TL;DR: Integration is presented as a solved problem in Fischer Identity’s latest IGA guidance series, but the deeper point is that hybrid identity programmes cannot govern what they cannot synchronise across HR, ERP, SIS, cloud, and on-prem systems. That makes interoperability a baseline control, not an implementation detail, according to Fischer Identity.
NHIMG editorial — based on content published by Fischer Identity: Integration Isn’t Optional, It’s Solved
By the numbers:
- 90% of IT leaders say properly managing NHIs is essential for a successful zero-trust implementation.
- Only 5.7% of organisations have full visibility into their service accounts.
- 96% of organisations store secrets outside of secrets managers in vulnerable locations including code, config files, and CI/CD tools.
Questions worth separating out
Q: How should security teams govern access changes across hybrid identity environments?
A: They should treat provisioning, review, and revocation as one lifecycle control loop rather than separate tasks.
Q: Why does custom code create problems in IGA programmes?
A: Custom code turns each integration into a maintenance dependency that can break during upgrades, schema changes, or policy changes.
Q: How do organisations know whether their IGA programme is actually working?
A: Look for fewer orphaned accounts, fewer unresolved SoD conflicts, and a lower rate of redundant approvals in certification campaigns.
Practitioner guidance
- Map every authoritative identity source and downstream target Identify where HR, ERP, SIS, directory, and cloud identity data diverge, then document which system owns each attribute and entitlement decision.
- Measure synchronisation latency as a governance control Set acceptable time limits for joiner, mover, and leaver propagation, then monitor where feeds miss those limits.
- Eliminate bespoke connector code where configuration will do Prioritise integrations that still rely on scripts, fragile mappings, or professional services workarounds.
What's in the full article
Fischer Identity's full blog covers the operational detail this post intentionally leaves for the source:
- A deployment-oriented walkthrough of how configuration-only connectors are positioned across cloud and on-prem systems.
- Examples of the enterprise applications Fischer says it supports natively, including HR, ERP, SIS, and service platforms.
- The maintenance argument behind real-time synchronization and why it is presented as superior to custom code in hybrid estates.
👉 Read Fischer Identity's blog on integration-driven IGA guidance →
IGA integration across hybrid systems: what practitioners should re-evaluate?
Explore further
Integration is not an IGA feature layer, it is the control plane. When identity data moves slowly or unreliably between authoritative sources and downstream systems, lifecycle governance becomes partial by design. The article is right to treat interoperability as foundational because access, certification, and audit evidence all depend on current state, not best-effort state. Practitioners should read this as a control-design problem, not a tooling preference.
A few things that frame the scale:
- Only 5.7% of organisations have full visibility into their service accounts, according to Ultimate Guide to NHIs.
- 96% of organisations store secrets outside of secrets managers in vulnerable locations including code, config files, and CI/CD tools, according to Ultimate Guide to NHIs.
A question worth separating out:
Q: Who is accountable when identity data is not synchronised?
A: Accountability sits with the team that owns identity governance, because synchronisation is a control outcome, not an optional convenience. If identity data is inconsistent across directories, no downstream application can reliably know which record to trust. That makes identity governance accountable for the failure, even if the symptom appears in authentication.
👉 Read our full editorial: Hybrid IGA integration is now a governance requirement, not a feature