A smart-city pilot ends, yet project AD groups and API keys still grant access to IoT dashboards. What should IAM operations prioritize?
Select an answer to reveal the explanation.
Short Explanation
Projects die; their group memberships sometimes keep the lights on for strangers. Hunt orphaned access—accounts and keys with no living owner or project—and shut them off.
Full Explanation
Orphaned access remains after projects, contractors, or systems end without deprovisioning. Detection through entitlement reviews, owner attestation, and secret inventory should drive removal of unused groups, accounts, and API keys. Extending passwords, publishing keys, or collapsing groups into broad roles increases exposure rather than closing the orphan gap.