By NHI Mgmt Group Editorial TeamBased on Zluri: “How Zluri Helps Get More ROI From Okta Investment” (June 26, 2025)

TL;DR: Automating Okta administration can reduce manual effort across onboarding, offboarding, factor enrollment, access reviews, and license cleanup, while improving visibility into dormant users and shadow IT, according to Zluri. The broader issue is that identity operations remain brittle when IAM and lifecycle work depend on repetitive human handling rather than governed automation.


At a glance

What this is: This is an Okta automation analysis showing that lifecycle tasks, factor enrolment, license cleanup, and access reviews become brittle when handled manually at scale.

Why it matters: It matters because IAM teams managing human identities, service access, and lifecycle governance need to know which operational tasks should be automated before delays and errors create security drift.


Context

Identity and access management breaks down when routine lifecycle work depends on repetitive manual handling. In this article, Zluri argues that Okta administration becomes time-consuming as organisations grow, especially for onboarding, offboarding, access changes, and user review activity.

The operational problem is not authentication alone. It is the volume of identity operations that sit around Okta, including licence tracking, factor enrolment, profile updates, and user access reviews, all of which become slower and more error-prone when the process is human-paced.


Key questions

Q: What breaks when Okta lifecycle tasks stay manual?

A: Manual lifecycle handling breaks consistency, delays deprovisioning, and leaves stale access in place longer than intended. The result is not just extra work for IT teams, but weaker governance over joiner, mover, and leaver events. Automating those tasks turns identity administration into a repeatable control instead of a queue of tickets.

Q: Why do manual SOC 2 access reviews become unreliable as SaaS use expands?

A: Manual reviews become unreliable because SaaS sprawl creates too many identity and application relationships to track accurately by hand. Access changes happen continuously through sign-ins, role changes, onboarding, offboarding, and app decommissioning. Without automation and live inventory, teams miss entitlements, overlook risky connections, and struggle to prove that only authorized users retained access during the review period.

Q: How should organisations automate MFA enrolment in an IAM workflow?

A: They should make factor enrolment part of the onboarding and access-grant process, not a separate help desk step. That lets the organisation apply enrolment consistently, reduce setup delays, and ensure users receive the right authentication controls before they reach sensitive systems. The key is to govern enrolment at identity creation time.

Q: What is the operational difference between access provisioning and licence cleanup?

A: Access provisioning grants what a user needs to work, while licence cleanup removes unused entitlements that continue to consume capacity and create governance noise. Both are lifecycle functions, but they solve different problems. Treating them separately helps teams avoid confusing active access decisions with recovery of wasted software licences.


Technical breakdown

Why manual Okta administration does not scale

Manual IAM work becomes brittle when every joiner, mover, leaver, and access change requires a human to update records, assign groups, and reconcile entitlements. In practice, the control plane is not the login flow itself but the lifecycle work around it. The article shows that licence assignment, user provisioning, access changes, and reviews all consume time and create inconsistency when teams do them one by one. That is why organisations see delays and drift long before they see a headline incident.

Practical implication: reduce repetitive lifecycle handling by automating high-frequency Okta administration tasks first.

How automated factor enrolment changes authentication operations

The article links automation to factor enrolment for MFA, biometrics, smart cards, and related authentication setup. The technical point is that factor assignment is often part of identity onboarding, not a separate security project. If enrolment is manual, it becomes a queue-dependent control that slows new-user readiness and invites exceptions. If it is automated, the organisation can apply the same enrolment logic consistently at the point of identity creation or access grant.

Practical implication: treat factor enrolment as part of onboarding workflow design, not as an afterthought for help desk teams.

Why access reviews and shadow IT discovery belong in the same workflow

Zluri's article ties Okta usage reporting, user access reviews, and discovery of other SaaS applications into one operational picture. That matters because review quality depends on whether the organisation can actually see who holds access and what else the user touches. Manual review cycles often lag behind entitlement change, while discovery data can expose inactive users and unmanaged applications sooner. The result is not just better visibility, but a tighter connection between identity governance and SaaS inventory.

Practical implication: use discovery and access review data together so governance decisions reflect current application use, not stale records.


Threat narrative

Attacker objective: The practical objective is to find lingering identity and access paths that manual administration fails to close quickly enough.

  1. Entry occurs through ordinary identity operations that are too slow or incomplete to keep pace with employee joins, moves, and departures.
  2. Credential or access abuse emerges when inactive users, stale licences, or delayed deprovisioning leave access paths open longer than intended.
  3. Impact is reduced governance quality, wider attack surface, and a higher chance that unused accounts or permissions remain available after they should have been removed.
  • Okta support system breach 2023: A support service account credential saved in a personal Google profile let attackers take HAR files and hijack five Okta customers' sessions.
  • MGM Resorts breach 2023: A help desk call gave attackers Okta and Azure admin access at MGM, leading to ransomware, ten days of outages and a $100 million hit.

Read and download The State of NHI & AI Agent Breach Report 2026, covering 150+ breaches impacting Non-Human Identities including AI Agents.


NHI Mgmt Group analysis

Manual lifecycle handling is the real control failure, not the lack of an IAM platform. The article makes clear that organisations often already have Okta, but still rely on people to process onboarding, offboarding, access changes, and reviews. That is where error, lag, and inconsistency enter the identity stack. The practitioner lesson is to treat manual administration as a governance weakness in its own right.

