Akamai access control & privilege security checks
Admin roles, standing privileges, permission scopes and policy enforcement — the settings that decide how much damage one compromised account can do.
On Akamai, Black Cat runs 6 checks in this area on every scan. Each one below lists its severity, how to fix it, and the compliance controls it satisfies where a control applies. See what access the Akamai connector needs.
Checks (6)
severity: medium User Account Locked fix difficulty: easy #
Investigate and unlock or revoke the locked Akamai Control Center user account
- Sign in to Akamai Control Center at control.akamai.com
- Navigate to Identity & Access Management > Users
- Locate the locked user account (indicated by lock icon or status)
- Review the reason for the lockout (failed login attempts, admin action)
- If the lock is legitimate, click "Unlock Account" to restore access
- If the account should not be active, click "Deactivate" or remove the user instead
Satisfies: ISO 27001:2022 A.5.15 SOC 2 Type II CC6.1 CIS Controls v8 CIS-06.1 NIST CSF 2.0 PR.AA-05 GDPR (SaaS Security) GDPR-25.2 HIPAA (SaaS Security) HIPAA-308.a3 NIS2 Directive NIS2-21.i.1 DORA (SaaS Security) DORA-9.2
severity: medium User Inactive fix difficulty: easy #
Disable or remove Akamai Control Center user accounts that have been inactive
- Sign in to Akamai Control Center at control.akamai.com
- Navigate to Identity & Access Management > Users
- Identify users with no recent login activity (check "Last Login" column)
- Confirm with the user's manager whether the account is still needed
- For accounts no longer required, click the user name and select "Deactivate" or "Delete"
- For accounts that should remain active, verify the user's access needs and update accordingly
Satisfies: ISO 27001:2022 A.5.15 SOC 2 Type II CC6.1 CIS Controls v8 CIS-06.1 NIST CSF 2.0 PR.AA-05 GDPR (SaaS Security) GDPR-25.2 HIPAA (SaaS Security) HIPAA-308.a3 NIS2 Directive NIS2-21.i.1 DORA (SaaS Security) DORA-9.2
severity: high User All Groups Access fix difficulty: medium #
Restrict the user's group access to only the groups required for their role
- Sign in to Akamai Control Center at control.akamai.com
- Navigate to Identity & Access Management > Users
- Click the user's name to open their profile
- Review the "Groups" section listing all group memberships
- Remove the user from groups they do not require by clicking the group and revoking membership
- Confirm that the user retains only the minimum necessary group access
Satisfies: ISO 27001:2022 A.5.15 SOC 2 Type II CC6.1 CIS Controls v8 CIS-06.1 NIST CSF 2.0 PR.AA-05 GDPR (SaaS Security) GDPR-25.2 HIPAA (SaaS Security) HIPAA-312.a NIS2 Directive NIS2-21.i.1 DORA (SaaS Security) DORA-9.2
severity: high API Client Credentials Near Expiry fix difficulty: medium #
Rotate expiring API client credentials before they expire to prevent service disruption
- Sign in to Akamai Control Center at control.akamai.com
- Navigate to Identity & Access Management > API Clients
- Locate the affected API client and click its name
- Click "Generate Credentials" to create a new client secret/token
- Download or securely record the new credentials
- Update all systems and integrations using the old credentials with the new values
- Verify the new credentials work, then revoke the expiring credentials
Satisfies: ISO 27001:2022 A.5.15 SOC 2 Type II CC6.1 CIS Controls v8 CIS-06.1 NIST CSF 2.0 PR.AA-05 GDPR (SaaS Security) GDPR-25.2 HIPAA (SaaS Security) HIPAA-312.a NIS2 Directive NIS2-21.i.1 DORA (SaaS Security) DORA-9.2
severity: low API Client Inactive fix difficulty: easy #
Remove or deactivate API clients that are no longer in active use
- Sign in to Akamai Control Center at control.akamai.com
- Navigate to Identity & Access Management > API Clients
- Identify the inactive client (check "Last Used" timestamp)
- Confirm with the owning team that the client is no longer needed
- Click the client name and select "Deactivate" or "Delete"
- Verify no active integrations depend on the client before deletion
Satisfies: ISO 27001:2022 A.5.15 SOC 2 Type II CC6.1 CIS Controls v8 CIS-06.1 NIST CSF 2.0 PR.AA-05 GDPR (SaaS Security) GDPR-25.2 HIPAA (SaaS Security) HIPAA-312.a NIS2 Directive NIS2-21.i.1 DORA (SaaS Security) DORA-9.2
severity: high Custom Role With Admin Permissions fix difficulty: medium #
Review and remove unnecessary admin-level grants from custom Akamai roles
- Sign in to Akamai Control Center at control.akamai.com
- Navigate to Identity & Access Management > Roles
- Locate the custom role flagged with admin-level permissions
- Click the role name to review the full list of assigned permissions
- Remove admin-level capabilities not required for the role's function
- Apply least-privilege principles and save the updated role definition
Satisfies: ISO 27001:2022 A.5.15 SOC 2 Type II CC6.1 CIS Controls v8 CIS-06.1 NIST CSF 2.0 PR.AA-05 GDPR (SaaS Security) GDPR-25.2 HIPAA (SaaS Security) HIPAA-312.a NIS2 Directive NIS2-21.i.1 DORA (SaaS Security) DORA-9.2