Join our Newsletter — 33% off our NHI Course

Identity consolidation at acquisition speed: what IAM teams should note

 

(@nhi-mgmt-group)
Member Moderator
Joined: 1 year ago
Posts: 21730
Topic starter  

TL;DR: Accenture’s identity standardisation across nearly 100 acquisitions in two years included centralising phishing-resistant authentication for 2,000 end users and reducing highly privileged AD admin accounts by about 50%, according to Axiad. The case shows that acquisition velocity makes identity governance an operational scaling problem, not a back-office control exercise.

Editorial analysis by NHI Mgmt Group, based on content published by Axiad: “Why Accenture Is Axiad's 2025 Customer of the Year”.

By the numbers:

  • Accenture deployed centralized phishing-resistant MFA to 2,000 end users across multiple AD environments.
  • Accenture reduced highly privileged AD admin accounts by about 50%.

Key questions

Q: How should security teams govern identity across acquired Active Directory environments?

A: They should standardise authentication and administrative control before expecting full technical consolidation.

Q: Why do acquired directories create more identity risk than a single clean environment?

A: Each inherited directory brings its own policies, admin accounts, exceptions, and migration delays.

Q: What breaks when privileged AD accounts are left untouched during acquisition integration?

A: The control plane stays fragmented.

Practitioner guidance

  • Standardize acquisition onboarding on one authentication pattern Define a corporate authentication standard that newly acquired environments must converge to immediately, even if directory migration is still in progress.
  • Deploy phishing-resistant MFA as the interim control Use phishing-resistant MFA to close the highest-risk login gap before the full directory transition is finished.
  • Rationalize highly privileged AD accounts Inventory administrative accounts across inherited directories and remove roles that duplicate corporate control functions.

Bottom line: Accenture’s acquisition pace shows that identity governance becomes a live integration discipline when organisations absorb many environments in a short period.

Explore further

View Full Forum →  |  NHI Foundation Course →  |  Our Services →  |  Read the full analysis →


This topic was modified 4 days ago by NHI Mgmt Group

   
Quote
(@mr-nhi)
Member Moderator
Joined: 5 months ago
Posts: 21566
 

Identity consolidation is now an M&A control plane problem, not an IT migration project. When nearly 100 acquisitions happen in two years, the question is not whether identity should be standardised, but how quickly the enterprise can impose one trust model across inherited environments. The governance burden sits with authentication, privilege, and directory control at the point of integration. The practitioner conclusion is simple: acquisition velocity should be measured against identity convergence speed, not just legal close dates.

A question worth separating out:

Q: When should organisations prioritize phishing-resistant MFA in merger integration plans?

A: Prioritize it immediately when newly acquired users must be onboarded before full directory migration is complete. That is the point where password reuse, inconsistent local controls, and weak verification create the most risk. Stronger authentication should come before comfort with temporary exceptions hardens into a permanent operating model.

👉 Read our full editorial: Accenture's identity consolidation shows how authentication scales


This post was modified 4 days ago by NHI Mgmt Group

   
ReplyQuote
Share:

Free weekly newsletter

Subscribe to the NHI & AI Identity Journal

The latest on NHI and Agentic AI security – articles, research, breaches, news and events every week.

Bonus 33% off our NHI Course when you subscribe.