This article introduces Attack Path Management (APM) as a new security practice to address the risk of identity-based attacks that bypass traditional security controls. It highlights that the focus should shift from just preventing logins to understanding and eliminating the "attack graph," which details how attackers can move laterally through an organization's network, and outlines best practices for implementing an APM program.