Privileged inventoryFind every identity that can materially change the environment.
Inventory domain and local administrators, cloud and SaaS tenant administrators, network and security-device administrators, database administrators, virtualization and backup administrators, application administrators, emergency accounts, service accounts, API credentials, automation identities, deployment credentials, root-equivalent roles, and accounts that can grant privilege to others.
Record owner, purpose, privilege level, authentication method, management path, credential location, last use, review date, dependencies, and whether the access is standing or activated on demand. Include delegated and inherited privilege; a user may not hold an obvious administrator role but can still become privileged through group membership, role assignment, automation, or ownership of a powerful application.
Identify orphaned and shared accounts early. Privilege without accountable ownership or individual attribution is difficult to review and nearly impossible to investigate confidently after an incident.