,\"height\":425,\"caption\":\"Top-Tier Password Best Practices for World Password Day 2021\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\/\/solutionsreview.com\/identity-management\/want-better-identity-management-remove-your-orphaned-accounts\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\/\/solutionsreview.com\/identity-management\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Want Better Identity Management? Remove your Orphaned Accounts\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\/\/solutionsreview.com\/identity-management\/#website\",\"url\":\"https:\/\/solutionsreview.com\/identity-management\/\",\"name\":\"Best Identity Access Management (IAM) Software, Tools, Vendors, Solutions, &amp; Services\",\"description\":\"Identity Access Management (IAM) News, Best Practices and Buyer&#039;s Guide\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\/\/solutionsreview.com\/identity-management\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Person\",\"@id\":\"https:\/\/solutionsreview.com\/identity-management\/#\/schema\/person\/357f925262827fcf840b4341920a1541\",\"name\":\"Ben Canner\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/solutionsreview.com\/identity-management\/#\/schema\/person\/image\/\",\"url\":\"https:\/\/secure.gravatar.com\/avatar\/63f68345052a446ce0cc9c802dd3f373?s=96&d=mm&r=g\",\"contentUrl\":\"https:\/\/secure.gravatar.com\/avatar\/63f68345052a446ce0cc9c802dd3f373?s=96&d=mm&r=g\",\"caption\":\"Ben Canner\"},\"description\":\"Ben Canner is an enterprise technology writer and analyst covering Identity Management, SIEM, Endpoint Protection, and Cybersecurity writ large. He holds a Bachelor of Arts Degree in English from Clark University in Worcester, MA. He previously worked as a corporate blogger and ghost writer. You can reach him via Twitter and LinkedIn.\",\"url\":\"https:\/\/solutionsreview.com\/identity-management\/author\/bcanner\/\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Want Better Identity Management? Remove your Orphaned Accounts","description":"While the name may appear adorable - like a digital Oliver Twist - orphaned accounts resemble Bill Sikes more than a ruddy-cheeked street urchin.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/solutionsreview.com\/identity-management\/want-better-identity-management-remove-your-orphaned-accounts\/","twitter_misc":{"Written by":"Ben Canner","Est. reading time":"4 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"WebPage","@id":"https:\/\/solutionsreview.com\/identity-management\/want-better-identity-management-remove-your-orphaned-accounts\/","url":"https:\/\/solutionsreview.com\/identity-management\/want-better-identity-management-remove-your-orphaned-accounts\/","name":"Want Better Identity Management? Remove your Orphaned Accounts","isPartOf":{"@id":"https:\/\/solutionsreview.com\/identity-management\/#website"},"primaryImageOfPage":{"@id":"https:\/\/solutionsreview.com\/identity-management\/want-better-identity-management-remove-your-orphaned-accounts\/#primaryimage"},"image":{"@id":"https:\/\/solutionsreview.com\/identity-management\/want-better-identity-management-remove-your-orphaned-accounts\/#primaryimage"},"thumbnailUrl":"https:\/\/solutionsreview.com\/identity-management\/files\/2018\/07\/privileged-access-management-MOD.jpg","datePublished":"2019-01-15T16:14:47+00:00","dateModified":"2019-01-15T16:14:47+00:00","author":{"@id":"https:\/\/solutionsreview.com\/identity-management\/#\/schema\/person\/357f925262827fcf840b4341920a1541"},"description":"While the name may appear adorable - like a digital Oliver Twist - orphaned accounts resemble Bill Sikes more than a ruddy-cheeked street urchin.","breadcrumb":{"@id":"https:\/\/solutionsreview.com\/identity-management\/want-better-identity-management-remove-your-orphaned-accounts\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/solutionsreview.com\/identity-management\/want-better-identity-management-remove-your-orphaned-accounts\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/solutionsreview.com\/identity-management\/want-better-identity-management-remove-your-orphaned-accounts\/#primaryimage","url":"https:\/\/solutionsreview.com\/identity-management\/files\/2018\/07\/privileged-access-management-MOD.jpg","contentUrl":"https:\/\/solutionsreview.com\/identity-management\/files\/2018\/07\/privileged-access-management-MOD.jpg","width":800,"height":425,"caption":"Top-Tier Password Best Practices for World Password Day 2021"},{"@type":"BreadcrumbList","@id":"https:\/\/solutionsreview.com\/identity-management\/want-better-identity-management-remove-your-orphaned-accounts\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/solutionsreview.com\/identity-management\/"},{"@type":"ListItem","position":2,"name":"Want Better Identity Management? Remove your Orphaned Accounts"}]},{"@type":"WebSite","@id":"https:\/\/solutionsreview.com\/identity-management\/#website","url":"https:\/\/solutionsreview.com\/identity-management\/","name":"Best Identity Access Management (IAM) Software, Tools, Vendors, Solutions, &amp; Services","description":"Identity Access Management (IAM) News, Best Practices and Buyer&#039;s Guide","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/solutionsreview.com\/identity-management\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Person","@id":"https:\/\/solutionsreview.com\/identity-management\/#\/schema\/person\/357f925262827fcf840b4341920a1541","name":"Ben Canner","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/solutionsreview.com\/identity-management\/#\/schema\/person\/image\/","url":"https:\/\/secure.gravatar.com\/avatar\/63f68345052a446ce0cc9c802dd3f373?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/63f68345052a446ce0cc9c802dd3f373?s=96&d=mm&r=g","caption":"Ben Canner"},"description":"Ben Canner is an enterprise technology writer and analyst covering Identity Management, SIEM, Endpoint Protection, and Cybersecurity writ large. He holds a Bachelor of Arts Degree in English from Clark University in Worcester, MA. He previously worked as a corporate blogger and ghost writer. You can reach him via Twitter and LinkedIn.","url":"https:\/\/solutionsreview.com\/identity-management\/author\/bcanner\/"}]}},"_links":{"self":[{"href":"https:\/\/solutionsreview.com\/identity-management\/wp-json\/wp\/v2\/posts\/4159"}],"collection":[{"href":"https:\/\/solutionsreview.com\/identity-management\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/solutionsreview.com\/identity-management\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/solutionsreview.com\/identity-management\/wp-json\/wp\/v2\/users\/41"}],"replies":[{"embeddable":true,"href":"https:\/\/solutionsreview.com\/identity-management\/wp-json\/wp\/v2\/comments?post=4159"}],"version-history":[{"count":0,"href":"https:\/\/solutionsreview.com\/identity-management\/wp-json\/wp\/v2\/posts\/4159\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/solutionsreview.com\/identity-management\/wp-json\/wp\/v2\/media\/3375"}],"wp:attachment":[{"href":"https:\/\/solutionsreview.com\/identity-management\/wp-json\/wp\/v2\/media?parent=4159"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/solutionsreview.com\/identity-management\/wp-json\/wp\/v2\/categories?post=4159"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/solutionsreview.com\/identity-management\/wp-json\/wp\/v2\/tags?post=4159"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}