007. ADR: Privileged Access Groups in ADME
Date: 18-08-2025
State: Proposed/Accepted/Deprecated/Superseded
Status: Approved
Context
To comply with TR2325 and strengthen security around privileged access roles in OSDU, it is recommended to use dedicated administrative accounts for the following roles:
Service Access Groups
- users.datalake.admins
- users.datalake.ops
Data Access Group
- users.data.root (this access is granted with users.datalake.ops)
| Requirement ID | Description | Assessment |
|---|---|---|
| SR-132953 | A process for the allocation and use of privileged access shall be implemented and documented. | Gap |
| SR-132955 | Privileged access shall only be granted to dedicated privileged accounts. | Gap |
| SR-132956 | Dedicated privileged access accounts shall only be used for privileged access. | Gap |
| SR-132960 | All tasks requiring a privileged account shall be performed using approved Equinor-managed devices. | Gap |
Decision
We have agreed to implement the following recommendations:
For Production (equinor) and Test (equinortest) ADME Instances: Standard user accounts associated with users.datalake.ops or users.datalake.admins will be removed. An AZ account group will be added to users.datalake.ops.
Detailed Change Description
- osdu-data-landing-zone-ops will be removed from the admin.platform user group which is a member of users.datalake.ops
- osdu platform privileged access group will be added to the admin.platform user group
- user groups in users.datalake.admins will be deprecated
For the Development instance (equinordev): Access will remain as is. A review of existing access in Development will be conducted at a later stage.
Impact
- To gain privileged access through CLI, Postman and other tools, you must log into your AZ account separately
- Privileged access will be restricted to Equinor devices only.
- The platform team from Sopra Steria has been allocated Equinor laptops, while the offshore team will utilize a Citrix VDI.
- For contractors who do not have an Equinor device (e.g. Microsoft), a new process will need to be implemented to facilitate access.
Last update:
2026-09-14