Device inventory is not privileged account discovery
Sep 14, 2026
A device inventory tells you where the machines are, while a privilege inventory tells you where an attacker can go.
An endpoint record can show that a machine exists, who owns it, and whether a management agent has checked in. It does not show who can administer that machine.
That distinction matters because an attacker doesn't need a complete asset inventory. A valid privileged path to one useful endpoint may be enough. If your team reports known devices as evidence of completed privileged account discovery, it is measuring the wrong thing.
A device inventory shows which systems are known. Privileged account discovery shows which identities can administer those systems, how they receive that access, whether the evidence is current, and which endpoints remain unscanned. Measure successful scan coverage against all in-scope endpoints, then analyze direct and group-derived administrator access. Do not report device coverage as privilege visibility.
Device inventory and privilege discovery answer different questions
Device inventory is essential, and it answers an asset-management question: what systems do we know about? The record may include a hostname, owner, operating system, business unit, installed agent, or last check-in time.
Privileged account discovery answers a different security question: who can administer each system right now, and through which relationship?
Device inventory can show | Privilege inventory must show |
|---|---|
|
The endpoint exists |
The endpoint's privilege state was successfully checked |
|
The endpoint has an owner or management agent |
Which accounts and groups have administrative access |
|
The endpoint last checked in |
When its privilege evidence was collected |
|
The endpoint belongs to a business unit |
Whether access is assigned directly or inherited through a group |
|
The endpoint is in scope for management |
Which in-scope endpoints still have no trustworthy result |
A listed device may still have unknown local administrator membership.
I recommend treating the device list as the starting population instead of the discovery result. Until the privilege check succeeds, that endpoint belongs in the coverage gap.
Privileged account discovery needs a coverage denominator
Every privilege metric needs a denominator. For endpoint discovery, a useful starting measure is:
Current privilege coverage = in-scope endpoints with a successful, current privilege scan / all in-scope endpoints
Define “current” for each endpoint population. Seven days may be acceptable for workstations but too old for critical servers, so align the interval with how quickly access can change.
The denominator can't silently shrink when scanning gets difficult. Keep at least these categories visible:
- Successfully scanned within the accepted interval
- Successfully scanned, but now out of date
- Offline or unreachable
- Failed because of authentication, authorization, connectivity, or configuration issues
- Known, but never scanned
- Newly discovered records that have not yet been reconciled to a scan target
These are security results that need follow-up. An offline, failed, or never-scanned endpoint may still contain standing access and cannot be counted as clean.
Enrollment and health reporting establish device status. Privilege coverage adds current evidence of administrative access.
Effective administrator access has to be traced from the endpoint
On a Windows endpoint, the local Administrators group is the practical starting point. Its members may include a local account, a named domain account, or a domain group. Effective access also extends to identities that inherit membership through a group path.
That creates two different views:
- Direct membership: An account or group appears directly in the endpoint's local Administrators group.
- Group-derived access: A person or account receives administrative access because they belong to a group that is a direct or nested member.
Direct assignments explain the endpoint's configuration. Resolved group-derived relationships show an identity's reach across the environment. A list of local group entries alone can understate that reach.
Local accounts need special attention as well. MITRE ATT&CK T1078.003, Local Accounts, describes how adversaries can abuse valid local credentials for persistence, privilege escalation, defense evasion, and access. MITRE also notes that reused local account credentials can support movement between machines. A device inventory cannot tell you whether the same local administrative identity or credential pattern creates that reach.
Privilege discovery must connect endpoint evidence to the identity relationships that make access effective.
Endpoint platforms extend discovery; business context guides policy
Asset and endpoint platforms help define scope. Integrated collection paths can extend evidence gathering across managed endpoints.
Trustworthy results tie each check's outcome and time to the administrative relationships found.
Business context turns evidence into policy. Teams combine discovery results with account ownership, workflow dependencies, and business need to choose which access to retain, review, or remove.
These responsibilities work together:
- Asset and endpoint platforms establish scope and, where integrated, extend collection.
