By NHI Mgmt Group Editorial TeamBased on JumpCloud: “Identity Is The Key to Modernizing Your MSP’s Tech Stack” (August 6, 2025)

TL;DR: As hybrid work dissolves the old perimeter, identity is becoming the primary control plane for managing users, devices, cloud apps, and conditional access across fragmented environments, according to JumpCloud. The strategic shift is real, but the governance burden now moves to identity policy, lifecycle control, and access discipline.


At a glance

What this is: This is a JumpCloud blog excerpt arguing that identity, not the network perimeter, is now the control plane for MSP-managed environments.

Why it matters: It matters because IAM teams, MSP operators, and platform architects now have to govern access, devices, SaaS, and AI-related permissions through identity policy rather than relying on perimeter assumptions.


Context

The article argues that traditional perimeter-based IT management no longer fits hybrid work, multi-device estates, and mixed cloud application usage. In that environment, identity becomes the organising layer for who can access what, from where, and under which policy conditions.

For MSPs, the governance problem is not just operational convenience. When identity becomes the primary control plane, lifecycle discipline, access policy, and conditional access logic start carrying the security burden that network location and device type used to absorb.


Key questions

Q: How should MSPs use identity as the primary control plane?

A: MSPs should anchor access, policy, and response in user identity rather than device location or network perimeter. That means entitlement decisions, conditional access, and lifecycle changes are driven from the identity layer and then enforced consistently across endpoints, SaaS apps, and other connected systems.

Q: Why does a multi-IdP environment create governance risk?

A: Multiple identity providers increase the chance that lifecycle events, group membership, and access policies drift apart across platforms. If the same user is governed differently in Microsoft 365 and Google Workspace, access decisions become inconsistent and difficult to audit.

Q: What are the signs that identity governance is not keeping pace with hybrid work?

A: Common warning signs include inconsistent access rights after role changes, weak visibility into who can reach critical systems, audit discrepancies, and access approvals that are handled manually or too slowly. If security teams cannot quickly confirm which identities have access, or if segregation of duties is regularly broken, the governance model is already lagging behind the operating reality.

Q: How should organisations decide whether to consolidate identity security tooling?

A: Organisations should consolidate when fragmented tools prevent them from tracing one identity event across authentication, privilege, and movement. The question is not how many products exist, but whether the programme can produce a single control story for the attack surface. If not, consolidation may reduce blind spots more than it reduces licences.


Technical breakdown

Why identity becomes the control plane in hybrid MSP environments

Identity-centric management means using the user identity as the anchor point for policy, access, and response across devices and applications. In practice, that replaces perimeter trust with identity-bound decisions, so access is evaluated against who the user is, what they should reach, and under which conditions. This model matters most when environments span multiple operating systems, SaaS estates, and remote users, because device location no longer tells you enough about trust.

Practical implication: design access policy around identity assertions and entitlement scope, not around network presence or device class.

Conditional access and cross-platform response for users, devices, and apps

The article points to a model where identity events can trigger responses across associated devices and applications. That is a control architecture, not a single feature: the identity provider becomes the source of policy context, while endpoint and SaaS controls execute the response. This is especially relevant where organisations use more than one identity platform, because enforcement has to remain coherent even when the identity source is fragmented.

Practical implication: map which identity events should drive access changes, then verify that the same policy outcome holds across all connected systems.

Multi-IdP governance and the risk of fragmented access control

Supporting multiple identity providers is not only an integration challenge. It creates governance drift if user lifecycle events, group membership, or conditional access rules are not normalised across platforms. The technical issue is consistency: if Microsoft 365 and Google Workspace are both in play, identity policy has to remain synchronised enough that access decisions do not diverge by platform. Without that, users inherit different trust boundaries depending on the application path.

Practical implication: establish a single governance model for identity lifecycle and access policy before adding more IdPs or client environments.


  • JumpCloud breach 2023: North Korean hackers breached JumpCloud and abused its device commands framework against a few customers; all admin API keys were reset.

Read and download The State of NHI & AI Agent Breach Report 2026, covering 150+ breaches impacting Non-Human Identities including AI Agents.


NHI Mgmt Group analysis

Identity-centric MSP management is really a governance model, not a tooling preference. The article describes a shift in where trust is anchored: away from perimeter location and toward the user identity that governs access across devices and apps. For NHIMG, that means MSPs are being asked to operationalise identity as the control plane for lifecycle, entitlements, and conditional access, which is a governance change before it is a product choice.

Conditional access becomes more valuable when it is tied to identity events, not device assumptions. When identity drives response, access can be adjusted as user context changes across a fragmented client estate. That aligns with NIST CSF access governance principles and with the practical reality that control must follow the user, not the network boundary.

Multi-IdP environments expose identity policy drift faster than single-suite estates. The article notes that modern customers commonly span Microsoft 365 and Google Workspace, which means MSPs must govern access consistently across multiple identity sources. The practitioner problem is not whether an IdP exists, but whether policy, lifecycle, and authorization remain coherent when there are several.

