By NHI Mgmt Group Editorial TeamBased on JumpCloud: “Build a Secure, Powerful IT Foundation That Skyrockets Growth” (October 24, 2025)

TL;DR: Fragmented IT infrastructure creates security gaps, slows onboarding and license management, and makes access governance harder to enforce, according to JumpCloud. The core issue is not tooling sprawl alone: identity, device, and automation controls break down when there is no single source of truth for access.


At a glance

What this is: This is a blog post arguing that fragmented IT infrastructure increases identity security risk by weakening central control, slowing operations, and making automation harder to apply consistently.

Why it matters: It matters because IAM, IGA, and PAM teams cannot enforce reliable access governance or lifecycle controls when identities, devices, and admin workflows are split across disconnected tools.

By the numbers:

  • The average cost of a data breach for businesses with under 500 employees is $3.31 million.
  • IT teams estimate that increasing automation could save employees an average of 11 hours per week.
  • Stolen credentials were a factor in 30% of all breaches.
  • 91% of IT admins agree that centralizing control over user identities and devices from a single platform would make their organization more secure.

Context

Fragmented IT infrastructure is a governance problem as much as an operations problem. When identities, devices, and admin workflows live across disconnected tools, there is no single source of truth for access decisions, lifecycle actions, or policy enforcement.

JumpCloud frames this as a foundation issue because manual processes and tool sprawl make consistency hard to sustain as organisations grow. For identity teams, the practical consequence is that control quality becomes uneven across users, devices, and automation paths, which raises both risk and workload.

The article is about why centralised identity and device control matters when companies scale. That is a typical mid-market pattern, not an edge case.


Key questions

Q: How should teams reduce identity risk when IT environments stay fragmented?

A: Start by identifying every place where access can be granted, changed, or revoked, then remove duplicate approval paths and orphaned controls. The objective is not tool reduction alone, but a governable identity path that covers human users, service accounts, and AI-connected workloads without gaps between systems.

Q: Why does fragmented privileged access management create more risk in complex IT environments?

A: Fragmented privileged access management creates risk because teams lose visibility into hidden identities, orphaned accounts, and inconsistent policies across environments. When controls are disconnected, access decisions become harder to audit and mistakes happen more easily. The result is broader attack surface, slower remediation, and weaker enforcement of least privilege across human, machine, and application identities.

Q: What are the signs that identity controls are too fragmented to trust?

A: Look for repeated manual onboarding, inconsistent offboarding timing, duplicate identity records, and different authentication rules in different systems. Those are strong indicators that the control plane is not coherent. When teams must reconcile access by hand, the programme is relying on effort rather than governance.

Q: What happens when automation is layered onto disconnected identity tools?

A: Automation usually becomes partial and brittle. It can complete isolated tasks, but it cannot reliably drive the full identity lifecycle if the underlying records and policies are not unified. That means organisations automate fragments of the process while the real governance gaps remain in the manual exceptions.


Technical breakdown

Why a single source of truth matters for identity governance

A single source of truth means the organisation can answer one basic question consistently: who has access to what, on which device, and under which policy. In fragmented environments, that answer is split across directories, device tools, SaaS admin consoles, and manual records. The result is policy drift, delayed revocation, and uneven enforcement of authentication and access rules. Identity governance depends on dependable inventory and lifecycle state. Without that, access reviews become snapshots of incomplete data rather than control points. The problem is not just visibility. It is that governance decisions lose reliability when the underlying identity record is distributed across multiple control planes.

Practical implication: unify identity and device records before treating access reviews or offboarding as trustworthy control points.

How fragmentation weakens access control and authentication

Fragmentation creates different security standards across tools, which makes policy enforcement inconsistent. One system may enforce strong authentication, while another still allows weaker administrative paths or delayed revocation. That creates a larger attack surface because access can persist in places the security team does not inspect often enough. In identity terms, the issue is not only authentication strength but control coherence: the same user can be governed differently depending on the platform holding the record. This is why centralised identity control is repeatedly linked to lower risk. It reduces the number of places where security exceptions can accumulate and makes entitlements easier to manage across the estate.

Practical implication: standardise authentication and access policy enforcement across all identity and device management surfaces.

Why automation only works when the control plane is unified

Automation is most effective when the underlying processes follow a shared data model and predictable lifecycle rules. In a fragmented estate, onboarding, license assignment, and permission removal are often semi-manual because no single workflow can reliably reach every system. That creates operational drag and extends the time between an identity event and the corresponding control action. Automation is therefore not just a labour-saving feature. It is the mechanism that turns identity governance from sporadic cleanup into repeatable execution. If the control plane is split, automation fragments too, and the organisation ends up automating only pieces of the workflow rather than the full lifecycle.

Practical implication: design automation around a unified identity lifecycle, not around isolated tool-specific tasks.


Threat narrative

Attacker objective: The objective is to exploit inconsistent identity governance to gain unauthorised access and move through the environment before controls catch up.

  1. Entry begins with a fragmented environment in which identity and device controls are spread across disconnected systems, leaving gaps in policy enforcement and record keeping.
  2. Credential abuse becomes easier because permissions are not governed from one place, so compromised access can persist longer than the security team expects.
  3. Impact follows as attackers or internal misconfigurations exploit the inconsistent control environment to reach sensitive data and systems with less resistance.
  • JumpCloud breach 2023: North Korean hackers breached JumpCloud and abused its device commands framework against a few customers; all admin API keys were reset.

