Skip to content

007. ADR: Privileged Access Groups in ADME

Date: 18-08-2025

State: Proposed/Accepted/Deprecated/Superseded

Status: Approved

Context

To comply with TR2325 and strengthen security around privileged access roles in OSDU, it is recommended to use dedicated administrative accounts for the following roles:​

Service Access Groups​

  • users.datalake.admins​
  • users.datalake.ops​

Data Access Group​

  • users.data.root (this access is granted with users.datalake.ops)
Requirement ID Description Assessment
SR-132953 A process for the allocation and use of privileged access shall be implemented and documented. Gap
SR-132955 Privileged access shall only be granted to dedicated privileged accounts. Gap
SR-132956 Dedicated privileged access accounts shall only be used for privileged access. Gap
SR-132960 All tasks requiring a privileged account shall be performed using approved Equinor-managed devices. Gap

Decision

We have agreed to implement the following recommendations:

For Production (equinor) and Test (equinortest) ADME Instances: Standard user accounts associated with users.datalake.ops​ or users.datalake.admins​ will be removed. An AZ account group will be added to users.datalake.ops.

Detailed Change Description

  1. osdu-data-landing-zone-ops will be removed from the admin.platform user group which is a member of users.datalake.ops
  2. osdu platform privileged access group will be added to the admin.platform user group
  3. user groups in users.datalake.admins will be deprecated

For the Development instance (equinordev): Access will remain as is. A review of existing access in Development will be conducted at a later stage.

Impact

  • To gain privileged access through CLI, Postman and other tools, you must log into your AZ account separately​
  • Privileged access will be restricted to Equinor devices only. ​
  • The platform team from Sopra Steria has been allocated Equinor laptops, while the offshore team will utilize a Citrix VDI.​
  • For contractors who do not have an Equinor device (e.g. Microsoft), a new process will need to be implemented to facilitate access.

Last update: 2026-09-14