By NHI Mgmt Group Editorial TeamBased on SecurEnds: “Identity Lifecycle Management for Active Directory Users: Automate Provisioning, Reviews & Offboarding” (August 21, 2025)

TL;DR: Manual onboarding, review, and offboarding in Active Directory still produce lingering access, privilege creep, and audit gaps, according to SecurEnds. The practical shift is to treat identity lifecycle management as a governance control, not an IT convenience, because delayed deprovisioning and spreadsheet-based reviews leave accounts active after roles change or people leave.


At a glance

What this is: This is an analysis of why manual Active Directory lifecycle management breaks down, with lingering access, privilege creep, and weak review evidence as the key findings.

Why it matters: It matters because identity teams need lifecycle controls that keep entitlements aligned to role changes and departures, or they inherit audit gaps and avoidable access risk across IAM, IGA, and PAM programmes.


Context

Identity lifecycle management is the control discipline that keeps accounts, entitlements, and group memberships aligned from joiner through mover to leaver. In Active Directory, the failure mode is usually not a missing account, but access that outlives the reason it was granted.

The security gap is governance, not effort. Manual tickets, spreadsheet reviews, and email-based approvals cannot keep pace with role changes, contractors, or departures, so access drifts away from business need and audit evidence becomes fragile.

For AD environments, that drift shows up as lingering VPN access, stale privileged group membership, and reviews that certify whatever happens to be easiest to find. That is a lifecycle problem first, and an operations problem second.


Key questions

Q: What breaks when identity lifecycle management is manual in Active Directory?

A: Manual lifecycle management breaks when account creation, group changes, and offboarding rely on tickets, spreadsheets, and memory. Access becomes stale, reviews become incomplete, and departed users can retain valid permissions far longer than intended. The result is privilege creep, poor audit evidence, and unnecessary exposure across critical systems.

Q: Why do delayed offboarding processes create security risk?

A: Delayed offboarding creates security risk because access can remain active after the business relationship ends. Former users may still reach email, files, CRM, or admin tools, which expands the window for data theft or disruption. The issue is not the departure itself, but the period during which stale access still works.

Q: How do you know if application access reviews are actually working?

A: Access reviews are working only when they result in measurable removal of stale accounts, roles, and integrations. If the same privileged entitlements keep reappearing, or if reviewers cannot identify an owner or business purpose, the programme is documenting risk rather than reducing it.

Q: What should organisations do when AD access is still tied to tickets and spreadsheets?

A: Move the lifecycle to an authoritative workflow that links joiner, mover, and leaver events to provisioning and deprovisioning. Tickets can remain the request channel, but they should not be the control plane. The control plane has to be the governed identity record, with approvals and removals tracked centrally.


Technical breakdown

How manual provisioning creates access drift in Active Directory

Manual provisioning usually starts with a business request and ends with a human making judgment calls about groups, roles, and exceptions. In Active Directory, that means entitlements are often assigned by urgency rather than by policy, so the initial access set is already inconsistent. The deeper problem is that provisioning decisions are rarely tied to an authoritative source of role data. Once an account exists, later changes depend on someone remembering to remove what no longer fits. That is why lifecycle controls matter more than one-time account creation: they keep access state synchronized with employment state, not with memory.

Practical implication: tie provisioning to authoritative HR and role data instead of free-text tickets.

Why user access reviews fail when evidence lives in spreadsheets

User access review is meant to confirm that a person still needs the access they have. In manual AD programmes, the review artifact is often a spreadsheet or email chain that lacks a stable relationship to current entitlements. That breaks the control in two ways. First, reviewers cannot reliably see all active access paths, especially nested group membership. Second, the review trail becomes weak evidence because it captures a point-in-time opinion rather than a governed access record. When the evidence layer is manual, certification turns into a clerical exercise instead of a control.

Practical implication: make access reviews consume live entitlement data, not static spreadsheets.

How offboarding delays leave privileged access active after departure

Offboarding is the highest-risk point in the lifecycle because it is the moment when legitimate business need ends. If deprovisioning is delayed, the account may still authenticate, retain VPN reach, or remain inside high-value groups long after the worker or contractor has left. In an AD context, that creates a residual access window that attackers can abuse if credentials are reused or if the account is simply forgotten. The mechanism is simple: identity state changed, but access state did not. That is why offboarding must be treated as a revocation event, not an administrative task.

Practical implication: revoke AD access on leaver events as a governance control, not a cleanup task.


Threat narrative

Attacker objective: The objective is to exploit residual access that outlives its business justification, especially through stale AD accounts and unrevoked entitlements.

  1. Entry occurs when accounts are created or modified faster than governance can reconcile business need, leaving excessive group membership in place.
  2. Credential and access abuse follows when stale accounts, lingering VPN access, or over-assigned roles remain active after a move or departure.
  3. Impact appears as privilege creep, audit findings, and the possibility that dormant access becomes an attacker foothold if credentials are misused or forgotten.
  • Internet Archive breach 2024: An exposed GitLab token opened Internet Archive code and 31 million user records; unrotated Zendesk tokens let the attacker back in weeks later.

Read our 52 NHI Breaches Analysis report for a comprehensive view of breaches impacting Non-Human Identities including AI Agents.


NHI Mgmt Group analysis

Manual AD lifecycle management fails because identity state and access state drift apart. The article shows the classic pattern: onboarding pressure causes over-assignment, role moves leave old groups behind, and offboarding is delayed until someone notices. That is not just operational slippage. It is a governance failure in which the access record no longer reflects the business relationship, and practitioners should treat that mismatch as a control defect, not a housekeeping issue.