Read and download The State of NHI & AI Agent Breach Report 2026, covering 150+ breaches impacting Non-Human Identities including AI Agents.


NHI Mgmt Group analysis

Fragmentation is an identity control problem, not just an infrastructure problem. When access state is split across multiple tools, security teams lose the ability to enforce one policy consistently across users, devices, and applications. That weakens lifecycle control, auditability, and revocation discipline at the same time. The practical conclusion is that identity security quality depends on control-plane coherence, not just on adding more tools.

The real risk is policy drift across the stack. A fragmented environment makes it easy for different systems to apply different authentication strength, access scope, and offboarding timing. That creates uneven governance even when each tool looks acceptable on its own. In NIST CSF terms, access permissions and authorisations stop behaving as a managed control set and start behaving like local exceptions.

Automation cannot compensate for a broken control model. Manual onboarding and license administration are symptoms of a larger architectural issue: the lifecycle is not unified enough to automate reliably. Once the identity record is fragmented, every workflow inherits that fragmentation. Practitioners should treat automation readiness as evidence of governance coherence, not as a separate efficiency project.

Identity blast radius grows when the foundation is inconsistent. A centralised control plane reduces the number of places where stale access, orphaned permissions, and device exceptions can hide. The identity team should therefore read infrastructure fragmentation as a multiplier on governance debt, because every disconnected tool extends the time and effort needed to prove access is correct.

What this signals

Fragmented identity governance tends to fail in the same place every time: the organisation assumes access can be managed as a series of local tool decisions, when it is really a lifecycle problem. Once that assumption breaks, onboarding, offboarding, and access review become slower and less trustworthy.

The most useful metric here is not how many tools exist, but whether the team can answer who has access, where that access is enforced, and how quickly it can be removed. If those answers differ by platform, the programme is carrying governance debt that will surface during growth.


For practitioners

  • Map every identity control point Inventory where authentication, provisioning, device trust, and offboarding are actually enforced, then identify where manual exceptions bypass the main lifecycle.
  • Consolidate access state into one authoritative record Create one operational source of truth for user identity, device posture, and application entitlement so revocation and certification are based on current state.
  • Automate the highest-friction lifecycle tasks first Prioritise onboarding, offboarding, and license assignment where manual work consumes the most time and creates the most delay between decision and enforcement.
  • Standardise authentication policy across systems Ensure that strong authentication, entitlement review, and revocation timing do not vary materially from one admin plane to another.

Key takeaways

  • Fragmented IT infrastructure weakens identity governance because access state is spread across disconnected tools and manual processes.
  • The article ties that fragmentation to both security exposure and operational drag, showing why centralised control matters for scaling safely.
  • Practitioners should prioritise a single authoritative identity record, then automate lifecycle actions on top of that foundation.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

NIST CSF 2.0, CIS Controls v8 and NIST SP 800-53 Rev 5 set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
NIST CSF 2.0PR.AA-05 — Access Permissions, Entitlements and AuthorizationsThe article is about centralising access control and reducing inconsistent entitlement management.
Recommendation — Centralise entitlement governance so access permissions are consistent across tools and lifecycle events.
CIS Controls v8CIS-5 — Account ManagementThe post focuses on identity lifecycle control, onboarding, and removal of access in a fragmented estate.
Recommendation — Standardise account provisioning, review, and removal across the full identity estate.
NIST SP 800-53 Rev 5AC-2 — Account ManagementThe article highlights inconsistent account lifecycle handling across disconnected systems.
IA-5 — Authenticator ManagementThe piece links centralised control to stronger authentication and faster access removal.
Recommendation — Apply AC-2 to keep account creation, modification, and deactivation under one governed process. Use IA-5 to govern credential issuance, rotation, and revocation from a central control point.

Key terms

  • Fragmented IT Infrastructure: An environment where identity, device, and access controls are split across multiple tools, consoles, or manual processes. The result is inconsistent policy enforcement, slower lifecycle handling, and weaker assurance that the recorded access state matches reality.
  • Single source of truth: A single source of truth is the authoritative system that holds the current state of identity and access records. In practice, it reduces reconciliation work, improves auditability, and gives security teams one place to enforce policy and detect drift.
  • Identity Lifecycle Event: A business event that changes a person’s access, obligations, or record status, such as hiring, role change, or offboarding. In HR programmes, these events often drive entitlement changes and evidence requirements, so they need to be governed as part of the identity lifecycle rather than handled as isolated paperwork.
  • Control Plane Consistency: Control plane consistency means applying the same policy logic across different channels rather than managing each surface separately. For DLP and AI governance, this reduces blind spots when data moves from email to SaaS to browser or agentic workflows, and it improves the quality of enforcement and investigation.

Deepen your knowledge

NHI governance, agentic AI identity, and machine identity lifecycle are core topics in our NHI Foundation Level course, the industry's only accredited NHI security programme. If you are building or maturing an IAM programme, it is worth exploring.
NHIMG Editorial Note
Published by the NHIMG editorial team on June 11, 2026.
Updated on October 8, 2026.
NHI Mgmt Group, the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org