By NHI Mgmt Group Editorial TeamDomain: Cyber SecuritySource: IslandPublished August 22, 2025

TL;DR: M&A onboarding can force thousands of users into enterprise systems at once, making VPN-only or VDI-led access models harder to govern than gradual hiring, according to Island. The real issue is not access speed alone but whether device posture, visibility, and least-privilege controls can scale without creating a standing trust gap.


At a glance

What this is: The article argues that M&A onboarding creates a sharp access-governance problem because organisations must onboard large acquired workforces quickly while still controlling visibility and device posture.

Why it matters: This matters to IAM practitioners because high-volume onboarding can stress identity, access, and endpoint control assumptions at the same time, especially when human identities and device trust are introduced in a compressed timeline.

By the numbers:

👉 Read Island's blog post on M&A onboarding with Enterprise Browser and Private Access


Context

M&A onboarding is an access control problem as much as an integration problem. When two organisations combine, identity sprawl, device trust, and application access all need to be reconciled quickly, often before the normal lifecycle and review processes have settled. In practice, this creates a short window where access is needed immediately but governance maturity is still incomplete.

For IAM teams, the point is not whether a browser-based access layer is convenient. The real question is whether the merged environment can deliver day-one productivity without weakening controls around authentication, device posture, and privileged reach. That is the same pattern seen in broader identity programmes where rapid access expansion outpaces control visibility, especially in identity governance and NHI-adjacent environments.


Key questions

Q: How should security teams handle access when onboarding users after an acquisition?

A: Security teams should separate onboarding speed from network trust. Grant access in stages, validate device posture before production access, and prefer session-scoped controls over broad VPN reach. The goal is to avoid creating a temporary flat trust zone while identity sources, policies, and endpoint standards are still being aligned.

Q: Why do M&A projects create more access risk than normal hiring?

A: M&A projects compress thousands of access decisions into a short period, often across two different policy environments. That compression increases the chance of inherited over-permissioning, inconsistent device standards, and undocumented accounts. Normal hiring is easier to govern because controls can scale gradually instead of being forced to absorb an entire workforce at once.

Q: What breaks when VPNs are used as the main onboarding control?

A: VPNs can make remote access easy, but they often give users broader network reach than they actually need. In merger scenarios, that creates a trust gap because access is expanded before the organisation has full visibility into devices, entitlements, and application needs. The result is convenience without enough containment.

Q: How should organisations govern human and non-human access during mergers?

A: They should treat both as part of the same identity estate. Human onboarding, service account inheritance, API keys, and integration credentials can all introduce hidden access paths if they are not reviewed together. A merger is the wrong time to separate IAM from machine identity governance.


Technical breakdown

Why M&A onboarding breaks traditional access models

Traditional onboarding assumes a steady flow of new users, not a sudden influx of thousands of accounts from an acquisition. VPNs and VDI can extend reach into internal resources, but they often do so by creating broad connectivity first and then relying on downstream controls to limit misuse. That model is fragile when identity sources, endpoint standards, and access expectations differ between the two organisations. The technical challenge is to bind authentication, application reach, and device trust together fast enough to avoid a temporary over-permissioned state.

Practical implication: merge access paths only after you can enforce consistent authentication and device trust decisions across both organisations.

How browser-mediated access changes the control plane

An enterprise browser can shift access from network-centric to session-centric control. Instead of giving a device a wide network foothold, the control plane can restrict what the session can see, how it interacts with internal resources, and what posture conditions must be met before access is granted. That matters in M&A contexts because you are dealing with unfamiliar endpoints, mixed policy baselines, and users who need immediate productivity. The security value comes from reducing ambient trust, not from simply replacing one remote access method with another.

Practical implication: evaluate whether the access layer enforces session-scoped controls rather than merely delivering network connectivity.

Why visibility and posture controls matter more during acquisition integration

Acquisition onboarding amplifies blind spots because the acquirer inherits users, devices, and access patterns it does not fully understand. Device posture controls, application visibility, and policy consistency become the difference between controlled onboarding and unmanaged exposure. This is especially important when access must be granted before endpoint standardisation is complete. The governance lesson is that onboarding speed should never come at the cost of losing the ability to observe who has access, from what device, and under which policy.

Practical implication: require visibility into sessions and device posture before extending production access to acquired users.


NHI Mgmt Group analysis

Acquisition onboarding is a standing trust problem, not just a provisioning problem. The article shows how merger activity compresses identity and access decisions into a short operational window. That window is where broad trust tends to be introduced, often before lifecycle controls are aligned across systems. The practitioner lesson is that onboarding scale must be governed as a privilege design problem, not treated as a helpdesk exercise.

M&A identity sprawl: the hidden risk is the inherited access estate, not the new login flow. When two organisations merge, the new risk surface includes legacy accounts, duplicated roles, and inconsistent access paths. That is why IAM teams need a clear view of inherited entitlements before they decide how users will connect. In identity programmes, the first failure is usually not authentication, but uncertainty about what access already exists and who can still reach it.

Session-level control is becoming a practical requirement for post-merger access governance. Browser-mediated access reflects a broader shift away from trusting the network as the security boundary. For organisations under M&A pressure, session-scoped controls can reduce the temptation to solve onboarding with a blanket VPN or flat internal reach. The practitioner conclusion is that access architecture should support controlled productivity without expanding lateral movement potential.

