Skip to content
Cloud Security DeskSearch
Menu

Research topic

Identity & access

Trust is a path, not a policy.

27 publications

Research on effective permissions, federation, workload identity, and the conditions that reshape cloud access.

View every topic

From the desk

27 publications
Technical guide · September 12, 2026 · Source-based analysis

Protect and recover your AWS root account

Protect AWS root access with MFA, current recovery contacts, separate daily administration, and a clear plan for Organizations member accounts.

Technical guide · September 12, 2026 · Source-based analysis

Remove unused AWS access keys without breaking a job

Review IAM access-key usage, find job dependencies, deactivate safely, and verify final deletion without collecting or exposing secret credentials.

Technical guide · September 12, 2026 · Source-based analysis

Give Google Cloud teams access through IAM groups

Give Google Cloud teams IAM access through owned groups, choose a sensible resource scope, and verify migration and removal with practical checks.

Technical guide · September 12, 2026 · Source-based analysis

Connect to a Google Cloud VM with IAP and OS Login

Connect to a Linux VM through IAP and OS Login, check each permission and network layer, and remove old SSH paths with a tested recovery plan.

Technical guide · September 12, 2026 · Source-based analysis

Give Azure readers access to one resource group

Assign Reader without granting write access or assuming it grants data access.

Technical guide · September 12, 2026 · Source-based analysis

Read an Azure Key Vault secret from a VM without a password

Set up one system-assigned VM identity and a vault-scoped secret permission.

Technical guide · September 2, 2026 · Source-based analysis

Design application authorization before writing Cedar policies

Define business actions, trustworthy entities and tenant boundaries before writing Cedar policies, then make the application responsible for enforcing the resulting decision.

Technical guide · September 2, 2026 · Source-based analysis

Set explicit trust boundaries for Entra partner access

Accepting another tenant’s authentication claims is a specific trust decision, not blanket approval of its users, devices or access to your applications.

Technical guide · September 2, 2026 · Source-based analysis

Bind OAuth tokens to the client that presents them

DPoP can make possession of an access token insufficient for use, provided the issuer, client and resource server implement the same proof and key-binding contract.

Technical guide · September 2, 2026 · Source-based analysis

Keep S3 presigned access inside an explicit delegation window

Treat an S3 presigned URL as a reusable delegation whose usable lifetime depends on the signer, the request and the policies that still apply.

Technical guide · September 2, 2026 · Source-based analysis

Prove Identity Center permission changes reached every account

A permission-set change is complete only when the intended accounts, account-local policies, provisioning results and assignments have converged.

Technical guide · September 2, 2026 · Source-based analysis

Restrict device code sign-in without breaking approved clients

Restrict device-code authentication through an explicit client and resource policy, and test the tracked sessions that can outlive the initial browser approval.

Technical guide · August 28, 2026 · Source-based analysis

Passkey deployment needs a recovery design

A workforce passkey rollout needs a recovery contract before broad enforcement. Separate credential custody, enrollment evidence and application sessions.

Technical guide · August 28, 2026 · Source-based analysis

Workload federation across clouds needs separate trust decisions

Cross-cloud federation adds trust decisions, not a portable permission system. Map each credential and resource grant before moving a runtime workload.

Technical guide · August 28, 2026 · Source-based analysis

Entra emergency access that survives normal sign-in failure

A second administrator account does not prove an independent recovery path. Test the credential, workstation, policy and alert dependencies together.

Technical guide · August 28, 2026 · Source-based analysis

Rotate Entra application certificates with proof of adoption

A renewed certificate can exist in Key Vault while a running client still uses the old key. Define the evidence that makes application rotation complete.

Technical guide · August 28, 2026 · Source-based analysis

Short SSH certificates still need explicit access boundaries

An SSH certificate supplies bounded identity claims. The issuer, server, client and incident operator still make separate access decisions.

Technical guide · August 28, 2026 · Source-based analysis

Measure SCIM offboarding at the application

A successful provisioning update proves a directory action, not the end of every application session. Define and test the application's offboarding contract.

Technical guide · Published August 28, 2026 · Source-based analysisSeries July 25, 2026

Trace Google service account impersonation across every hop

A short-lived token can carry a broad identity. Review who can mint it, which account it represents and whether the original caller remains visible.

Research note · Published August 28, 2026 · Source-based analysisSeries June 15, 2026

Place AWS guardrails on the principal and the resource

SCPs and RCPs constrain different sides of a request. A useful review records both the applicable guardrails and the policies that actually grant access.

Technical guide · Published August 28, 2026 · Source-based analysisSeries May 6, 2026

Review the authority behind every Entra app consent

The permission name is only part of the decision. Review the access mode, resource scope, consenting authority and people who can change the application.

Research note · Published August 28, 2026 · Source-based analysisSeries March 27, 2026

Define the expiry boundary for Entra privileged access

PIM records activation and expiry, but the protected application still determines when changed authority takes effect. Review both sides of that boundary.

Technical guide · Published August 28, 2026 · Source-based analysisSeries February 15, 2026

Close the AWS sessions that survive identity shutdown

Removing a login does not by itself establish that issued AWS credentials have lost their authority. Build a revocation procedure that accounts for both.

Technical guide · Published August 28, 2026 · Source-based analysisSeries January 6, 2026

Lock GitHub deployment trust to the job you intend

A short-lived token still needs a narrow trust decision. Review the subject, deployment environment, reusable workflow and AWS role together.

Questions answered

  1. What does Cloud Security Desk cover under Identity & access?

    Research on effective permissions, federation, workload identity, and the conditions that reshape cloud access.

    Supporting context

    Trust is a path, not a policy.

  2. Why does the identity & access topic matter to cloud security?

    Trust is a path, not a policy. This topic applies that principle to practical control evidence and review decisions.

  3. Which control questions belong to Identity & access?

    Research belongs here when its central evidence, failure mode, or operational decision falls within the identity & access boundary described on this page.

  4. How many identity & access publications are available?

    This page currently lists 27 publications assigned to Identity & access.

  5. How should readers use the Identity & access research?

    Start with the publication closest to the control, platform, or evidence gap under review, then follow its findings, limitations, numbered sources, related work, and downloadable material.

  6. Can identity & access overlap other research topics?

    Yes. A publication can appear under several topics when one evidence path crosses multiple control boundaries; each publication page identifies its complete scope.

    Supporting context