High School BeginnerModule B14Lesson 2 of 7

B14.2 Identity and Access Review Lab

Practice reviewing fictional identities, accounts, login events, MFA status, roles, permissions, ownership, least privilege, and documented access decisions.

Lesson Progress

Identity and Access Review Lab

High School BeginnerB14: Beginner Defensive Practice Labs • Lesson 2 of 7

29% complete

Readiness Check

Before You Start

0/3 ready

Professional Hook

Most Access Problems Begin With One Unanswered Question: Does This Account Still Need This Permission?

Accounts change as people join, move roles, take leave, complete projects, or leave an organization. Defenders must regularly confirm who owns each identity, what it is for, how it authenticates, and whether its access still matches approved responsibilities.

Lab safety reminder: do not use real usernames, passwords, MFA codes, student records, employee records, or live account details. All evidence in this lab is fictional.

Learning Objective

Explain identity, authentication, authorization, least privilege, role-based access, and access reviews.

Learning Objective

Evaluate fictional accounts for current need, ownership, MFA, unusual login activity, and permission fit.

Learning Objective

Choose and document safe actions such as keep, reduce, suspend, reset, investigate, or escalate.

Why This Matters

Old, Shared, or Over-Permissioned Accounts Create Avoidable Risk

Unused accounts, excessive privileges, shared credentials, and weak offboarding can allow inappropriate access or make investigations difficult. Regular reviews reduce exposure and improve accountability.

Visual Diagram

The Identity and Access Review Workflow

Strong access reviews connect identity, authentication, authorization, business need, evidence, ownership, and documented action.

1

Identify the account

Confirm the fictional user, service, owner, department, role, and account status.

2

Review authentication

Check MFA enrollment, login history, trusted devices, failed attempts, and unusual locations.

3

Review authorization

Compare assigned roles and permissions with the account's approved responsibilities.

4

Choose and document action

Keep, reduce, suspend, reset, investigate, or escalate access based on evidence and policy.

Access rule: access should reflect current approved responsibilities, not old assumptions or convenience.

Core Concept

Access Should Follow Current Responsibility

A user's access should be tied to a current approved role or task. When that need changes, permissions should be reviewed and adjusted through an authorized process with evidence and clear ownership.

Key Vocabulary

Terms for Identity and Access Review

Identity

The digital representation of a person, service, device, or application in a system.

Authentication

The process of verifying that an identity is who or what it claims to be.

Authorization

The process of deciding which resources and actions an authenticated identity may access.

Least privilege

Giving an identity only the minimum access needed for its approved responsibilities.

Role-based access control

Assigning permissions based on a defined job, function, or responsibility rather than granting access individually without structure.

Access review

A periodic check of accounts, roles, permissions, ownership, MFA status, and continued business need.

Identity Review

Access Decision Board

Each decision should be based on current need, trusted evidence, least privilege, clear ownership, and approved process.

Identity status

Review question

Is the account active, inactive, temporary, shared, service-based, or no longer needed?

Strong defensive action

Verify ownership and current need before keeping, changing, or disabling access.

Authentication

Review question

Is MFA enabled, are devices expected, and do login patterns match approved activity?

Strong defensive action

Review trusted context and escalate unusual activity that cannot be verified.

Authorization

Review question

Do roles and permissions match the account's current responsibilities?

Strong defensive action

Remove unnecessary access and keep only documented, approved permissions.

Documentation

Review question

Can another reviewer understand the evidence, decision, owner, and next step?

Strong defensive action

Record the reason, approval, timestamp, evidence, and follow-up action clearly.

Fake Identity Dashboard

Account and Permission Review

This fictional panel compares account purpose, ownership, permissions, authentication status, and recommended action.

Fake Data

Teacher account

Active employee with course-management responsibilities

Keep standard teaching access and remove unrelated administrative permissions.

Former contractor

Contract ended 21 days ago; account remains enabled

Suspend the account, preserve evidence, confirm offboarding, and escalate the process gap.

Shared admin account

Used by four staff members with no individual accountability

Replace with named admin accounts, least privilege, MFA, and documented emergency access.

Student help-desk volunteer

Can view password-reset tickets but cannot approve resets

Appropriate if the role is documented, supervised, and limited to necessary ticket data.

Service account

Runs nightly reports and has interactive login enabled

Disable unnecessary interactive login, rotate credentials through approved processes, and confirm ownership.

