Replace standing admin rights with one scoped, logged permission

short · 35 min · Objective 1.1

Task

Give a lab operator account the shortcut everyone takes -- full sudo, all the time -- then replace that standing access with a single permission scoped to the one task the account exists for. Prove that the task still works, that everything else is refused, and that every request, allowed or refused, is recorded. That is least privilege deciding how much an allowed request can reach, with each sudo prompt acting as a per-request check.

Steps

  1. Snapshot the VM. Create the operator account: sudo useradd -m -s /bin/bash labop && sudo passwd labop.
  2. Grant the shortcut so you can see what it looks like: sudo usermod -aG sudo labop (on Rocky or AlmaLinux the group is wheel). Save sudo -l -U labop into /tmp/before.txt; the line (ALL : ALL) ALL is standing access -- everything, always, whether used or not.
  3. Remove it: sudo gpasswd -d labop sudo (or wheel).
  4. Write the scoped rule with sudo visudo -f /etc/sudoers.d/labop, containing exactly one line: labop ALL=(root) /usr/bin/systemctl restart rsyslog. Then check it parses: sudo visudo -cf /etc/sudoers.d/labop.
  5. Become the operator with sudo -iu labop and test both sides: sudo systemctl restart rsyslog must succeed after labop's password; sudo systemctl stop rsyslog and sudo cat /etc/shadow must both be refused. Type exit to return to your own account.
  6. Read the record of all three requests: sudo journalctl -t sudo --since '15 min ago' | grep labop. The allowed restart and both refusals are there, which is the accounting half of the decision.
  7. Write /tmp/least-privilege.md with three short sections: what the account could reach before, what it can reach now, and what an attacker who phished labop's password would get in each case -- the blast radius the lesson says least privilege exists to limit.

Verify

sudo -l -U labop | grep -c 'ALL) ALL'
sudo -l -U labop | grep -c 'systemctl restart rsyslog'
id -nG labop | grep -cwE 'sudo|wheel'
sudo journalctl -t sudo --since today | grep -c 'labop : command not allowed'

The first must print 0: no blanket rule is left anywhere, including one inherited through a group. The second must print 1: the single task is still permitted. The third must print 0, because group membership is the usual way standing access survives a cleanup -- the rule file looked right while the group still granted everything. The fourth must be at least 2: both refused requests were logged, so a refused attempt is evidence rather than silence.

Notes

Notice what did not change: labop's password is exactly as phishable as before. Least privilege did nothing to prevent the compromise; it decided what the compromise is worth. The same discipline applies to service accounts, API keys and automation, which is where standing access most often hides, because nobody logs in as them to notice.

This is an independent study companion for CompTIA Security+ SY0-801 and is not produced by or endorsed by CompTIA.