Join our Newsletter — 33% off our NHI Course

What should IAM teams prioritise after a merger closes?

They should prioritise permission truth, ownership assignment and risk-based review of the identities most likely to preserve hidden access. That means focusing on effective permissions, orphaned accounts and non-human identities before consolidating directories or standardising roles.

Why post-merger identity work should start with truth, not normalisation

The first priority is to establish what access actually exists, who owns it, and which identities can still reach critical systems after the close. In merger environments, directory consolidation often creates a false sense of control before effective permissions, inherited entitlements, and dormant access paths have been reconciled. That is why permission truth comes before role standardisation.

Start by comparing granted access with real usage, then separate human accounts, service accounts, shared accounts, and other non-human identities into distinct review paths. The fastest way to lose visibility is to collapse different identity types into one migration stream before you know which ones are carrying operational access or hidden privilege.

A useful working model is to treat every entitlement as provisional until it is tied to an owner, a business function, and a removal path. That prevents inherited access from surviving the transaction simply because no team can yet explain why it exists.

Where hidden access usually survives the merger cutover

Hidden access tends to persist in three places: orphaned accounts, overbroad group membership, and machine identities that were issued for automation rather than people. Those identities often bypass the clean-up attention given to named users, yet they can retain production reach long after the original system owner has left or the application has been retired.

That is why an early review should focus on identities most likely to preserve access without obvious human ownership. The practical test is not whether an account exists, but whether it still authenticates, what it can touch, and whether anyone is prepared to defend that access if asked.

For merger teams, the main mistake is to optimise for directory hygiene before entitlement hygiene. A tidy directory with unresolved effective permissions can still leave critical applications, cloud roles, and integration accounts exposed.

How to sequence review, ownership, and cleanup without breaking the business

Use a risk-based sequence: first isolate the identities with privileged, cross-environment, or high-blast-radius access; then assign accountable owners; then decide what can be recertified, shortened, or removed. Lifecycle processes for managing NHIs are especially relevant where the acquired environment contains service identities, automation, or other accounts that will not surface in a standard joiner-mover-leaver review.

The review should not be limited to named admins. In post-merger estates, the highest-risk paths often sit in application roles, delegated access, legacy integrations, and cloud permissions that were created to keep acquired systems running. Cloud PAM and CIEM guidance is useful here because effective permissions, escalation paths, and rightsizing are exactly the problems that tend to survive acquisition.

Ownership assignment is not a clerical step. It is the control that determines whether an entitlement can later be reviewed, revoked, or explained. If no business or technical owner can be named, that access should be treated as suspect until proven necessary.

Risk and Threat Considerations

Merger activity creates a concentrated window for privilege sprawl, orphaned access, and attacker persistence because control ownership is fragmented and inventories are incomplete. Attackers do not need to compromise the whole estate if they can keep one inherited account, service principal, or stale integration credential alive long enough to blend in.

Failure mechanism: Inherited permissions remain active while teams focus on directory integration, so dormant or misowned accounts retain access to sensitive systems and can be abused before governance catches up.

Impact: The result can be unauthorized access, lateral movement across the combined environment, and delayed containment if the surviving identity is a non-human account used by production automation or cross-system integrations.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

OWASP Non-Human Identity Top 10 addresses the attack and risk surface, while CIS Controls v8 sets the governance and control requirements practitioners need to meet.

Framework Control / Reference Relevance
OWASP Non-Human Identity Top 10 NHI-01 — Improper Offboarding Merger cleanup must remove stale non-human identities and inherited access.
NHI-05 — Overprivileged NHI Post-close reviews must find excessive machine and service access.
NHI-10 — Human Use of NHI Mergers often leave humans relying on machine identities without clear ownership.
Recommendation — Revoke or revalidate NHI access during merger cleanup before directory consolidation. Review effective permissions and reduce excess NHI privilege first. Separate human and non-human access paths and assign explicit owners.
CIS Controls v8 CIS-5 — Account Management The question is about prioritising account review, ownership and cleanup after a merger.
CIS-6 — Access Control Management Effective permissions and least privilege are central to post-merger access review.
Recommendation — Inventory, validate and retire unnecessary accounts before normalising roles. Right-size access based on actual need and revoke inherited excess.

Practitioner Guidance

What to prioritise: Review the identities with the largest blast radius first, especially privileged users, shared accounts, orphaned entries, and machine identities that can still reach production. If the account can authenticate, the next question is whether it still needs to exist in its current form.

What to verify: For each high-risk identity, verify a named owner, a current business purpose, last-use evidence, and a removal or reauthorization path. If any of those are missing, treat the entitlement as unresolved rather than temporarily acceptable.

Common mistake: Teams often start by harmonising groups and roles, then discover too late that the merged role model has preserved old excess access. Permission truth must precede standardisation, otherwise the target design simply inherits the problem.

Practitioner takeaway: After a merger, the safest posture is to assume that hidden access exists until effective permissions, ownership, and usage evidence prove otherwise.