Supplier access
Third parties with privileged or remote access are inside your perimeter, whatever the diagram says.
Their laptop, their identity provider and their security practices are now part of your attack surface. It is one of the best-documented routes into large organisations, and it is frequently granted permanently, with shared credentials, because that was simplest during onboarding.
Checked against the primary source.
