Terminology Index
Glossary
2953 terms
IAM Entitlement Management
Managing the fine-grained permissions (entitlements) that cloud identities hold, discovering, right-sizing, and governing them toward least privilege, since cloud IAM grants are numerous, complex, and easily over-provisioned.
Cloud identities accumulate many granular permissions across services, and entitlement management is the practice of gaining visibility into who can do what, removing unused or excessive grants, and continuously steering entitlements toward least privilege. Often supported by cloud infrastructure entitlement management (CIEM) tooling, it tackles one of the cloud's biggest risks, over-permissioned identities, by treating entitlements as something to be actively governed rather than granted and forgotten.
Introduced in: Cloud Security Engineer Fundamentals
Examples
- Discovering and removing unused permissions from a cloud role.
- Right-sizing an over-permissioned identity toward least privilege.
- Using CIEM tooling to govern entitlements across cloud accounts.
Related
