Join our Newsletter — 33% off our NHI Course

What should IAM teams do when two companies use different access models?

IAM teams should establish a temporary control baseline that covers both estates, then normalise authentication, entitlement, and privileged access policies before expanding trust. The point is not to preserve both models indefinitely. It is to reduce the combined estate to one governed identity plane as quickly as possible.

Why Mixed Access Models Need a Short-Lived Common Baseline

When two companies merge or integrate, the immediate problem is not which model is “better,” but how to keep both estates governable while trust is being established. A temporary baseline should therefore standardise the minimum authentication strength, the shared entitlement review process, and the handling of privileged access across both sides until a single operating model can replace the overlap.

That baseline should be narrow, explicit, and time-boxed. The goal is to avoid permanent dual-track administration, hidden exceptions, and inconsistent account treatment that make audits, incident response, and access reviews harder once the combined environment starts behaving like one business.

What “Normalise” Means for Authentication, Entitlements, and Privileged Access

Normalisation is not a rebranding exercise. It means mapping both companies’ access concepts into one governed control plane so that authentication, role assignment, exception handling, and elevated access are judged against the same policy logic. The more the two estates differ, the more important it becomes to define a common set of rules for proofing, MFA strength, session controls, and admin approval paths.

The first practical step is usually to inventory where the models diverge, then decide which side will supply the target standard for each control domain. In practice, teams often structure the identity programme around a single operating model, while using authorisation model comparisons to decide whether roles, attributes, or policy-based controls best fit the combined estate.

Privileged access deserves separate treatment because merger states often leave too many administrators, too many break-glass paths, and too much inherited trust. A good interim pattern is to reduce standing privilege, force explicit elevation for high-risk actions, and treat old cross-domain admin paths as temporary exceptions rather than future architecture.

How Teams Avoid Turning a Transition Into Long-Term Access Debt

The real danger in a two-model environment is that the temporary bridge becomes the new normal. Once teams allow both sides to keep their own entitlement logic, admin conventions, and account lifecycle rules indefinitely, every future review becomes a reconciliation exercise instead of a control decision. The fastest path to stability is to choose one governed identity plane, then retire duplicate account logic and overlapping trust relationships as soon as the transition allows.

That usually means pairing policy harmonisation with technical consolidation. Where the access models differ because one estate is older or more fragmented, teams can use a maturity model to decide what to fix first, and programme governance to assign ownership for migration, exceptions, and decommissioning. If the combined environment includes cloud platforms, cloud privilege right-sizing helps identify where permissions still exceed the agreed baseline.

For many teams, the question is also how fast they can shrink the number of systems that hold separate truth for identities and permissions. The answer is to make consolidation measurable: fewer authoritative sources, fewer manual exceptions, fewer admin models, and fewer places where entitlement decisions can drift apart without detection.

Risk and Threat Considerations

Mixed access models create a short-term control gap that attackers and internal abuse can exploit. During transition, the most common failure mode is inconsistent privilege enforcement, where one estate is already tightened and the other still allows legacy access, stale entitlements, or overly broad admin paths.

Failure mechanism: Users, service accounts, or admins retain access under the weaker model while the stronger model is being introduced, letting excessive privilege persist across trust boundaries and making revocation or review incomplete.

Impact: The combined estate can inherit the worst properties of both models, including privilege escalation paths, audit blind spots, and slower containment if an account or admin relationship is abused.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

NIST SP 800-53 Rev 5 and CIS Controls v8 set the governance and control requirements practitioners need to meet.

Framework Control / Reference Relevance
NIST SP 800-53 Rev 5 IA-2 — Identification and Authentication (Organizational Users) Mixed access models require one consistent user authentication baseline.
AC-6 — Least Privilege Temporary dual estates should be reduced through tighter entitlement and admin scope.
IA-5 — Authenticator Management Credential and authenticator handling must be normalised during consolidation.
Recommendation — Standardise user authentication requirements across both estates. Remove excess access and constrain privileged actions to the minimum. Align authenticator lifecycle, rotation, and protection across both companies.
CIS Controls v8 CIS-6 — Access Control Management The question is about harmonising access models and governing exceptions.
CIS-5 — Account Management Merging estates requires a common account lifecycle and review process.
Recommendation — Centralise access control decisions and retire legacy access paths. Inventory, review, and decommission accounts under one lifecycle process.

Practitioner Guidance

What to prioritise: Start with the controls that change blast radius fastest, which are authentication consistency, privileged access reduction, and entitlement cleanup. If a model difference affects who can administer, approve, or bypass controls, treat it as a migration blocker rather than an acceptable variance.

What to verify: Confirm that every exception has an owner, an expiry, and a migration path. If teams cannot show which entitlements still depend on the old model, the transition is not controlled yet.

Common mistake: Keeping both access models alive because each business unit prefers its historic setup. That preserves local convenience but delays the one decision that matters, which is where the combined identity authority will ultimately live.

Practitioner takeaway: The right transition target is not coexistence, it is convergence; temporary duality is acceptable only when it is actively shrinking toward one authoritative access model.