Protecting how you administer cloud services

No matter which cloud service you choose, there are two aspects of your security that you always have some responsibility for:
- how you authenticate to the service
- how you manage the service
If an attacker compromises one of the admin accounts used to manage your cloud, this will seriously undermine any protections you’ve set up, as admins are trusted enough to overcome security controls.
In light of this, we've recently updated the secure system administration guidance to cover two topics that we felt needed more explanation:
- high-risk access (where access is needed to administer a critical component of your system during normal operation)
- emergency access (where access is needed when the normal ways of administering your system are not available, also known as ‘break-glass’ access)
While these concepts apply to all IT and OT systems, this blog looks at how we think these can apply when administering a cloud service.
Protecting high-risk access
Some basic management of a cloud service can be achieved with constrained (that is, tier 3) admin access, keeping the impact of compromise relatively low. An example task might be support staff resetting a standard user’s credentials, or managing access to a development sandbox. However, higher-risk admin access is often necessary for managing features and capabilities of a cloud service, such as:
- creating, changing, and disabling other administrative identities as individuals join, move role, or leave (the JML process)
- changing how your users authenticate to the service, such as updating your single sign-on configuration
- removing or loosening access controls on a critical or highly sensitive set of data
This kind of high-risk access occurs when you manage a cloud service, but they are the same activities that attackers also take after initial compromise, such as when trying to move laterally. This makes accurate detection of malicious admin access much more difficult, so preventing it in the first place becomes even more important.
For users with high-risk access to a cloud service, it’s a good idea to frequently check that you’re following the latest authentication best practice, such as using a phishing-resistant form of MFA. We talk about this in more detail in our recent guidance on using the cloud securely.
When protecting admin access, don’t overlook the value of a privileged access workstation (PAW). A dedicated PAW is one of the most effective tools for defending your administrators from common attacks, such as credential theft and malware infection. This is why the NCSC recommend you always use a PAW for high-risk access to a cloud service handling sensitive data.
Where a dedicated PAW isn't an option, you should think about how close you can get to the protection that PAW provides. For example, could your high-risk admins do the majority of their work in a highly locked down device, but use a local or cloud virtual machine to browse-down for more risky activities, such as reading emails and opening complex documents?
You can combine these with other security signals in your access control policies, as described in our Zero trust architecture design principles.
Preparing emergency access
Emergency access, also known as ‘break-glass’ access, describes a form of emergency access that is absolutely necessarily to have in place, but you hope is never required. It allows you to access and administer your systems, even if all your normal IT is unavailable.
Creating and maintaining effective emergency access is hard because it may need to work without depending on any of the other security-enabling systems you’ve built. However, when preparing for emergency access to cloud services, you can leverage your cloud provider to help you solve this effectively. You should discuss with your cloud provider what account recovery options exist, and put preparations in place before you need them.
The important thing to remember here is that, unlike for high-risk access, you probably won’t be able to follow all the normal secure system administration principles to protect emergency access. For example, you may have to use an unmanaged device, or use fewer security signals in your zero trust architecture than you would normally prefer.
As you won’t be able to protect this access in as much depth as high-risk access, one of the most important things to consider is prompt and robust alarms. When any emergency access is triggered (such as signing in to an emergency administrator account), it should send immediate alarms to your operations personnel so that they can investigate. This serves two main purposes:
- You can ensure that if an attacker compromises an emergency access method, you can take prompt action to limit the damage.
- You want the use of emergency access to be ‘irritating enough’, so that nobody gets in the habit of using it when it isn't absolutely necessary.
Not all risks are equal
It's important to ensure that your security posture is proportionate to your risk appetite. You probably don’t need to be using PAWs and tiered administration for the service that manages your tea club rota. But for your sensitive systems, particularly where you store large volumes of personally identifiable information, make sure the work you invest in securing your cloud estate isn't undermined by poor admin security.


