Skip to content

Akamai access control & privilege security checks

Admin roles, standing privileges, permission scopes and policy enforcement — the settings that decide how much damage one compromised account can do.

On Akamai, Black Cat runs 6 checks in this area on every scan. Each one below lists its severity, how to fix it, and the compliance controls it satisfies where a control applies. See what access the Akamai connector needs.

Checks (6)

severity: medium User Account Locked fix difficulty: easy #

Investigate and unlock or revoke the locked Akamai Control Center user account

  1. Sign in to Akamai Control Center at control.akamai.com
  2. Navigate to Identity & Access Management > Users
  3. Locate the locked user account (indicated by lock icon or status)
  4. Review the reason for the lockout (failed login attempts, admin action)
  5. If the lock is legitimate, click "Unlock Account" to restore access
  6. If the account should not be active, click "Deactivate" or remove the user instead

Vendor docs ↗

Satisfies: ISO 27001:2022 A.5.15 SOC 2 Type II CC6.1 CIS Controls v8 CIS-06.1 NIST CSF 2.0 PR.AA-05 GDPR (SaaS Security) GDPR-25.2 HIPAA (SaaS Security) HIPAA-308.a3 NIS2 Directive NIS2-21.i.1 DORA (SaaS Security) DORA-9.2

severity: medium User Inactive fix difficulty: easy #

Disable or remove Akamai Control Center user accounts that have been inactive

  1. Sign in to Akamai Control Center at control.akamai.com
  2. Navigate to Identity & Access Management > Users
  3. Identify users with no recent login activity (check "Last Login" column)
  4. Confirm with the user's manager whether the account is still needed
  5. For accounts no longer required, click the user name and select "Deactivate" or "Delete"
  6. For accounts that should remain active, verify the user's access needs and update accordingly

Vendor docs ↗

Satisfies: ISO 27001:2022 A.5.15 SOC 2 Type II CC6.1 CIS Controls v8 CIS-06.1 NIST CSF 2.0 PR.AA-05 GDPR (SaaS Security) GDPR-25.2 HIPAA (SaaS Security) HIPAA-308.a3 NIS2 Directive NIS2-21.i.1 DORA (SaaS Security) DORA-9.2

severity: high User All Groups Access fix difficulty: medium #

Restrict the user's group access to only the groups required for their role

  1. Sign in to Akamai Control Center at control.akamai.com
  2. Navigate to Identity & Access Management > Users
  3. Click the user's name to open their profile
  4. Review the "Groups" section listing all group memberships
  5. Remove the user from groups they do not require by clicking the group and revoking membership
  6. Confirm that the user retains only the minimum necessary group access

Vendor docs ↗

Satisfies: ISO 27001:2022 A.5.15 SOC 2 Type II CC6.1 CIS Controls v8 CIS-06.1 NIST CSF 2.0 PR.AA-05 GDPR (SaaS Security) GDPR-25.2 HIPAA (SaaS Security) HIPAA-312.a NIS2 Directive NIS2-21.i.1 DORA (SaaS Security) DORA-9.2

severity: high API Client Credentials Near Expiry fix difficulty: medium #

Rotate expiring API client credentials before they expire to prevent service disruption

  1. Sign in to Akamai Control Center at control.akamai.com
  2. Navigate to Identity & Access Management > API Clients
  3. Locate the affected API client and click its name
  4. Click "Generate Credentials" to create a new client secret/token
  5. Download or securely record the new credentials
  6. Update all systems and integrations using the old credentials with the new values
  7. Verify the new credentials work, then revoke the expiring credentials

Vendor docs ↗

Satisfies: ISO 27001:2022 A.5.15 SOC 2 Type II CC6.1 CIS Controls v8 CIS-06.1 NIST CSF 2.0 PR.AA-05 GDPR (SaaS Security) GDPR-25.2 HIPAA (SaaS Security) HIPAA-312.a NIS2 Directive NIS2-21.i.1 DORA (SaaS Security) DORA-9.2

severity: low API Client Inactive fix difficulty: easy #

Remove or deactivate API clients that are no longer in active use

  1. Sign in to Akamai Control Center at control.akamai.com
  2. Navigate to Identity & Access Management > API Clients
  3. Identify the inactive client (check "Last Used" timestamp)
  4. Confirm with the owning team that the client is no longer needed
  5. Click the client name and select "Deactivate" or "Delete"
  6. Verify no active integrations depend on the client before deletion

Vendor docs ↗

Satisfies: ISO 27001:2022 A.5.15 SOC 2 Type II CC6.1 CIS Controls v8 CIS-06.1 NIST CSF 2.0 PR.AA-05 GDPR (SaaS Security) GDPR-25.2 HIPAA (SaaS Security) HIPAA-312.a NIS2 Directive NIS2-21.i.1 DORA (SaaS Security) DORA-9.2

severity: high Custom Role With Admin Permissions fix difficulty: medium #

Review and remove unnecessary admin-level grants from custom Akamai roles

  1. Sign in to Akamai Control Center at control.akamai.com
  2. Navigate to Identity & Access Management > Roles
  3. Locate the custom role flagged with admin-level permissions
  4. Click the role name to review the full list of assigned permissions
  5. Remove admin-level capabilities not required for the role's function
  6. Apply least-privilege principles and save the updated role definition

Vendor docs ↗

Satisfies: ISO 27001:2022 A.5.15 SOC 2 Type II CC6.1 CIS Controls v8 CIS-06.1 NIST CSF 2.0 PR.AA-05 GDPR (SaaS Security) GDPR-25.2 HIPAA (SaaS Security) HIPAA-312.a NIS2 Directive NIS2-21.i.1 DORA (SaaS Security) DORA-9.2

More Akamai checks

The information on this page is provided for general informational purposes and is believed to be accurate as of its most recent update. Product names, logos, and trademarks are the property of their respective owners and are used for identification purposes only; their use does not imply any affiliation with or endorsement by those owners. Descriptions of third-party applications and of compliance frameworks are based on publicly available documentation and may change over time.

See these checks run on your stack

Start a free 14-day trial — no credit card required.

Start Free Trial