TechKnowSurge
NIST 800-53 AC-2 NIST 800-53 PS-4 NIST 800-53 PS-5 CompTIA Security+ 4.6 NIST 800-53 AC-6 NIST CSF PR.AA-05 ISC2 CC 3.2
InteractiveSecurityFree

Access Review Audit

Run TechKnowDJ's quarterly access review and flag every account that should fail it.

⚑ Complete this interactive to capture a CTF flag worth 5 points.

About this interactive

Every few months, someone in IT sits down with a list of every account the company has and asks one question of each: should this still look like this? That is a user access review, and it exists because a directory only knows what someone told it. When a person leaves, moves to another team or finishes a contract, HR knows the same day. The directory finds out only if somebody acts on it, and the review is where the gaps get caught. In this activity you are the new IAM analyst at TechKnowDJ, the fictional music-tech company from the TKS simulations, and the Q3 review is on your desk. You get three things: a six-line access policy, HR's list of who left, moved, joined or went on leave since the last review, and the directory export itself. Your job is to check each account against the other two and flag every one that should fail. Eight do, and between them they cover the whole account lifecycle the lesson describes. Three are accounts that should already have been switched off: an employee who left more than six weeks ago whose account is still switched on, a contractor whose contract ended but whose account is set to expire never, and an account nobody has signed in to in over four months. One is a mover who changed departments and kept the old department's access, which is how privilege creep happens. The other four are about how much access an account holds and for how long, the least privilege, just-in-time and ephemeral credential ideas from the access control lesson: a helpdesk technician with permanent full admin rights, an admin account whose password the whole IT team shares, a service account that holds full admin rights and that a person can sign in with, and temporary access to payroll that was granted in April with no end date. Every one of them comes with its fix, from disabling the account to swapping permanent admin rights for access requested only when it is needed. Just as important are the accounts that pass. A disabled account for someone on parental leave, a sealed emergency admin account with one named owner, a service account that can only read one system, temporary access with an end date: each looks risky at a glance and is managed exactly right. A review that flags everything that looks unusual wastes everyone's time. The skill is telling the difference.

What you'll learn

Aligned to

NIST 800-53
AC-2 Account Management
PS-4 Personnel Termination
PS-5 Personnel Transfer
AC-6 Least Privilege
CompTIA Security+
4.6 Given a scenario, implement and maintain identity and access management.
NIST CSF
PR.AA-05 Access permissions, entitlements, and authorizations are defined in a policy, managed, enforced, and reviewed, and incorporate the principles of least privilege and separation of duties.
ISC2 CC
3.2 Understand logical access controls

Key terms

De-provisioning
The process of revoking and removing a user's access rights and accounts when they leave an organization or no longer require access.
Least Privilege
A security principle that grants users and systems only the minimum access rights needed to perform their functions.
Just-in-Time Permissions
A practice of granting access to resources only for the specific period of time a user or system needs them, then revoking that access immediately after.
Ephemeral Credentials
Temporary account credentials provisioned for a limited time to grant access to specific resources, then removed once the need has ended.
Account Lifecycle Management
The process of provisioning, maintaining, and deprovisioning user accounts throughout their existence within an organization.
Provisioning
The process of creating and configuring user accounts and granting appropriate access rights when a user joins or changes roles in an organization.
Offboarding
The process of revoking a departing or transitioning employee's system access and decommissioning their accounts to prevent unauthorized access.
Privileged Access Management
PAM
Privileged Access Management encompasses the policies, tools, and technologies used to control, monitor, and audit access by privileged accounts such as administrators, reducing insider threat risk through just-in-time access grants and full session recording.
Identity and Access Management
IAM
A framework of policies and technologies that ensures the right users have appropriate access to resources.
Permissions
The defined access rights granted to users, groups, or objects that control what resources they can access or modify.

Topics

Interactive Spot The Error

About TechKnowSurge

TechKnowSurge builds IT and cybersecurity professionals through hands-on, concept-first training built around real understanding — not memorization. Free interactive tools, structured programs, and 25+ years of real-world experience, all in one place.

Explore free tools and programs →