Vendor access
Third parties with admin are still your admin. Unique credentials, time-boxed, logged, MFA. You can hire the hands. You cannot hire away the accountability.
First principles
A vendor with admin on your identity, your mail, your backups, or your cloud is inside the blast radius. The contract does not absorb that. You can outsource the work. You cannot outsource the risk. Treat their access with the same controls you would give a privileged staff member, plus an end date you actually enforce.
Shared 'support' logins, standing VPN accounts, a copied admin password, remote tools installed once and never reviewed — those are how a third party becomes a permanent, unmonitored admin. Unique credentials mean you can revoke one person at the vendor without rotating the whole company. Time-boxing means the access ends when the job ends, not when someone remembers.
The four controls
Unique creds. Time-boxed. Logged. MFA. All four. Three of four is how a contractor still has VPN a year after the project. MFA on a shared account does not count: see Offboarding. Logs you cannot attribute to a named human do not count either.
What an admin actually does
- Issue a named identity in your directory, not an account in theirs that you never see. Federate if you can.
- Put an end date on the role. Calendar the review. No standing vendor admin for 'just in case they need it'.
- MFA, preferably a hardware key you issued. Privileged, remote, and email still go first — including theirs.
- Log their admin actions into the same place you log yours. If you cannot, they do not get admin.
- A break-glass vendor path for incidents is fine. It is still dual-control, still reviewed, still named.
Informed by ASD's ACSC — ISM. Wording is ours.
