All Posts

Best Practices

7 min

 min read

Zero Standing Privileges – No Permanent Admin Rights in PAM

Permanent admin rights are one of the largest attack surfaces in any network. Zero Standing Privileges (ZSP) removes them with just-in-time access, least privilege, and automatic revocation. What the model is, and how to implement it with VISULOX.

Jan Zeppernick - Amitego CEO

Jan Zeppernick

Management

Introduction

In many organizations, unused or over-provisioned accounts with permanently assigned administrator rights are quietly sitting around, so-called standing privileges. They enlarge the attack surface considerably: every permanent admin account is an open door that an attacker can use immediately after a stolen password or a compromised service-provider connection.

Zero Standing Privileges (ZSP) inverts this principle: no account holds rights permanently. Access is granted only when needed, only for the specific task, and only for its duration. This article explains the model, its four principles, and its benefits and shows how to implement ZSP in practice with a remote PAM platform like VISULOX.

Key Takeaways

  • Standing privileges  permanently assigned admin rights  are one of the largest and most frequently overlooked attack surfaces in corporate networks.
  • Zero Standing Privileges (ZSP) is based on Zero Trust: no account holds rights by default; every access is verified individually and time-limited.
  • Four principles carry the model: Zero Access by Default, Just-in-Time Access (JIT), Just-Enough Access (JEA), and automatic privilege revocation.
  • ZSP reduces the attack surface, mitigates insider threats, and produces gap-free audit trails for GDPR, NIS-2, and DORA.
  • ZSP is not a standalone project but the evolution of an existing PAM program, best implemented with automated JIT workflows and MFA.
  • VISULOX implements ZSP technically: just-in-time approvals, least privilege per system, and audit-proof session recording, agentless, productive in under two days.
  • What are standing privileges and why are they a risk?

    Standing privileges are permanently assigned privileged rights: administrator accounts, service accounts, or service-provider access paths that remain active around the clock — regardless of whether they are currently needed. In practice, such accounts accumulate over the years: rights are granted for a project and never revoked, service providers keep access long after a contract ends, and service accounts run in the background with far-reaching rights.

    Each of these accounts is an open door. If a password is stolen, an endpoint is compromised, or a service provider is attacked, the attacker immediately has privileged access at hand — without having to escalate rights themselves. This is precisely why, according to recent breach analyses, privileged accounts are involved in a large share of serious security incidents.

    What does Zero Standing Privileges mean?

    Zero Standing Privileges is a security model based on the Zero Trust principle. No account holds rights by default; with every request, privileged access must be verified, validated, and time-limited. User, system, or application accounts receive only the minimum rights required (least privilege) and lose them automatically as soon as they are no longer needed.

    The difference from classic PAM is fundamental: conventional privileged access management manages and protects permanent entitlements — ZSP abolishes them. Instead of securing a password vault for permanently existing admin accounts, privileged access only exists at the moment it is used.

    The four principles of ZSP

    Four principles define Zero Standing Privileges:

    • Zero Access by Default: Every access starts with no rights. Permissions are granted only when a concrete task exists, and removed again afterwards.
    • Just-in-Time Access (JIT): Privileged access is granted dynamically when needed and revoked immediately after use.
    • Just-Enough Access (JEA): The granted rights are strictly limited to what the task requires — no more.
    • Automatic privilege revocation: Once the work is completed, all permissions are withdrawn immediately, so that no permanently idle admin accounts remain.

    The benefits of Zero Standing Privileges

    • Protection against insider threats: Through time-limited permissions, ZSP minimizes the risk of malicious or negligent insiders.
    • Reduced attack surface: The combination of JIT and JEA policies restricts unauthorized access and significantly shrinks the attack surface.
    • Regulatory compliance: Temporary permissions and gap-free logging create meaningful audit trails that help with GDPR, NIS-2, or DORA audits.

    Implementing Zero Standing Privileges in practice

    Zero Standing Privileges should not be treated as an isolated project, but as the logical evolution of an existing privileged access management program. Integrate ZSP into existing processes, replace static admin accounts with automated JIT workflows, and use multi-factor authentication for approval. This lowers risk while meeting current compliance requirements. The foundation is the principle of least privilege.

    VISULOX: implementing Zero Standing Privileges

    VISULOX implements Zero Standing Privileges consistently. Instead of permanent admin rights, internal users and external service providers receive access only through a central access point — time-limited, personalized, and recorded in an audit-proof way:

    • Just-in-time instead of permanent rights: Access exists only for the approved time window and is revoked automatically afterwards. There are no permanent credentials that could be hijacked.
    • Least privilege per system: Access only to the required target system — no blanket network access, no shared account.
    • Audit-proof session recording: Every privileged session is recorded without gaps — as evidence for GDPR, NIS-2, and DORA.
    • Agentless, in under two days: VISULOX is implemented without interrupting operations and connects to existing identity providers (SAML/OAuth).

    Contact

    Your Direct Path to Secure Remote Access

    Speak directly with a cybersecurity expert.

    Personal Meeting
    Personal Meeting
    Personal Meeting

    Conclusion

    Zero Standing Privileges is a core building block of modern security strategies. Replacing permanent admin rights with just-in-time access and least privilege not only reduces the attack surface it also improves auditability and prepares you for future regulatory requirements. With a remote PAM platform like VISULOX, the model can be implemented without rebuilding your infrastructure time-limited, verifiable, and productive in under two days.

    Jan Zeppernick - Amitego CEO

    Jan Zeppernick

    Management

    Jan verfügt über mehr als 12 Jahre Beratungserfahrung bei PwC und Ernst & Young, mit Schwerpunkt auf Informationssicherheit und Compliance für kritische Infrastrukturen und die Automobilbranche. Als zertifizierter ISO 27001 Lead Auditor und Strategieexperte berät er Organisationen beim Aufbau und der Auditierung von Sicherheitsmanagementsystemen nach ISO 27001 und TISAX.