About this interactive
Every few months, someone in IT sits down with a list of every account the company has and asks one question of each: should this still look like this? That is a user access review, and it exists because a directory only knows what someone told it. When a person leaves, moves to another team or finishes a contract, HR knows the same day. The directory finds out only if somebody acts on it, and the review is where the gaps get caught. In this activity you are the new IAM analyst at TechKnowDJ, the fictional music-tech company from the TKS simulations, and the Q3 review is on your desk. You get three things: a six-line access policy, HR's list of who left, moved, joined or went on leave since the last review, and the directory export itself. Your job is to check each account against the other two and flag every one that should fail. Eight do, and between them they cover the whole account lifecycle the lesson describes. Three are accounts that should already have been switched off: an employee who left more than six weeks ago whose account is still switched on, a contractor whose contract ended but whose account is set to expire never, and an account nobody has signed in to in over four months. One is a mover who changed departments and kept the old department's access, which is how privilege creep happens. The other four are about how much access an account holds and for how long, the least privilege, just-in-time and ephemeral credential ideas from the access control lesson: a helpdesk technician with permanent full admin rights, an admin account whose password the whole IT team shares, a service account that holds full admin rights and that a person can sign in with, and temporary access to payroll that was granted in April with no end date. Every one of them comes with its fix, from disabling the account to swapping permanent admin rights for access requested only when it is needed. Just as important are the accounts that pass. A disabled account for someone on parental leave, a sealed emergency admin account with one named owner, a service account that can only read one system, temporary access with an end date: each looks risky at a glance and is managed exactly right. A review that flags everything that looks unusual wastes everyone's time. The skill is telling the difference.
About TechKnowSurge
TechKnowSurge builds IT and cybersecurity professionals through hands-on, concept-first training built around real understanding — not memorization. Free interactive tools, structured programs, and 25+ years of real-world experience, all in one place.
Explore free tools and programs →