Case study · Cloud security

Reviewing Cloud Administrative Access

A controlled access route only helps if an alternative route does not leave the same systems exposed.

My role: Penetration tester conducting a read-only cloud configuration assessment.

An anonymised account of an engagement. The client, cloud provider, dates, resource details and original evidence are withheld to protect confidentiality.

The question

This assessment examined how administrative access to cloud workloads was controlled. The review also considered identity permissions, logging and the policies intended to keep configurations consistent.

The central question was whether the observed access rules matched the intended protection. A security service being present is only part of that answer.

What the configuration showed

The review identified a controlled administrative access service alongside rules that still permitted direct public access to administrative interfaces. The alternative path meant the controlled route was not enforced as the only way in.

This was a configuration finding. The assessment did not need to claim a successful intrusion to explain why that access path deserved attention.

Working within the available access

I used read-only configuration evidence to review access rules, workload exposure and supporting controls. Some identity and detection settings could not be fully inspected with the permissions available for the assessment.

Those limits were part of the result. Where a control could not be verified, the report recorded that uncertainty. Restricted visibility is not, by itself, proof that a control is missing.

Prioritising the response

The recommended sequence started with reducing direct administrative exposure, then strengthening access controls and visibility, and finally establishing policies to prevent the same configuration pattern from returning.

  • Reduce exposure: restrict direct public administrative access and review the remaining routes to affected workloads.
  • Control access: enforce an approved administrative path and review whether access should be time-bound.
  • Make the controls sustainable: clarify ownership, improve logging and use enforceable policies to limit configuration drift.

The result

The deliverable was an evidence-based assessment and a prioritised remediation roadmap. It separated observed configuration issues from controls that still required verification.

The supplied engagement record does not establish that the recommended changes were implemented. This case therefore describes the assessment and advice, rather than claiming a completed remediation or a prevented incident.

What this work illustrates

Cloud security review involves tracing how access is actually allowed. Looking at the routes around a protective control can be as useful as checking the control itself.