Skip to main content

← Back to glossary

Term · 11. Risk & Compliance

Over-provisioning

IDM/IGA Domain
Personal Data JML ISO/IEC OWASP Introduced by: Big4 (Deloitte / PwC / EY / KPMG)

Definition

Granting access beyond what's needed for the role — common cause of attack surface expansion and SoD violations. Sources: copy-paste provisioning (give new hire same access as predecessor without review), accumulated access from role changes, over-broad role definitions. Detected by CIEM/ISPM tools.

Application
MidPoint: Situation when an identity has more privileges than are necessary for the tasks that the identity is supposed to carry out.