Subscribe to the Non-Human & AI Identity Journal

Notifications
Clear all

M&A onboarding and access control: are VPNs enough for day one?


(@nhi-mgmt-group)
Member Moderator
Joined: 1 year ago
Posts: 15051
Topic starter  

TL;DR: M&A onboarding can force thousands of users into enterprise systems at once, making VPN-only or VDI-led access models harder to govern than gradual hiring, according to Island. The real issue is not access speed alone but whether device posture, visibility, and least-privilege controls can scale without creating a standing trust gap.

NHIMG editorial — based on content published by Island: Updated: WWLW Ep. 18, The Case of the Graceful M&A Onboarding

By the numbers:

Questions worth separating out

Q: How should security teams handle access when onboarding users after an acquisition?

A: Security teams should separate onboarding speed from network trust.

Q: Why do M&A projects create more access risk than normal hiring?

A: M&A projects compress thousands of access decisions into a short period, often across two different policy environments.

Q: What breaks when VPNs are used as the main onboarding control?

A: VPNs can make remote access easy, but they often give users broader network reach than they actually need.

Practitioner guidance

  • Map inherited access before onboarding begins Inventory the acquired organisation’s identity sources, remote access paths, and privileged accounts before broad access is granted.
  • Enforce device posture checks at first access Require posture validation for devices used by acquired staff before they can reach internal resources.
  • Replace blanket network trust with session controls Prefer controls that limit what a user can do inside the session rather than opening the broader internal network.

What's in the full article

Island's full blog post covers the operational detail this post intentionally leaves for the source:

  • How Island Private Access was configured for the M&A onboarding workflow across the acquired workforce
  • Why the organisation chose browser-based access over VPN or VDI for day-one productivity
  • How the platform provided visibility and device posture controls without requiring additional agents on endpoints
  • What the deployment looked like in practice for staff at the acquired company

👉 Read Island's blog post on M&A onboarding with Enterprise Browser and Private Access →

M&A onboarding and access control: are VPNs enough for day one?

Explore further

View Full Forum →  |  NHI Foundation Course →



   
Quote
(@mr-nhi)
Member Moderator
Joined: 3 months ago
Posts: 14635
 

Acquisition onboarding is a standing trust problem, not just a provisioning problem. The article shows how merger activity compresses identity and access decisions into a short operational window. That window is where broad trust tends to be introduced, often before lifecycle controls are aligned across systems. The practitioner lesson is that onboarding scale must be governed as a privilege design problem, not treated as a helpdesk exercise.

A question worth separating out:

Q: How should organisations govern human and non-human access during mergers?

A: They should treat both as part of the same identity estate. Human onboarding, service account inheritance, API keys, and integration credentials can all introduce hidden access paths if they are not reviewed together. A merger is the wrong time to separate IAM from machine identity governance.

👉 Read our full editorial: M&A onboarding exposes the limits of VPN-led access models



   
ReplyQuote
Share: