B14.2 Identity and Access Review Lab
Practice reviewing fictional identities, accounts, login events, MFA status, roles, permissions, ownership, least privilege, and documented access decisions.
Lesson Progress
Identity and Access Review Lab
High School Beginner • B14: Beginner Defensive Practice Labs • Lesson 2 of 7
Readiness Check
Before You Start
0/3 ready
Professional Hook
Most Access Problems Begin With One Unanswered Question: Does This Account Still Need This Permission?
Accounts change as people join, move roles, take leave, complete projects, or leave an organization. Defenders must regularly confirm who owns each identity, what it is for, how it authenticates, and whether its access still matches approved responsibilities.
Learning Objective
Explain identity, authentication, authorization, least privilege, role-based access, and access reviews.
Learning Objective
Evaluate fictional accounts for current need, ownership, MFA, unusual login activity, and permission fit.
Learning Objective
Choose and document safe actions such as keep, reduce, suspend, reset, investigate, or escalate.
Why This Matters
Old, Shared, or Over-Permissioned Accounts Create Avoidable Risk
Unused accounts, excessive privileges, shared credentials, and weak offboarding can allow inappropriate access or make investigations difficult. Regular reviews reduce exposure and improve accountability.
Visual Diagram
The Identity and Access Review Workflow
Strong access reviews connect identity, authentication, authorization, business need, evidence, ownership, and documented action.
Identify the account
Confirm the fictional user, service, owner, department, role, and account status.
Review authentication
Check MFA enrollment, login history, trusted devices, failed attempts, and unusual locations.
Review authorization
Compare assigned roles and permissions with the account's approved responsibilities.
Choose and document action
Keep, reduce, suspend, reset, investigate, or escalate access based on evidence and policy.
Core Concept
Access Should Follow Current Responsibility
A user's access should be tied to a current approved role or task. When that need changes, permissions should be reviewed and adjusted through an authorized process with evidence and clear ownership.
Key Vocabulary
Terms for Identity and Access Review
Identity
The digital representation of a person, service, device, or application in a system.
Authentication
The process of verifying that an identity is who or what it claims to be.
Authorization
The process of deciding which resources and actions an authenticated identity may access.
Least privilege
Giving an identity only the minimum access needed for its approved responsibilities.
Role-based access control
Assigning permissions based on a defined job, function, or responsibility rather than granting access individually without structure.
Access review
A periodic check of accounts, roles, permissions, ownership, MFA status, and continued business need.
Identity Review
Access Decision Board
Each decision should be based on current need, trusted evidence, least privilege, clear ownership, and approved process.
Identity status
Review question
Is the account active, inactive, temporary, shared, service-based, or no longer needed?
Strong defensive action
Verify ownership and current need before keeping, changing, or disabling access.
Authentication
Review question
Is MFA enabled, are devices expected, and do login patterns match approved activity?
Strong defensive action
Review trusted context and escalate unusual activity that cannot be verified.
Authorization
Review question
Do roles and permissions match the account's current responsibilities?
Strong defensive action
Remove unnecessary access and keep only documented, approved permissions.
Documentation
Review question
Can another reviewer understand the evidence, decision, owner, and next step?
Strong defensive action
Record the reason, approval, timestamp, evidence, and follow-up action clearly.
Fake Identity Dashboard
Account and Permission Review
This fictional panel compares account purpose, ownership, permissions, authentication status, and recommended action.
Teacher account
Active employee with course-management responsibilities
Keep standard teaching access and remove unrelated administrative permissions.
Former contractor
Contract ended 21 days ago; account remains enabled
Suspend the account, preserve evidence, confirm offboarding, and escalate the process gap.
Shared admin account
Used by four staff members with no individual accountability
Replace with named admin accounts, least privilege, MFA, and documented emergency access.
Student help-desk volunteer
Can view password-reset tickets but cannot approve resets
Appropriate if the role is documented, supervised, and limited to necessary ticket data.
Service account
Runs nightly reports and has interactive login enabled
Disable unnecessary interactive login, rotate credentials through approved processes, and confirm ownership.
Fake Dashboard
Fake Identity and Access Dashboard
Training dashboard using fictional users, roles, permissions, MFA status, login events, owners, and review decisions.
Accounts reviewed
42
Fictional employee, student, contractor, service, administrator, and temporary accounts.
Access reductions
8
Unnecessary administrative, reporting, storage, and support permissions were removed.
Accounts requiring escalation
5
Former users, shared admin access, unusual logins, and unowned service accounts.
Fake SOC Alert
Former Contractor Account Still Enabled
Source: Fake Identity Governance Monitor • Time: 9:26 AM
Fake Log Panel
Fake Access Review Log
08:45:02 ACCOUNT user='contractor_17' status='enabled' 08:48:19 OWNER department='facilities' contract_end='21_days_ago' 08:52:44 ACCESS groups='shared_files,reporting_tool' 08:57:31 AUTH mfa='enabled' last_login='2_days_ago' 09:03:08 BUSINESS_NEED manager_confirmed='none' 09:14:56 DECISION action='suspend_and_escalate' 09:26:11 CASE owner='identity_team' evidence='preserved'
Training note: this is fake data for defensive analysis practice only.
Analyze the Evidence
Should This Account Keep Its Current Access?
What is the strongest access-review decision?
Common Mistakes
Mistakes That Weaken Access Reviews
Safe Practice Lab
Review a Fictional Access Inventory
Fake Access Inventory
Community Learning Portal Accounts
A fictional inventory includes teacher, student, contractor, administrator, volunteer, guest, emergency, and service accounts with different MFA, ownership, login, and role details.
Review Steps
- Confirm the account type, owner, status, and business purpose.
- Review MFA, login history, device context, and unusual activity.
- Compare assigned roles with current responsibilities.
- Identify shared, inactive, excessive, temporary, or unowned access.
- Choose keep, reduce, suspend, reset, investigate, or escalate.
- Document evidence, approval, owner, timestamp, and follow-up.
Scenario Decision Lab
A Shared Administrator Account Is Used by Four Staff Members
A fictional support team uses one administrator account because it is easier than managing separate named accounts.
Scenario Decision Lab
An MFA Login Comes From an Unfamiliar Device
A fictional administrator account completes MFA from a new device and location with no approved travel or change record.
Defender Habits
Identity and Access Review Checklist
Check Your Understanding
B14.2 Mini Quiz: Identity and Access Review
Choose your answers first. Explanations appear only after submission.
1. What is least privilege?
2. What is the difference between authentication and authorization?
3. What should happen to an account belonging to a former contractor?
4. Why are shared administrator accounts risky?
5. What is the strongest access-review decision?
Portfolio Prompt
Portfolio Prompt
Create a one-page fictional identity and access review report. Include account type, owner, status, business purpose, MFA status, login evidence, assigned roles, excessive permissions, risk, decision, approval, owner, timestamp, and follow-up action.
Key Takeaways
What You Should Remember
Navigation