Security | Threat Detection | Cyberattacks | DevSecOps | Compliance

How to Reduce Your Cloud Attack Surface by Eliminating Standing Privileges

You can reduce your cloud attack surface by auditing every persistent permission across your cloud and identity platforms, stripping away unnecessary access and replacing always-on admin rights with Just-In-Time (JIT) access that’s granted on approval, time-limited and automatically revoked. Getting there starts with understanding why standing privilege makes up such a significant portion of the cloud attack surface.

Shadow AI: What Clients Aren't Telling Their MSPs

MSPs are expected to understand their clients’ technology environments. They know which endpoints are managed, which applications are business-critical, which systems require patching or maintenance, where sensitive data resides and who has access to it. Increasingly, however, critical technology decisions are now being made without IT or MSP involvement. Across client environments, this can take many forms: And each instance can occur without the MSP ever knowing.

Common Zero Standing Privilege Challenges and How To Solve Them

One of the most exploitable parts of modern attack surfaces is standing privileges: the persistent access rights that linger on accounts long after they’re needed. With standing privilege, static credentials are easier to steal, and overprovisioned accounts give attackers far more reach than they should have. Zero Standing Privilege (ZSP) solves these issues by granting access only when necessary and revoking it as soon as the task is finished, leaving behind no lingering access.

How Keeper Privileged Cloud Delivers Zero Standing Privilege

Keeper Privileged Cloud delivers Zero Standing Privilege (ZSP) by extending KeeperPAM’s Just-In-Time (JIT) access framework to cloud identity platforms. A user gets elevated permissions only after a request is approved; those permissions last for a set time window, and Keeper removes them automatically once the window ends. No permanent privilege is left in place.

Zero Standing Privilege vs Least Privilege: What's the Difference?

The main difference between Zero Standing Privilege (ZSP) and least privilege is that least privilege limits the amount of access an identity has, whereas ZSP limits both the amount of access and its duration. Least privilege grants every user or machine only the minimum permissions necessary to do its job, but those permissions tend to persist once a task is completed, leaving standing access behind.

Keeper Security Launches Certified Microsoft Power Platform Connector for Secrets Manager, Bringing Zero-Knowledge Credential Management to Azure Logic Apps

Keeper Security, the leading zero-trust and zero-knowledge identity security platform, today announces the availability of a certified connector integrating Keeper Secrets Manager with Microsoft Azure Logic Apps. The connector, now published on the Microsoft Power Platform marketplace, enables enterprise teams to create and retrieve credentials at runtime directly within automated workflows without ever hardcoding sensitive values in flows.

What To Know About the US Water Cyber Attacks

In late July 2026, over 30 municipal water systems across Minnesota were targeted in coordinated cyber attacks that disrupted the Operational Technology (OT) used to remotely monitor and control water equipment. The attacks initially unfolded on July 26 and 27, striking multiple automated control systems across the state, including those in Plymouth, Braham and South St. Paul.

Keeper Security Issues Cybersecurity Guidance for Education IT Teams As Students Return to Campus

Every fall, school districts and universities across the country race to onboard thousands of new students, faculty and staff, provisioning accounts, issuing credentials and connecting a wave of new devices to institutional networks. It is a moment of organized chaos, and cybercriminals know it.

How AI Governance Reduces Security Risks

AI governance reduces security risk by enforcing least-privilege access, protecting the data and credentials AI systems handle and making every AI action auditable. This matters because most organizations deploy AI faster than they can govern it. Employees adopt unsanctioned tools, and autonomous AI agents are created under existing user identities. Each one adds unmonitored machine identities that expand your attack surface – the exact gap that governance closes.

AI's Hidden Identity Risk for MSPs

Organizations are rapidly integrating AI into everyday business operations. Teams are using Microsoft Copilot and Gemini to summarize meetings, developers are accelerating software delivery with coding copilots and customer service teams are deploying AI-powered chatbots to improve response times. While these initiatives are viewed through the lens of productivity and innovation, they are also reshaping organizations’ identity environments in ways that frequently go unnoticed.