Fake Dashboard

Fake Identity and Access Dashboard

Training dashboard using fictional users, roles, permissions, MFA status, login events, owners, and review decisions.

Accounts reviewed

42

Fictional employee, student, contractor, service, administrator, and temporary accounts.

Access reductions

8

Unnecessary administrative, reporting, storage, and support permissions were removed.

Accounts requiring escalation

5

Former users, shared admin access, unusual logins, and unowned service accounts.

Fake SOC Alert

Former Contractor Account Still Enabled

Source: Fake Identity Governance Monitor • Time: 9:26 AM

High Severity
A fictional contractor account remains active 21 days after the contract ended and still has access to shared files and an internal reporting tool.
Defensive recommendation: Suspend the account through the approved process, preserve login evidence, confirm ownership and offboarding status, and escalate the process failure.

Fake Log Panel

Fake Access Review Log

training-log-viewer.log
08:45:02 ACCOUNT user='contractor_17' status='enabled'
08:48:19 OWNER department='facilities' contract_end='21_days_ago'
08:52:44 ACCESS groups='shared_files,reporting_tool'
08:57:31 AUTH mfa='enabled' last_login='2_days_ago'
09:03:08 BUSINESS_NEED manager_confirmed='none'
09:14:56 DECISION action='suspend_and_escalate'
09:26:11 CASE owner='identity_team' evidence='preserved'

Training note: this is fake data for defensive analysis practice only.

Analyze the Evidence

Should This Account Keep Its Current Access?

A fictional teacher account is active and still employed.
The account has normal teaching access plus system-wide user administration.
The teacher's role does not include account administration.
No approval record explains the extra permission.

What is the strongest access-review decision?

Common Mistakes

Mistakes That Weaken Access Reviews

Keeping access because an account has always had it.
Assuming MFA alone proves every login is safe.
Using shared administrator accounts for convenience.
Leaving former users, contractors, or temporary accounts enabled.
Granting broad permissions when a narrower role would work.
Removing access without documenting evidence, ownership, approval, or business impact.

Safe Practice Lab

Review a Fictional Access Inventory

Fake Access Inventory

Community Learning Portal Accounts

A fictional inventory includes teacher, student, contractor, administrator, volunteer, guest, emergency, and service accounts with different MFA, ownership, login, and role details.

Review Steps

  • Confirm the account type, owner, status, and business purpose.
  • Review MFA, login history, device context, and unusual activity.
  • Compare assigned roles with current responsibilities.
  • Identify shared, inactive, excessive, temporary, or unowned access.
  • Choose keep, reduce, suspend, reset, investigate, or escalate.
  • Document evidence, approval, owner, timestamp, and follow-up.

Scenario Decision Lab

A Shared Administrator Account Is Used by Four Staff Members

A fictional support team uses one administrator account because it is easier than managing separate named accounts.

Scenario Decision Lab

An MFA Login Comes From an Unfamiliar Device

A fictional administrator account completes MFA from a new device and location with no approved travel or change record.

Defender Habits

Identity and Access Review Checklist

Check Your Understanding

B14.2 Mini Quiz: Identity and Access Review

Choose your answers first. Explanations appear only after submission.

1. What is least privilege?

2. What is the difference between authentication and authorization?

3. What should happen to an account belonging to a former contractor?

4. Why are shared administrator accounts risky?

5. What is the strongest access-review decision?

Portfolio Prompt

Portfolio Prompt

Create a one-page fictional identity and access review report. Include account type, owner, status, business purpose, MFA status, login evidence, assigned roles, excessive permissions, risk, decision, approval, owner, timestamp, and follow-up action.

Use fictional names, accounts, devices, roles, login events, and organizations only.
Do not include real usernames, passwords, MFA codes, private records, or live account screenshots.
Explain why each access decision follows least privilege and current business need.

Key Takeaways

What You Should Remember

1.Authentication verifies identity; authorization determines permitted access.
2.Least privilege limits access to the minimum required for approved responsibilities.
3.Access reviews should confirm ownership, current need, MFA, login context, roles, and permissions.
4.Shared, inactive, excessive, suspicious, and unowned accounts require action or escalation.
5.Every access change should be supported by evidence, approval, documentation, and clear ownership.

Navigation

Continue Module B14