All Posts

Best Practices

7 min

 read

Zero Standing Privileges – No Permanent Admin Rights in PAM

Permanent admin rights are one of the largest attack surfaces in any network. Zero Standing Privileges (ZSP) removes them with just-in-time access, least privilege, and automatic revocation. What the model is, and how to implement it with VISULOX.

Jan Zeppernick - Amitego CEO

Jan Zeppernick

Management

Published

03 Sep 2025

Aktualisiert

25 Sep 2026

Introduction

In many organizations, unused or over-provisioned accounts with permanently assigned administrator rights are quietly sitting around, so-called standing privileges. They enlarge the attack surface considerably: every permanent admin account is an open door that an attacker can use immediately after a stolen password or a compromised service-provider connection.

Zero Standing Privileges (ZSP) inverts this principle: no account holds rights permanently. Access is granted only when needed, only for the specific task, and only for its duration. This article explains the model, its four principles, and its benefits and shows how to implement ZSP in practice with a remote PAM platform like VISULOX.

Key Takeaways

  • ‍
    • Standing privileges  permanently assigned admin rights  are one of the largest and most frequently overlooked attack surfaces in corporate networks.
    • Zero Standing Privileges (ZSP) is based on Zero Trust: no account holds rights by default; every access is verified individually and time-limited.
    • Four principles carry the model: Zero Access by Default, Just-in-Time Access (JIT), Just-Enough Access (JEA), and automatic privilege revocation.
    • ZSP reduces the attack surface, mitigates insider threats, and produces gap-free audit trails for GDPR, NIS-2, and DORA.
    • ZSP is not a standalone project but the evolution of an existing PAM program, best implemented with automated JIT workflows and MFA.
    • VISULOX implements ZSP technically: just-in-time approvals, least privilege per system, and audit-proof session recording, agentless, productive in under two days.
  • What are standing privileges and why are they a risk?

    Standing privileges are permanently assigned privileged rights: administrator accounts, service accounts, or service-provider access paths that remain active around the clock — regardless of whether they are currently needed. In practice, such accounts accumulate over the years: rights are granted for a project and never revoked, service providers keep access long after a contract ends, and service accounts run in the background with far-reaching rights.

    Each of these accounts is an open door. If a password is stolen, an endpoint is compromised, or a service provider is attacked, the attacker immediately has privileged access at hand — without having to escalate rights themselves. This is precisely why, according to recent breach analyses, privileged accounts are involved in a large share of serious security incidents.

    What does Zero Standing Privileges mean?

    Zero Standing Privileges is a security model based on the Zero Trust principle. No account holds rights by default; with every request, privileged access must be verified, validated, and time-limited. User, system, or application accounts receive only the minimum rights required (least privilege) and lose them automatically as soon as they are no longer needed.

    The difference from classic PAM is fundamental: conventional privileged access management manages and protects permanent entitlements — ZSP abolishes them. Instead of securing a password vault for permanently existing admin accounts, privileged access only exists at the moment it is used.

    The four principles of ZSP

    Four principles define Zero Standing Privileges:

    • Zero Access by Default: Every access starts with no rights. Permissions are granted only when a concrete task exists, and removed again afterwards.
    • Just-in-Time Access (JIT): Privileged access is granted dynamically when needed and revoked immediately after use.
    • Just-Enough Access (JEA): The granted rights are strictly limited to what the task requires — no more.
    • Automatic privilege revocation: Once the work is completed, all permissions are withdrawn immediately, so that no permanently idle admin accounts remain.

    The benefits of Zero Standing Privileges

    • Protection against insider threats: Through time-limited permissions, ZSP minimizes the risk of malicious or negligent insiders.
    • Reduced attack surface: The combination of JIT and JEA policies restricts unauthorized access and significantly shrinks the attack surface.
    • Regulatory compliance: Temporary permissions and gap-free logging create meaningful audit trails that help with GDPR, NIS-2, or DORA audits.

    Implementing Zero Standing Privileges in practice

    Zero Standing Privileges should not be treated as an isolated project, but as the logical evolution of an existing privileged access management program. Integrate ZSP into existing processes, replace static admin accounts with automated JIT workflows, and use multi-factor authentication for approval. This lowers risk while meeting current compliance requirements. The foundation is the principle of least privilege.

    VISULOX: implementing Zero Standing Privileges

    VISULOX implements Zero Standing Privileges consistently. Instead of permanent admin rights, internal users and external service providers receive access only through a central access point — time-limited, personalized, and recorded in an audit-proof way:

    • Just-in-time instead of permanent rights: Access exists only for the approved time window and is revoked automatically afterwards. There are no permanent credentials that could be hijacked.
    • Least privilege per system: Access only to the required target system — no blanket network access, no shared account.
    • Audit-proof session recording: Every privileged session is recorded without gaps — as evidence for GDPR, NIS-2, and DORA.
    • Agentless, in under two days: VISULOX is implemented without interrupting operations and connects to existing identity providers (SAML/OAuth).

    Contact

    Your Direct Path to Secure Remote Access

    Speak directly with a cybersecurity expert.

    Personal Meeting
    Personal Meeting
    Personal Meeting

    Conclusion

    Zero Standing Privileges is a core building block of modern security strategies. Replacing permanent admin rights with just-in-time access and least privilege not only reduces the attack surface it also improves auditability and prepares you for future regulatory requirements. With a remote PAM platform like VISULOX, the model can be implemented without rebuilding your infrastructure time-limited, verifiable, and productive in under two days.

    Frequently Asked Questions

    What are standing privileges?

    Standing privileges are permanently granted elevated rights: an administrator account that stays administrator around the clock even when it is used twice a month. They are convenient, which is why they are everywhere, but they enlarge the attack surface for the entire time nobody is using them.

    How does ZSP differ from just-in-time access?

    Just-in-time is the mechanism; zero standing privileges is the goal. JIT grants rights on request and withdraws them when the window closes. ZSP describes the resulting state: no account holds elevated rights at rest. JIT alone is not enough if permanent admin accounts still exist beside it.

    Does zero standing privileges work for service accounts?

    Partly. Interactive human access converts cleanly to just-in-time. Service and machine accounts need different mechanisms, such as short-lived tokens or a credential vault that rotates secrets and never exposes them. The principle is the same; the technical implementation differs.

    Does zero standing privileges slow operations down?

    Only where the approval process is badly designed. What matters is that requesting and granting takes seconds rather than ticket turnaround times, and that recurring tasks have standing rules. Where approval becomes a bottleneck, administrators route around it and the security gain disappears.

    Jan Zeppernick - Amitego CEO

    Jan Zeppernick

    Management

    Jan has over 12 years of consulting experience at PwC and Ernst & Young, focusing on information security and compliance for critical infrastructure and the automotive industry. As a certified ISO 27001 Lead Auditor and strategy expert, he advises organizations on establishing and auditing security management systems in accordance with ISO 27001 and TISAX.