← Back to PAM Best Practice main site
PAM Academy › Module 3 — Discovery & Assessment

Module 3: Discovery & Assessment

Priya hunts down every privileged account at Abby Steel, including AI identities, records each one in full and ranks it by risk.

Story: “The Hunt”
~82 minutes
Lead: Priya, Senior Security Analyst
DiscoveryRisk AssessmentService AccountsAI AgentsActive Directory
Included
Part of the PAM Best Practice Academy curriculum
Start Module 3 → ← Back to Module 2
  • 7-part narrated slide module
  • Follows Priya at Abby Steel
  • Practical, vendor-neutral PAM guidance
  • Key facts and real-world examples
  • 10-question knowledge check
Overview
Curriculum
Instructors
3
Module Number
7
Story Parts
82
Minutes
10
Quiz Questions
The question this module answers
What privileged access do we actually have, and how risky is it?

Layla hands Priya one instruction: find it, all of it. Priya works through nine discovery sources, from access control lists and Active Directory to logs and interviews. She sets one rule, collect once and audit forever, and follows it for every account, including the AI identities nobody hired. Six weeks later, 312 privileged accounts that nobody had on any list are recorded, owned and ranked by risk.

What you will learn
▶
Explain why discovery and assessment is the foundation of a PAM programme
▶
Identify the nine discovery sources and what each reveals about privileged access
▶
Capture a complete record for every privileged account using the four layers: account and asset, JML linkage, access patterns and password reality
▶
Recognise AI-related privileged access, including delegated assistants, autonomous agents, integrations, embedded vendor features and shadow AI, and record it in the same inventory
▶
Categorise privileged accounts by risk using reach, privilege level, state and, for non-human holders, autonomy
Module curriculum
1
Part 1: Why Discovery Comes First
Narrated slides
2
Part 2: Collect Once, Audit Forever
Narrated slides
3
Part 3: The Sources: ACLs, Roles, User Lists and Permissions
Narrated slides
4
Part 4: The AI Layer of Privileged Access
Narrated slides
5
Part 5: Active Directory, IAM and Best Practice
Narrated slides
6
Part 6: Assessment: Risk, Logs, Reviews and People
Narrated slides
7
Part 7: The Record, the Tally and the Handover
Narrated slides
8
Knowledge Check10 questions · pass mark 8/10
Quiz
Part 1: Why Discovery Comes First

Discovery and assessment means identifying, categorising and assessing every privileged account and access path. It is the ground the strategy, controls and programme scope stand on.

Part 2: Collect Once, Audit Forever

Priya's rule: capture four layers for every account in one pass (account and asset, JML linkage, access patterns, password reality), so reviews, audits and incidents never have to start again from scratch.

Part 3: The Sources: ACLs, Roles, User Lists and Permissions

Access control lists, role-based analysis reviews, privileged user lists and user and group permission reviews reveal special permissions, inherited rights and privilege creep. Each comes with a real-world case study.

Part 4: The AI Layer of Privileged Access

At survey depth: AI as a lens on the data, as a holder of privilege, as a break in the four-layer record, as a new part of the estate, as unapproved shadow AI and as an attacker capability. The test throughout is: if it can log in, it goes in the book.

Part 5: Active Directory, IAM and Best Practice

Active Directory and the IAM system provide privileged account identification, group nesting, dormant accounts and lifecycle data. A field guide covers automation, risk-based priorities, clear ownership and continuous assessment.

Part 6: Assessment: Risk, Logs, Reviews and People

Accounts are categorised by risk, then SIEM and syslog data, user access reviews and interviews with privileged users show how access is actually used. Interview accounts are checked against the records.

Part 7: The Record, the Tally and the Handover

Account, asset and application records are joined into one inventory. The final tally of 312 unlisted privileged accounts goes to Layla, and Omar takes the risk-ranked list into Module 4.

