Research topic
Identity & access
Trust is a path, not a policy.
Research on effective permissions, federation, workload identity, and the conditions that reshape cloud access.
View every topicFrom the desk
27 publicationsProtect and recover your AWS root account
Protect AWS root access with MFA, current recovery contacts, separate daily administration, and a clear plan for Organizations member accounts.
Remove unused AWS access keys without breaking a job
Review IAM access-key usage, find job dependencies, deactivate safely, and verify final deletion without collecting or exposing secret credentials.
Give Google Cloud teams access through IAM groups
Give Google Cloud teams IAM access through owned groups, choose a sensible resource scope, and verify migration and removal with practical checks.
Connect to a Google Cloud VM with IAP and OS Login
Connect to a Linux VM through IAP and OS Login, check each permission and network layer, and remove old SSH paths with a tested recovery plan.
Give Azure readers access to one resource group
Assign Reader without granting write access or assuming it grants data access.
Read an Azure Key Vault secret from a VM without a password
Set up one system-assigned VM identity and a vault-scoped secret permission.
Design application authorization before writing Cedar policies
Define business actions, trustworthy entities and tenant boundaries before writing Cedar policies, then make the application responsible for enforcing the resulting decision.
Set explicit trust boundaries for Entra partner access
Accepting another tenant’s authentication claims is a specific trust decision, not blanket approval of its users, devices or access to your applications.
Bind OAuth tokens to the client that presents them
DPoP can make possession of an access token insufficient for use, provided the issuer, client and resource server implement the same proof and key-binding contract.
Keep S3 presigned access inside an explicit delegation window
Treat an S3 presigned URL as a reusable delegation whose usable lifetime depends on the signer, the request and the policies that still apply.
Prove Identity Center permission changes reached every account
A permission-set change is complete only when the intended accounts, account-local policies, provisioning results and assignments have converged.
Restrict device code sign-in without breaking approved clients
Restrict device-code authentication through an explicit client and resource policy, and test the tracked sessions that can outlive the initial browser approval.
Passkey deployment needs a recovery design
A workforce passkey rollout needs a recovery contract before broad enforcement. Separate credential custody, enrollment evidence and application sessions.
Workload federation across clouds needs separate trust decisions
Cross-cloud federation adds trust decisions, not a portable permission system. Map each credential and resource grant before moving a runtime workload.
Entra emergency access that survives normal sign-in failure
A second administrator account does not prove an independent recovery path. Test the credential, workstation, policy and alert dependencies together.
Rotate Entra application certificates with proof of adoption
A renewed certificate can exist in Key Vault while a running client still uses the old key. Define the evidence that makes application rotation complete.
Short SSH certificates still need explicit access boundaries
An SSH certificate supplies bounded identity claims. The issuer, server, client and incident operator still make separate access decisions.
Measure SCIM offboarding at the application
A successful provisioning update proves a directory action, not the end of every application session. Define and test the application's offboarding contract.
Trace Google service account impersonation across every hop
A short-lived token can carry a broad identity. Review who can mint it, which account it represents and whether the original caller remains visible.
Place AWS guardrails on the principal and the resource
SCPs and RCPs constrain different sides of a request. A useful review records both the applicable guardrails and the policies that actually grant access.
Review the authority behind every Entra app consent
The permission name is only part of the decision. Review the access mode, resource scope, consenting authority and people who can change the application.
Define the expiry boundary for Entra privileged access
PIM records activation and expiry, but the protected application still determines when changed authority takes effect. Review both sides of that boundary.
Close the AWS sessions that survive identity shutdown
Removing a login does not by itself establish that issued AWS credentials have lost their authority. Build a revocation procedure that accounts for both.
Lock GitHub deployment trust to the job you intend
A short-lived token still needs a narrow trust decision. Review the subject, deployment environment, reusable workflow and AWS role together.
Questions answered
What does Cloud Security Desk cover under Identity & access?
Research on effective permissions, federation, workload identity, and the conditions that reshape cloud access.
Supporting context
Trust is a path, not a policy.
Why does the identity & access topic matter to cloud security?
Trust is a path, not a policy. This topic applies that principle to practical control evidence and review decisions.
Which control questions belong to Identity & access?
Research belongs here when its central evidence, failure mode, or operational decision falls within the identity & access boundary described on this page.
How many identity & access publications are available?
This page currently lists 27 publications assigned to Identity & access.
How should readers use the Identity & access research?
Start with the publication closest to the control, platform, or evidence gap under review, then follow its findings, limitations, numbered sources, related work, and downloadable material.
Can identity & access overlap other research topics?
Yes. A publication can appear under several topics when one evidence path crosses multiple control boundaries; each publication page identifies its complete scope.
Supporting context