Understand the business workflow before tightening permissions.
I once performed an internal permission tightening exercise. At first, I thought it was simple—just cut off high-privilege accounts, enforce MFA, and enable audit logs. The result? I was chased down by the business teams in the first week because some service accounts had been used as entry points for automation scripts for years, and no one had registered them. I changed my approach afterward…