Join our Newsletter — 33% off our NHI Course
Home› FAQ› Governance, Ownership & Risk› What do MSPs get wrong when they focus…
Governance, Ownership & Risk

What do MSPs get wrong when they focus too much on devices instead of identities?

← Back to all FAQ
By NHI Mgmt Group Editorial Team Updated September 28, 2026 Domain: Governance, Ownership & Risk

A common mistake is treating device management as the main security boundary when the real control point is identity. That approach can leave access decisions fragmented across tools and makes it harder to manage user lifecycle events cleanly. MSPs that overemphasise devices often miss the governance benefits of a unified identity-first operating model.

What MSPs miss when they treat devices as the security boundary

The core mistake is assuming the device is the thing being trusted, when the real control point is the identity that is authenticated, authorised, and governed across systems. Once MSPs make the device the centre of the model, access reviews, lifecycle changes, and exception handling become fragmented. A device-first view can also hide the fact that the same identity may span multiple endpoints, applications, and sessions.

Why identity-first thinking changes the operating model

An identity-first model answers a different question: who or what is allowed to act, and under what conditions. That is why the governance burden shifts from device posture alone to identity proofing, credential quality, privilege boundaries, and lifecycle control. For managed services, that usually means standardising access decisions around identity policy, not around the health or ownership of the endpoint.

When MSPs focus too heavily on devices, they often optimise for inventory and compliance evidence rather than for access assurance. Device controls still matter, but they are supporting controls. The practical value comes from making identity the consistent layer across users, admins, service accounts, and remote access paths, including managed endpoints and shared operational tools.

Where device-centric models fail in day-to-day operations

A device-centric model usually fails in the moments that matter most: joiner, mover, leaver events, privilege changes, lost devices, and emergency access. If access is tied to device trust alone, revocation can lag behind actual job change or compromise. That creates avoidable delay in removing access and makes it harder to prove that access decisions were current at the time they were made.

This is also where MSP environments become messy, because operators often support many tenants, many toolsets, and many exception paths. Identity controls are what let the MSP separate one customer’s access from another’s, define who can do what, and keep a stable audit trail even when devices are replaced, rebuilt, or temporarily unmanaged. The device is the access surface, but the identity is the governable unit.

Risk and Threat Considerations

Device-first thinking can leave organisations with broader access than intended, especially where a trusted endpoint silently becomes a proxy for repeated authentication and privileged actions. It also makes it easier for compromised credentials, shared admin accounts, or stale access to persist even after the device posture has changed.

Failure mechanism: When policy is anchored to endpoint trust instead of identity authority, attackers and insiders can exploit valid access paths that remain active after a device is replaced, repurposed, or partially compromised.

Impact: The result is weaker revocation, slower containment, and higher blast radius across customer environments, which is especially problematic for MSPs that depend on repeatable governance and clean separation of duties.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

NIST SP 800-53 Rev 5, NIST Zero Trust (SP 800-207) and CIS Controls v8 set the technical controls, while ISO/IEC 27001:2022 defines the regulatory obligations.

FrameworkControl / ReferenceRelevance
NIST SP 800-53 Rev 5IA-2 — Identification and Authentication (Organizational Users)Identity-first MSP access depends on authenticating the person or role, not the device.
AC-6 — Least PrivilegeThe question is about overly broad access when device trust is treated as the boundary.
Recommendation — Anchor access decisions on authenticated organizational identities before granting operational access. Limit privileges to the minimum needed regardless of endpoint state.
NIST Zero Trust (SP 800-207)N/A — Zero Trust ArchitectureZero Trust directly addresses device trust being used as the security boundary.
Recommendation — Shift trust decisions to identity, context, and policy rather than endpoint presence alone.
CIS Controls v8CIS-6 — Access Control ManagementMSPs need governed identity-based access rather than fragmented device-centric approvals.
Recommendation — Centralise access control decisions and review them on an identity basis.
ISO/IEC 27001:2022A.5.16 — Identity managementIdentity management is the control area most directly implicated by the question.
Recommendation — Manage identities as the durable control point for access and lifecycle changes.

Practitioner Guidance

What to prioritise: Treat identity governance as the primary control plane and use device management as a supporting signal, not the decision boundary. If a device can be reimaged or replaced without changing the access model, the identity layer is still doing the real work.

What to verify: Check whether access can be cleanly revoked by identity, not just by device state. Verify that emergency access, admin delegation, and customer-specific access all have explicit ownership, reviewability, and expiry conditions.

Common mistake: Do not use device compliance as a proxy for entitlement correctness. A healthy endpoint can still hold excessive or stale access, and a noncompliant endpoint may still have legitimate, time-bound access that must be governed separately.

Practitioner takeaway: MSPs get this wrong when they confuse endpoint trust with access governance, the stronger model is to make identity the stable control point and let device posture inform, not replace, the decision.

Deepen Your Knowledge

Sign up to our weekly newsletter — get 33% off our NHI Foundation Level Course

    NHIMG Editorial Note
    Reviewed and updated by the NHIMG editorial team on September 28, 2026.
    NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org