AI access control is emerging as part of the same identity plane. The article’s mention of conditional access to AI functionalities shows that identity governance is expanding into new runtime services, not just human sign-in flows. That places AI access under the same entitlement discipline as SaaS and device access, which is where NHI-adjacent governance begins to overlap with human IAM operations.

Identity-centric control planes can reduce tool sprawl only if lifecycle governance remains intact. Replacing multiple niche tools with integrated platforms simplifies administration, but simplification is not the same as control. If offboarding, access review, and policy exception handling are weak, consolidation merely centralises the same governance gaps. The practical conclusion is that architectural consolidation must be matched by tighter identity lifecycle control.

What this signals

Identity-centric control is becoming the practical answer to hybrid sprawl. MSPs that still think in terms of devices first will keep fighting fragmented enforcement, because the trust decision now lives in the identity layer. For reader programmes, that means access policy, offboarding, and exception handling need to be designed as one governance surface rather than separate tasks.

Multi-IdP estates are a policy-consistency problem, not just an integration problem. Once more than one identity source is in play, governance depends on whether the same lifecycle and access rules can be applied everywhere without drift. That is where many modern environments fail: the architecture looks unified, but the policy model is still split.


For practitioners

  • Define identity as the primary control plane Set policy ownership around user identity, entitlements, and access context instead of around network perimeter or device class.
  • Normalise lifecycle governance across IdPs Create one joiner-mover-leaver and access review process that applies consistently across Microsoft 365, Google Workspace, and any other client identity source.
  • Map identity-driven response paths Document which identity events should trigger access changes on endpoints, SaaS apps, and AI services so enforcement is predictable across environments.
  • Tighten conditional access for AI features Treat access to AI functionality as a governed entitlement, with policy conditions that reflect data sensitivity and user role.
  • Reduce tool sprawl without losing control Consolidate overlapping point tools only after confirming that offboarding, entitlement review, and exception handling remain enforceable.

Key takeaways

  • Identity is replacing the network perimeter as the main control point for access decisions in hybrid MSP environments.
  • The operational risk is policy drift across devices, SaaS apps, and multiple identity providers.
  • MSPs should prioritise lifecycle governance and conditional access consistency before adding more tools or identity sources.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

OWASP Non-Human Identity Top 10 addresses the attack and risk surface, while NIST CSF 2.0, NIST Zero Trust (SP 800-207) and CIS Controls v8 set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
NIST CSF 2.0PR.AA-05 — Access Permissions, Entitlements and AuthorizationsIdentity-led access decisions and entitlement governance are the article's central control theme.
Recommendation — Apply PR.AA-05 to keep access decisions tied to identity, entitlement scope, and policy conditions.
NIST Zero Trust (SP 800-207)Access decisions — Access decisionsThe article reflects zero trust logic by shifting enforcement from perimeter to identity context.
Recommendation — Base access decisions on verified identity and contextual policy rather than network location.
CIS Controls v8CIS-5 — Account ManagementThe article depends on consistent lifecycle handling across multiple identity sources.
Recommendation — Use account management controls to standardise joiner-mover-leaver handling across all IdPs.
OWASP Non-Human Identity Top 10NHI-01 — Improper OffboardingLifecycle governance is central, and inconsistent offboarding is a direct control gap.
Recommendation — Remove access promptly and consistently when users move or leave to avoid lingering entitlements.

Key terms

  • Identity Control Plane: An identity control plane is the governance layer that decides who or what can access systems and under what conditions. In practice, it coordinates authentication, authorization, privilege review, and lifecycle management across human and machine identities so access policy is enforced consistently across environments.
  • Conditional Access: Conditional access is a policy model that decides whether an action should proceed based on context such as posture, resource sensitivity, timing, and scope. For AI agents, it must be evaluated at request time so a valid credential does not automatically equal permitted behaviour.
  • Multi-IDP Environment: A multi-IDP environment uses more than one identity provider across the organisation, often because of mergers, cloud adoption, or application diversity. It can improve flexibility, but it also creates governance challenges, including inconsistent policy enforcement, fragmented visibility, and a higher risk of access drift.
  • Lifecycle Governance: Lifecycle governance is the set of controls that cover creation, assignment, review, rotation, and retirement of identities and credentials. For NHIs, it is the difference between a temporary automation asset and a persistent access risk. Strong lifecycle governance keeps ownership and expiry tied to actual business use.

Deepen your knowledge

NHI governance, agentic AI identity, and machine identity lifecycle are core topics in our NHI Foundation Level course, the industry's only accredited NHI security programme. If you are building or maturing an IAM programme, it is worth exploring.
NHIMG Editorial Note
Published by the NHIMG editorial team on June 11, 2026.
Updated on October 8, 2026.
NHI Mgmt Group, the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org