Join our Newsletter — 33% off our NHI Course

What should teams do after an Entra-centric model starts showing coverage gaps?

Shift from platform-specific control to a governance layer that evaluates access across the full identity estate. That means normalising data from Entra, other IAM systems and application-native identity stores before making review or policy decisions.

Why the control model has to broaden once Entra stops covering everything

An Entra-centric review model works until it does not. Once teams discover identities, apps or entitlements living outside that boundary, the issue is not just missing visibility, it is a broken decision model. Access review, policy enforcement and exception handling need to operate on the full estate, or you will keep certifying a partial picture and miss risk hiding in adjacent systems.

The practical shift is from product-led administration to estate-wide governance. That means treating Entra as one source of identity evidence, not the definition of the control itself, and normalising records from other IAM platforms and application-native stores before you decide what should be approved, recertified or removed.

When that broader model is in place, teams can compare like with like: who the subject is, where the entitlement lives, how it is used, and whether it still matches the approved business need. Without that normalisation step, even good reviewers end up making inconsistent calls because the same person may look compliant in one system and excessive in another.

What changes in review, policy and ownership

The biggest change is that governance moves above the platform layer. A review process should follow the identity wherever it has standing access, whether that is Entra, a legacy directory, a SaaS admin console, or an app-managed account store. That is the only way to catch cross-platform privilege drift, duplicate entitlements and accounts that survive a migration but fall out of central oversight.

This also changes ownership. Platform teams can still operate the directory, but they should not be the sole source of truth for access governance. Security, IAM and application owners need a shared model for identity inventory, entitlement mapping and decision authority, because the risk now sits in the joins between systems, not just inside one control plane.

Good policy also becomes more explicit about the review unit. Teams should decide whether the control is about the person, the account, the role, the entitlement bundle, or the application-specific permission set. If that is left vague, reviewers usually default to the easiest system to query, which is how coverage gaps persist even after a cleanup effort.

How teams should build a full-coverage governance layer

The first step is inventory. Before changing approval logic, teams need a reliable list of identity sources, authoritative attributes, and entitlement stores that matter to access decisions. That usually includes Entra, but also any other IAM system, privileged admin store, and application-native directory that can grant standing access.

Next, normalise the data model so the review process can reconcile identities across systems. The point is not to force every platform into the same product schema, but to create a governance view that can answer the same questions everywhere: who has access, to what, by which mechanism, and under what ownership. The NIST Privacy Framework is a useful reminder that data classification and governance views should support the decision, not dictate it.

Then define policy logic that can survive partial coverage. If a record is outside Entra, it should not be invisible to the control, and it should not automatically inherit a weaker approval path. Teams should also preserve evidence of the source system, the review decision and the mapping back to the business owner so exceptions do not become permanent blind spots.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

NIST CSF 2.0, NIST SP 800-53 Rev 5 and CIS Controls v8 set the technical controls, while ISO/IEC 27001:2022 defines the regulatory obligations.

Framework Control / Reference Relevance
NIST CSF 2.0 GV.OV-01 — Oversight of Risk Management Strategy Broader identity governance needs enterprise oversight across all identity sources.
ID.AM-01 — Physical devices and systems are inventoried Coverage gaps begin with incomplete inventory of identity and entitlement sources.
Recommendation — Define enterprise oversight for access governance across every identity source. Inventory every identity store and entitlement source before enforcing governance.
NIST SP 800-53 Rev 5 AC-2 — Account Management Access governance must cover account lifecycle and review across all systems.
Recommendation — Apply account management controls across all identity stores, not just Entra.
ISO/IEC 27001:2022 A.5.9 — Inventory of information and other associated assets An estate-wide governance layer depends on knowing all identity and access assets.
Recommendation — Maintain an inventory of identity stores and access-related assets.
CIS Controls v8 CIS-5 — Account Management The question is about controlling accounts consistently across the full estate.
Recommendation — Standardise account governance across every identity platform and application store.

Practitioner Guidance

What to verify: Confirm that your governance layer can enumerate every active identity store before you trust the review output. If the process only sees Entra-connected subjects, it is a directory review, not an enterprise access review.

What to prioritise: Start with systems that can grant standing or administrative access outside Entra, because those gaps create the largest blast radius and are hardest to recover from after the fact.

Common mistake: Do not let migration progress be mistaken for control coverage. Teams often assume that because Entra is the standard platform, every meaningful identity now flows through it, which is exactly when orphaned app-native access survives.

Practitioner takeaway: The right response to coverage gaps is not a bigger review queue, it is a governance model that can see and judge access consistently across every place identity lives.