Inventory the paths to administration
List the places from which someone can control the service: hosting, DNS, source code, deployment, databases and the application itself. Do not stop at the most visible login page. A forgotten infrastructure account may have broader access than an application administrator.
For each account, record its owner, purpose and last review. Separate human access from machine access. Shared accounts make it harder to know who performed a change, so record any unavoidable exception and the plan to remove it.
Check the entire sign-in journey
OWASP’s authentication guidance covers controls such as multifactor authentication, recovery and reauthentication for sensitive operations. A strong normal login can be undermined by a weaker recovery path. Examine both.
Walk through a lost-device scenario with a test account. Who approves recovery? What evidence is checked? Where are recovery materials held? The goal is a process that remains usable without quietly granting anyone who can send an email administrative access.
Make removal a normal operation
Choose a review cadence and repeat the review after role changes or departures. Confirm that disabling an account removes the intended access across connected services. Existing sessions and long-lived tokens may need separate treatment depending on the platform.
Close each review with a short list of changes and unresolved exceptions. A screenshot of a user list is not a complete review: the useful result is a reason for each retained privilege. Start with the accounts that can change identity, billing, DNS or production deployments.
Before you finish
- Infrastructure accounts included
- Account owners recorded
- Recovery path reviewed
- Removal process tested
Technical reference
OWASP: authentication cheat sheet