Key facts
  • Anthem (2015): spear-phishing emails sent to five employees led, through a poorly defended Active Directory, to the theft of personal information on nearly 78.8 million people.
  • Uber: login credentials for its cloud storage were found embedded in code on GitHub, leading to a breach affecting 57 million users.
  • US Office of Personnel Management: a breach traced to a contractor's credentials with more privilege than the work required exposed data on around 22 million people.
  • Adobe (2013): information on almost 38 million active users was stolen; the company had SIEM tooling, but the alert was likely lost in the noise.
  • Capital One (2019): a misconfigured web application firewall enabled a server-side request forgery attack affecting over 100 million customers.
  • LinkedIn: a breach that began in 2012 was not fully understood until 2016, when credentials for about 167 million users appeared for sale.
Knowledge Check
Q1: Under Priya's 'collect once, audit forever' rule, which of these is NOT one of the four layers captured for every privileged account?
The JML linkage: the named owner and their joiner-mover-leaver status
The access patterns: when, where from, how often and for what
The account's purchase cost and licence renewal date
The password reality: actual age, rotation history and whether it is vaulted
Q2: What is Priya's test for whether an identity belongs in the privileged access inventory?
Can it authenticate, and can it act?
Is it listed in the HR system?
Is it labelled as artificial intelligence?
Was it approved through a change request?
Q3: What role does artificial intelligence play in Priya's discovery work?
It replaces the analyst and the business owner
It automatically revokes suspicious access without review
It is only useful once the programme is fully mature
It finds, prioritises and explains findings, but people decide who holds privilege
Q4: Why did user and group permission reviews become a key source for spotting hidden privilege?
They list every device on the domain
They reveal inherited permissions through group membership: privilege nobody granted directly, so nobody remembers it
They record every command a user executes
They replace the need for access reviews
Q5: In the Attacker's Lens scene, why does the module treat the identity-verification (password and MFA reset) process as privileged access?
Because help-desk staff are always domain administrators
Because reset processes are covered by GDPR
Because whoever can reset a privileged user's password or re-enrol their MFA effectively holds privileged access, and synthetic voice makes a phone call weak proof of identity
Because reset requests are logged in the SIEM
Q6: Priya scores each account on its reach, its level of privilege and its state. What fourth question does she add when the holder isn't a person?
How much can it do without asking?
Which vendor built it?
How much did it cost to deploy?
Is it hosted in the cloud?
Q7: What is the main lesson of the Adobe (2013) case study?
SIEM tools are unnecessary if you have antivirus
Zero-day exploits cannot be detected
Logs should be deleted regularly to reduce noise
A SIEM is only as good as its configuration and the trained people interpreting its most significant alerts
Q8: How did attackers get the credentials used in the Uber breach described in this module?
From a former employee's account that was never disabled
From login credentials for Uber's cloud storage embedded in code on GitHub
Through a brute-force attack on the VPN
Through a compromised heating and air-conditioning contractor
Q9: When interviewing privileged users, what caveat does the module give?
Only interview senior managers
Never let interviewees know why they are being asked
Corroborate what people tell you against logs and records, because memory is a source, not an oracle
Treat interview answers as more reliable than any scan
Q10: What does the OPM case study show about risk categorisation?
Contractors should never be given accounts
Risk categorisation matters only for regulatory reporting
All accounts should receive equal monitoring
An uncategorised high-risk account gets the same limited attention as everything else; a list without risk ratings is a phone book
Requirements
Completion of Module 2 (recommended)
Basic understanding of IT administration or security concepts
Target audience: security and IT professionals, PAM practitioners and programme leads
No vendor-specific tool knowledge required — this module is vendor-neutral
Your instructors
NK
Nabeel Khaliq
IAM & Privileged Access Management SME · Founder, PAM Best Practice Ltd
Practitioner with deep hands-on experience implementing PAM across enterprise environments. Founder of PAM Best Practice Academy, a UK-registered education and community hub for PAM professionals. Arsenal and Middlesbrough fan.
AR
Adrian Russo
IAM & Privileged Access Management Architect
Senior PAM architect with extensive experience designing and deploying large-scale CyberArk and BeyondTrust implementations across enterprise environments globally. Keen cyclist.
ID
Iftikar Din
Manufacturing-focused Cyber Security Engineer
Cyber security engineer specialising in industrial and manufacturing environments. Brings real-world operational technology (OT) security perspective to PAM implementation. Middlesbrough fan who loves gardening.
Your progress
Module 3 — Discovery & Assessment
Not started0%
Module breakdown
Part 1: Why Discovery Comes FirstSlides
Part 2: Collect Once, Audit ForeverSlides
Part 3: The Sources: ACLs, Roles, User Lists and PermissionsSlides
Part 4: The AI Layer of Privileged AccessSlides
Part 5: Active Directory, IAM and Best PracticeSlides
Part 6: Assessment: Risk, Logs, Reviews and PeopleSlides
Part 7: The Record, the Tally and the HandoverSlides
Knowledge Check10 questions
Up next
Module 4 — Securing Privileged Access by Risk
In Module 4, Omar, Abby Steel's Infrastructure Security Architect, takes the risk-ranked inventory and decides which systems to protect first, and how.
PAM Community
Join our network of PAM practitioners, mentors and industry partners across the UK.