This use case also intersects with identity lifecycle governance for both human and non-human identities. Large-scale onboarding is not only about employees. Merger environments also inherit service accounts, integrations, and automation credentials that often receive less scrutiny than human access. That makes the acquisition period a useful test of whether the organisation can govern the full identity estate. The practitioner conclusion is to review human and non-human access together, not as separate workstreams.

The governance signal here is that speed is now an access-control requirement, but not a control substitute. Organisations increasingly need day-one productivity after an acquisition, yet they still have to preserve visibility, device posture, and least privilege. The field implication is that zero trust thinking is becoming operational rather than aspirational in merger integration. The practitioner conclusion is to treat onboarding speed as something controls must enable, not override.

What this signals

M&A identity sprawl: acquisition programmes expose a familiar governance weakness, namely that access can expand faster than visibility can keep up. That is true for both human users and inherited machine identities, which is why merger integration should be treated as an identity lifecycle event, not just a systems migration. The useful signal for practitioners is whether they can still explain who has access, from what device, and under which policy after the first wave of onboarding.

Browser-mediated access is one of several ways organisations are trying to reduce the gap between productivity and control during integration. The important question is not whether a browser replaces VPN in every case, but whether the access model preserves session visibility and limits lateral movement. For identity teams, that aligns with the broader zero trust direction described in NIST SP 800-53 Rev 5 Security and Privacy Controls and the idea that trust should be granted narrowly, not by default.

The more useful operating test is whether onboarding can be completed without creating a shadow entitlement layer that nobody fully owns. If service accounts, legacy integrations, and temporary access paths are folded into the same integration plan, the programme can avoid future cleanup debt. That is where the Ultimate Guide to NHIs , Key Challenges and Risks becomes relevant for merger teams as well as IAM teams.


For practitioners

  • Map inherited access before onboarding begins Inventory the acquired organisation’s identity sources, remote access paths, and privileged accounts before broad access is granted. Prioritise application-by-application review so you can identify where access can be limited to session scope instead of network scope.
  • Enforce device posture checks at first access Require posture validation for devices used by acquired staff before they can reach internal resources. Use the same checks for laptops, contractors, and temporary access paths so there is one policy baseline rather than a parallel onboarding exception.
  • Replace blanket network trust with session controls Prefer controls that limit what a user can do inside the session rather than opening the broader internal network. This reduces the blast radius if an acquired endpoint is compromised or misconfigured during integration.
  • Review human and non-human identities together Include service accounts, API keys, and integration credentials in the merger workstream, not just employee accounts. M&A often hides dormant or duplicated machine access that can persist after the human onboarding project is complete.

Key takeaways

  • M&A onboarding is an identity governance issue because rapid access expansion can outpace visibility, posture, and entitlement review.
  • The article’s core lesson is that VPN-style convenience can widen trust faster than organisations can verify devices, sessions, and inherited access.
  • Practitioners should treat merger integration as a full identity estate review, including human accounts, service accounts, and access paths.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

NIST CSF 2.0, NIST SP 800-53 Rev 5, NIST Zero Trust (SP 800-207), CIS Controls v8 and NIST AI RMF set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
NIST CSF 2.0PR.AC-4M&A onboarding depends on managing access permissions across merged environments.
NIST SP 800-53 Rev 5AC-6Least-privilege control is central to limiting broad access during merger onboarding.
NIST Zero Trust (SP 800-207)Zero trust architecture fits the session-based access model discussed in the article.
CIS Controls v8CIS-5 , Account ManagementAccount inventory and lifecycle control are critical when absorbing a new workforce.
NIST AI RMFGOVERNGovernance matters when access decisions are compressed into a merger timeline.

Use the GOVERN function to assign ownership for onboarding risk, policy alignment, and access exceptions.


Key terms

  • M&A onboarding: The process of bringing users, devices, applications, and access policies from an acquired organisation into the acquirer’s operating environment. It is not just account creation. It includes identity reconciliation, trust decisions, and lifecycle cleanup across both human and machine access.
  • Session-Scoped Access: Session-scoped access is permission that exists only for a defined task or time window and is expected to end when the task ends. For NHI governance, it reduces lingering authority and makes AI-driven activity easier to review, revoke, and investigate when behaviour changes.
  • Device Posture: The current security condition of a device or runtime at the moment access is requested or renewed. Posture can include patch state, protection status, integrity, and whether the endpoint is managed. In identity governance, posture is part of the trust decision, not a separate endpoint problem.
  • Identity Sprawl: Identity sprawl is the uncontrolled growth of identities, entitlements, and credentials across an environment. For NHIs, it usually appears when automation creates accounts faster than governance teams can inventory, review, and remove them. The result is hidden access, weak accountability, and a wider attack surface.

What's in the full article

Island's full blog post covers the operational detail this post intentionally leaves for the source:

  • How Island Private Access was configured for the M&A onboarding workflow across the acquired workforce
  • Why the organisation chose browser-based access over VPN or VDI for day-one productivity
  • How the platform provided visibility and device posture controls without requiring additional agents on endpoints
  • What the deployment looked like in practice for staff at the acquired company

👉 Island's full post covers the M&A onboarding workflow, access model choice, and device posture controls.

Deepen your knowledge

The NHI Foundation Level course, the industry's only accredited NHI security programme, covers NHI governance, machine identity security, and identity lifecycle controls. It is useful for practitioners who need to connect identity decisions to wider access governance and operational risk.
NHIMG Editorial Note
Published by the NHIMG editorial team on August 2, 2026.
NHI Mgmt Group — the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org