Access reviews lose value when entitlement data is stale by the time it is reviewed. The article's mix of licence reporting, inactive user identification, and user access reviews shows that review quality depends on current state, not periodic paperwork. If the underlying record does not reflect real usage, certification becomes a formality. Teams should view review freshness as a governance signal, not just an audit artefact.

Identity lifecycle automation is now part of security architecture. The article frames onboarding, factor enrolment, profile updates, and offboarding as operational tasks, but they are also enforcement points. When those steps are automated, control is applied at issuance and change time rather than after the fact. That shifts IAM from ticket handling toward policy execution, which is the direction mature identity programmes are already moving.

Shadow IT discovery and access governance are converging into one programme requirement. The article links SaaS discovery to Okta usage and access reviews, which is the right operational direction. If you cannot see the application footprint behind identity, you cannot judge whether entitlements are still justified. The implication is that identity governance now depends on application discovery as much as on account review.

Okta automation is a symptom of the broader move from manual IAM operations to governed workflow orchestration. This is not about replacing administrators with tools. It is about removing repetitive, human-paced handling from decisions that should be policy-driven and repeatable. The organisations that still treat lifecycle work as a help desk function will continue to carry unnecessary friction and avoidable risk.

What this signals

Lifecycle automation is becoming the baseline for manageable IAM operations: once onboarding, offboarding, factor enrolment, and permission changes are handled manually, the identity programme spends more time processing requests than enforcing policy. That shift turns routine administration into a source of delay and control drift rather than a reliability layer.

Identity governance and application discovery now depend on each other: user access reviews are only as useful as the inventory behind them, and SaaS discovery is only useful when it feeds entitlement decisions. For practitioners, that means review quality is increasingly determined by how well identity data and application usage data stay aligned.


For practitioners

  • Automate joiner-mover-leaver workflows Map onboarding, role changes, and offboarding into governed Okta workflows so access changes happen at the point of lifecycle events, not after tickets are processed.
  • Link factor enrolment to onboarding Include MFA and other factor enrolment in the identity creation flow so new users receive the right authentication setup without separate manual handling.
  • Remove stale licences on a defined schedule Use licence usage reporting to identify dormant assignments and reclaim unused Okta licences before renewals or audits expose waste and inconsistency.
  • Pair access reviews with discovery data Run user access reviews against current SaaS discovery and Okta usage data so reviewers can judge actual access rather than outdated entitlement lists.
  • Automate offboarding of groups and app access Trigger account suspension, group removal, and downstream app revocation from the same leaver event to prevent residual access after employment ends.

Key takeaways

  • Manual Okta administration creates avoidable governance drift when joiner, mover, leaver, and access tasks rely on human pacing instead of workflow control.
  • The article connects lifecycle automation with onboarding, offboarding, factor enrolment, licence cleanup, and access reviews, showing how operational load spreads across the identity stack.
  • Practitioners should treat discovery, review freshness, and lifecycle orchestration as one programme, because identity controls lose value when they operate on stale state.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

OWASP Non-Human Identity Top 10 addresses the attack and risk surface, while CIS Controls v8, NIST CSF 2.0 and NIST SP 800-53 Rev 5 set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
CIS Controls v8CIS-5 — Account ManagementThe article is about automating joiner-mover-leaver and access administration.
Recommendation — Automate account lifecycle tasks and remove manual account handling from routine access administration.
NIST CSF 2.0PR.AA-05 — Access Permissions, Entitlements and AuthorizationsOkta automation here focuses on entitlement changes, access review, and licence governance.
Recommendation — Apply PR.AA-05 to govern entitlement changes and validate access against current business need.
NIST SP 800-53 Rev 5IA-5 — Authenticator ManagementFactor enrolment and credential handling are part of the article's IAM automation scope.
Recommendation — Use IA-5 to govern authenticator lifecycle tasks such as enrolment, reset, and removal.
OWASP Non-Human Identity Top 10NHI-01 — Improper OffboardingThe article highlights automated offboarding as a control against lingering access after departure.
Recommendation — Apply NHI-01 to revoke access promptly when users leave or no longer need the account.

Key terms

  • Joiner, Mover, Leaver Workflow: A joiner, mover, leaver workflow is the process that grants, updates, and removes access as a user or identity changes state. In modern programs, the same logic should extend beyond employees to service accounts and AI agents so access does not persist after need ends.
  • Access Review: A formal process for confirming whether access is still needed and justified. In IAM programs, the review becomes an evidence-bearing control when decisions are recorded, scoped correctly, and traceable to the right reviewer, application owner, or auditor.
  • Factor enrollment: Factor enrollment is the process of adding a new trusted authentication method to an account, such as a device, push token, or software token. In IAM governance, it is a privileged identity event because it can create durable access paths that survive the original login session.
  • SaaS Discovery: SaaS discovery is the process of identifying all sanctioned and unsanctioned software-as-a-service applications in use across the organisation. It matters because cloud assurance increasingly depends on seeing where apps share data, what permissions they hold, and which identities can reach them.

Deepen your knowledge

NHI governance, identity lifecycle, and secrets management are core topics in our NHI Foundation Level course, the industry's only accredited NHI security programme. If you are building or maturing an IAM or identity governance programme, it is worth exploring.
NHIMG Editorial Note
Published by the NHIMG editorial team on June 11, 2026.
Updated on October 8, 2026.
NHI Mgmt Group, the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org