- Privileged account discovery maps administrative relationships and measures coverage.
- Ownership, dependency, and policy context guide remediation.
For the broader control framework around inventory, access reviews, least privilege, and time-bound access, see the Netwrix guide to privileged access management best practices.
Measure visibility before measuring privilege reduction
A privilege count becomes meaningful once discovery coverage is stable.
As scanning reaches a new server segment, the count may rise because visibility has improved. Track coverage alongside exposure so later reductions reflect removed access rather than disappearing evidence.
This is a widespread operational gap. The Netwrix 2026 Data and Identity Security Report found that 76% of organizations cannot immediately revoke standing access when it is no longer needed. Effective revocation starts with knowing exactly where the access exists and whether the evidence is current.
Report visibility and exposure together. Track:
- Total in-scope endpoints.
- Number and percentage with a current successful scan.
- Out-of-date, failed, offline, never-scanned, and unresolved endpoints.
- Identities with direct or group-derived local administrator access.
- Each identity's endpoint reach.
- Age of the oldest result accepted as current.
Once coverage is stable, prioritize identities with broad reach, repeated local accounts, unexpected group paths, and access to critical systems. From that point, a falling privilege count becomes evidence of remediation.
How NPS-D turns device records into privilege evidence
Netwrix Privilege Secure for Discovery (NPS-D) turns endpoint inventory into actionable privilege evidence. It discovers local administrative access on managed Windows endpoints, records direct and group-derived administrator relationships, and keeps scan status separate from the existence of a device record. This gives teams a clear view of discovered access and the coverage status behind it.
NPS-D can collect privilege evidence directly from Windows endpoints with a valid Scan account, without installing an NPS-D endpoint agent. It combines directory context from Active Directory, Microsoft Entra ID, or both with local administrator evidence gathered through direct connectivity or a supported EDR integration such as Tanium Cloud. This extends discovery across directly reachable and EDR-managed endpoints.
Where teams use Microsoft Intune, its managed-device inventory helps define the endpoint population. Reviewed alongside NPS-D privilege evidence, it provides views into which endpoints are managed and who can administer each one, how access is assigned, and when the evidence was collected.
NPS-D connects endpoint results to identities. Teams can analyze how broadly a privileged identity reaches across systems and distinguish direct assignments from group-derived access while keeping coverage gaps visible.
A practical NPS-D workflow is to:
- Establish the in-scope endpoint population.
- Collect current local administrator evidence and measure coverage.
- Trace direct and group-derived access back to identities.
- Review ownership, dependencies, and approved exceptions.
- Move from observation to policy enforcement in controlled stages.
Once teams understand who needs administrative access, they can use NPS-D to reduce unnecessary privileges. Start with a small group of endpoints, review the results, and expand gradually.
Report privilege coverage
A trustworthy privilege inventory connects four things: an in-scope endpoint, a successful and current scan, the administrative relationships found on that endpoint, and the identities that receive effective access through those relationships.
Start with four actions this week:
- Define the endpoint population that is in scope.
- Separate known devices from endpoints with a successful, current privilege scan.
- Investigate every out-of-date, failed, offline, never-scanned, or unresolved record.
- Rank direct and group-derived administrator relationships by their reach and business importance.
If you can list every device but cannot say who can administer each one, when that evidence was collected, and which systems remain unseen, you have a device inventory. You don't yet have privilege discovery.
See privilege discovery in action
Watch how Netwrix Privilege Secure for Discovery uncovers hidden privileged access on endpoints, shows who can administer each system, and helps teams reduce standing access.
Ready to turn device inventory into privilege evidence? Explore Netwrix Privilege Secure for Discovery.
Share on
Learn More
About the author
Tomasz Malik
Tomasz Malik is a cybersecurity and Linux specialist and Product Owner for Netwrix Privilege Secure for Discovery. He combines hands-on systems expertise with product leadership to help organizations discover, understand, and reduce unnecessary privileged access across endpoint environments.