You Can't Classify Your Way to Least Privilege
Aug 26, 2026
A building inspector can spend a day walking a house and hand the owner a thick binder: every cracked joist, every frayed wire, every code violation photographed and cataloged. The report is precise, and the house is exactly as dangerous as it was before anyone arrived. In simple terms, documentation is not repair.
What a DSPM scan actually tells you (and doesn't)
That gap is worth holding onto as data security posture management, or DSPM, becomes one of the fastest-growing categories in security. Gartner put DSPM adoption below 1% of organizations in 2022 and projects it past 20% by 2026, a steep climb for a young category. Gartner's definition explains the pull: DSPM tools discover, classify, and catalog sensitive data across on-premises stores, clouds, and SaaS, so a security team can finally see where its regulated and confidential information lives and, in the best case, who has access to it.
Seeing it is where the trouble starts.
Consider what a CISO actually receives at the end of a scan: a number. Some quantity of sensitive files spread across some set of repositories is flagged and labeled. The finding is real, and it affects the security team's anxiety far more than it affects the security team's exposure. The tool has only reported where the data sits. It might say something about who can reach that data, but whether those people were ever meant to have that access or what to do next is outside of DSPM. What lands on the CISO’s desk is an inventory of exposure, not a plan for reducing it.
Why classification can't get you to least privilege
Here is the distinction the category blurs. The risk attached to a sensitive file comes from three things at once: how sensitive the data is, who can reach it, and whether they have any business doing so. Classification addresses the first term. Even when it does so accurately, it says little about the legitimacy of access and the area where the exposure lives. That is why a security team cannot classify its way to least privilege.
Three mechanics explain the silence.
Start with the gap between effective access and the access control list. What a file's permissions say and who can genuinely open it diverge the moment reality intrudes: nested Active Directory groups, inheritance, inheritance broken somewhere up the tree, an "Everyone" or "Authenticated Users" entry sitting on a share, a forgotten SharePoint link still live in someone's inbox. A tool reading the sensitivity label sees the stated permissions. It does not resolve the true reachability graph, and the distance between the two is where a breach travels.
Then there is the origin of the access path, which sits in the identity fabric well before it reaches the data. The over-permissioned group, the security group with a few thousand members that no one has pruned in years, the service account or AI agent holding standing read access, the guest identity in Entra still carrying a link — these are what open the door, and they live in the identity layer. A scanner that reads only the data store cannot see the whole path, as half of it was never in the data store to begin with.
Finally, discovery and remediation are different jobs. A scan produces a finding. Risk falls only when someone removes the global group, quarantines the folder, re-permissions it against what the business genuinely needs, and can then demonstrate least privilege afterward. That is an act of access governance, and no volume of classification performs it.
Suppose a scan flags a folder of payroll records as highly sensitive. On one hand, the security team now knows the folder exists and matters, which is the necessary first step. On the other hand, the folder sits behind a legacy "Domain Users" grant applied years ago for a project that has long since closed, so several thousand people can open it this afternoon, and the classification label has changed none of that. The label tells the team the folder is worth protecting; only the access model tells them it is currently unprotected, and only remediation closes it.
How Netwrix Access Analyzer closes the gap
This is the direction Netwrix Access Analyzer works from. It begins in the access model and arrives at the data through it, where the cloud-native scanners run the other way, mapping data first and inferring access later. It resolves effective access across hybrid, unstructured environments, untangles the Active Directory and Entra permission sprawl that scanners treat as opaque, surfaces the over-exposed and the stale, and drives remediation with a simulate-then-execute step and reviews routed to the business owner who knows whether a given person should hold that access at all.
Classification finds the risk. Access removes it.
None of this makes classification pointless. A team cannot govern access to data it never located, so discovery has to come first. Its job is to locate the risk; closing that risk belongs to a different discipline. The defensible framing is a narrow one: classification shows a security team where its risk is concentrated, and access is where the risk is removed. You need to do both if the goal is a balanced risk management.
Which returns us to the inspector's binder. It has real value, as it tells the owner where to send the contractor. But no one mistakes the binder for a repaired house, and a classified data map deserves the same skepticism. Every DSPM tool on the market can say where sensitive data lives. The question that decides whether that data is at risk is who can open it, and that answer was never in the data map. It is in the access model.
Share on
Learn More
About the author
Dirk Schrader
VP of Security Research
Dirk Schrader is a Resident CISO (EMEA) and VP of Security Research at Netwrix. A 25-year veteran in IT security with certifications as CISSP (ISC²) and CISM (ISACA), he works to advance cyber resilience as a modern approach to tackling cyber threats. Dirk has worked on cybersecurity projects around the globe, starting in technical and support roles at the beginning of his career and then moving into sales, marketing and product management positions at both large multinational corporations and small startups. He has published numerous articles about the need to address change and vulnerability management to achieve cyber resilience.