TL;DR: Manual onboarding, review, and offboarding in Active Directory still produce lingering access, privilege creep, and audit gaps, according to SecurEnds. The practical shift is to treat identity lifecycle management as a governance control, not an IT convenience, because delayed deprovisioning and spreadsheet-based reviews leave accounts active after roles change or people leave.
Editorial analysis by NHI Mgmt Group, based on content published by SecurEnds: “Identity Lifecycle Management for Active Directory Users: Automate Provisioning, Reviews & Offboarding”.
Key questions
Q: What breaks when identity lifecycle management is manual in Active Directory?
A: Manual lifecycle management breaks when account creation, group changes, and offboarding rely on tickets, spreadsheets, and memory.
Q: Why do delayed offboarding processes create security risk?
A: Delayed offboarding creates security risk because access can remain active after the business relationship ends.
Q: How do you know if application access reviews are actually working?
A: Access reviews are working only when they result in measurable removal of stale accounts, roles, and integrations.
Practitioner guidance
- Tie provisioning to authoritative HR events Connect joiner and mover events to a trusted source of identity state so AD group membership changes follow role changes automatically, not through tickets.
- Automate leaver revocation paths Remove VPN, privileged group, and application access as part of the offboarding event so departure triggers a revocation workflow, not a manual follow-up.
- Replace spreadsheet reviews with live entitlement views Run user access review campaigns against current AD entitlements, including nested groups and inherited access, so reviewers certify real access instead of stale exports.
Bottom line: Manual AD lifecycle management creates privilege creep because access changes lag behind role changes and departures.
Explore further
View Full Forum → | NHI Foundation Course → | Our Services → | Read the full analysis →
Manual AD lifecycle management fails because identity state and access state drift apart. The article shows the classic pattern: onboarding pressure causes over-assignment, role moves leave old groups behind, and offboarding is delayed until someone notices. That is not just operational slippage. It is a governance failure in which the access record no longer reflects the business relationship, and practitioners should treat that mismatch as a control defect, not a housekeeping issue.
A few things that frame the scale:
- Only 20% have formal processes for offboarding and revoking API keys, and even fewer have procedures for rotating them, according to the Ultimate Guide to NHIs.
A question worth separating out:
Q: What should organisations do when AD access is still tied to tickets and spreadsheets?
A: Move the lifecycle to an authoritative workflow that links joiner, mover, and leaver events to provisioning and deprovisioning. Tickets can remain the request channel, but they should not be the control plane. The control plane has to be the governed identity record, with approvals and removals tracked centrally.
👉 Read our full editorial: Identity lifecycle management for Active Directory users is still brittle