Identity lifecycle management becomes a control surface, not an IT convenience, when Active Directory is the system of record. The problem is not whether teams can create accounts quickly. The problem is whether they can prove that entitlements were assigned, reviewed, and removed in step with business events. For IAM and IGA leaders, that means lifecycle discipline is part of auditability, least privilege, and access accountability, not separate from them.

Review workflows that depend on spreadsheets create certification theater. When managers certify access from incomplete exports, they are not really validating current privilege. They are validating the quality of the spreadsheet. That weakens both access governance and evidence quality, which is why AD review programmes need authoritative entitlement data and clear ownership if they are to mean anything in practice.

Offboarding latency is the real risk signal in this article. The longer a departed user, contractor, or mover retains access, the more the organisation normalises standing privilege after the business need has ended. That is the signal practitioners should watch most closely because it reveals whether lifecycle governance is acting as a revocation control or merely a recordkeeping process.

Lifecycle discipline in AD is the bridge between human IAM and NHI governance. The same governance logic applies when credentials belong to people, service accounts, or other non-human identities: access must be tied to an owner, a purpose, and an end state. Teams that cannot govern AD users cleanly will struggle even more when the lifecycle expands to NHIs and privileged automation.

From our research library:

What this signals

Manual lifecycle controls create access debt: every day that a moved or departed user keeps the wrong entitlement increases the gap between what the organisation believes is true and what Active Directory is actually enforcing. That gap is what auditors find, and it is also what attackers can exploit when stale access persists.

Access review quality depends on the source of truth: if the review input is a spreadsheet rather than the live directory and its inherited memberships, the programme is certifying stale state. The control question is no longer whether reviews exist, but whether they operate on current entitlement data.

Lifecycle governance is converging across people and machines: the same owner, purpose, and revocation logic that cleans up Active Directory users will increasingly be expected for service accounts and other non-human identities. Organisations that cannot close the loop for humans will struggle when the same discipline is applied to automation.


For practitioners

  • Tie provisioning to authoritative HR events Connect joiner and mover events to a trusted source of identity state so AD group membership changes follow role changes automatically, not through tickets.
  • Automate leaver revocation paths Remove VPN, privileged group, and application access as part of the offboarding event so departure triggers a revocation workflow, not a manual follow-up.
  • Replace spreadsheet reviews with live entitlement views Run user access review campaigns against current AD entitlements, including nested groups and inherited access, so reviewers certify real access instead of stale exports.
  • Track dormant accounts and delayed removals Flag accounts that remain active after role change or departure and treat the delay as a governance exception that needs ownership and closure.
  • Define ownership for every AD entitlement Assign accountable owners for privileged groups and high-risk access so each entitlement has a clear decision-maker for approval, review, and removal.

Key takeaways

  • Manual AD lifecycle management creates privilege creep because access changes lag behind role changes and departures.
  • Spreadsheet-based reviews and delayed revocation weaken both security and audit evidence, especially for contractors and movers.
  • The practical fix is governed lifecycle automation, with identity state driving provisioning, review, and offboarding decisions.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

OWASP Non-Human Identity Top 10 addresses the attack and risk surface, while NIST CSF 2.0 and CIS Controls v8 set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
OWASP Non-Human Identity Top 10NHI-01 — Improper OffboardingDelayed deprovisioning is the article's main failure mode.
NHI-05 — Overprivileged NHIRole changes and rushed onboarding leave users with excess access.
NHI-09 — NHI ReuseThe article shows access being carried forward across role changes instead of being reissued cleanly.
Recommendation — Automate leaver revocation so AD access ends when employment or contract status ends. Limit AD entitlements to role-based access and remove inherited excess privileges. Treat movers as access replacement events, not additions to existing entitlement sets.
NIST CSF 2.0PR.AA-05 — Access Permissions, Entitlements and AuthorizationsAD lifecycle governance is fundamentally about keeping authorisations current.
Recommendation — Govern permissions as living authorisations and recertify them against current business need.
CIS Controls v8CIS-5 — Account ManagementThe article is about managing accounts through joiner, mover, and leaver states.
Recommendation — Centralise account lifecycle decisions and remove stale access as soon as it is no longer needed.

Key terms

  • Identity Lifecycle Governance: Identity lifecycle governance is the set of processes that create, change, review, rotate, and revoke access across human and non-human identities. It matters because access risk usually increases when lifecycle events are slow, incomplete, or disconnected from the systems that rely on them.
  • User Access Review: A user access review is a periodic check that confirms each account still needs the access it has. In identity programs, the control is used to reduce excess privilege, support compliance, and catch access that has outlived its business need.
  • Off-boarding: Off-boarding is the process of removing a departing user’s access, credentials, and related entitlements from the environment. In mature IAM programmes, it also includes reviewing sessions, shared secrets, delegated roles, and linked non-human identities so that exit events do not leave behind hidden access paths.
  • Privilege Creep: Privilege creep is the gradual accumulation of access rights beyond what an identity actually needs. It usually happens when permissions are added for convenience and never removed. For NHIs, privilege creep expands blast radius and makes old credentials far more dangerous than their original purpose suggests.

Deepen your knowledge

NHI governance, identity lifecycle management, and secrets management are core topics in our NHI Foundation Level course, the industry's only accredited NHI security programme. If you are building or maturing an IAM or identity governance programme, it is worth exploring.
NHIMG Editorial Note
Published by the NHIMG editorial team on June 25, 2026.
Updated on October 6, 2026.
NHI Mgmt Group, the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org