XM Cyber rolls out tools to identify and revoke unused permissions across hybrid environments

Continuous exposure management company XM Cyber Inc. today announced an expansion of its platform with new capabilities aimed at helping enterprises enforce least-privilege access across Active Directory, Microsoft Entra and multicloud environments.

The company is targeting one of the most exploited weaknesses in modern enterprise security: excessive permissions. Overprovisioned identities give attackers ready-made paths for lateral movement once a single account is compromised, a problem that has grown more acute as artificial intelligence speeds up credential-based attacks.

The new release adds two capabilities to XM Cyber’s existing identity coverage.

The first, Active Directory Excessive Permissions, evaluates how often AD entities actually use the privileges assigned to them, giving identity teams evidence to justify revoking access that sits idle. The second is a Cloud Infrastructure Entitlement Management feature that profiles entitlement usage patterns across large multi-cloud estates so DevSecOps and cloud security teams can clean up overly permissive roles.