Privileged access to one or more assets is provisioned by default
Context and Guidance: Privileged access to assets (such as networks, systems, and applications) enables identities (users) to bypass security controls and can cause more severe impact to the business if the account is compromised or misused (including accidentally).
As a result, it is important that access provisioning follows the principle of least privilege. This means that identities (users) should only be granted privileged access following validation of a genuine business need, and not by default.
For example, if an identity (user) is provisioned with administrator access on their corporate computer by default, that would indicate that this Anti-Pattern is "Present".