The common mistake is depending on preconfigured devices, manual account preparation, and one-off exceptions to get users productive. That approach slows provisioning, increases configuration drift, and creates gaps between identity state and device state. Self-service onboarding, automated sync, and rule-based provisioning reduce those gaps and make lifecycle control more consistent.
Why manual onboarding and device setup break down
Manual onboarding assumes people, devices, and access paths can be assembled correctly one at a time. In practice, that creates a queue of inconsistent decisions: which account gets created first, which device image is trusted, which exceptions are allowed, and who is responsible when the setup drifts from policy. The result is slow provisioning with weak repeatability.
It also turns lifecycle control into a human memory problem. If onboarding depends on a preconfigured laptop, a ticket handoff, or a one-time spreadsheet update, the organisation is no longer managing state consistently. It is relying on people to remember to align identity, device posture, and access at the same time, which is exactly where gaps appear.
What actually goes wrong operationally
The most common failure is state mismatch. The account may exist before the device is hardened, the device may be shipped before the account is ready, or access may be granted before the user has completed all required steps. Each shortcut can be harmless in isolation, but together they produce configuration drift, orphaned exceptions, and avoidable delays in productive use.
Manual setup also makes exceptions sticky. Once a special build, temporary access path, or hand-typed configuration is used to move one user forward, that workaround often survives longer than intended. Over time, the exception becomes the process, and the organisation loses a clean baseline for provisioning, review, and deprovisioning.
That is why automation matters here: self-service onboarding, automated sync, and rule-based provisioning are not just efficiency tools. They are controls that keep identity state and device state aligned so that onboarding does not depend on ad hoc intervention.
Why the problem becomes a lifecycle and governance issue
Manual onboarding is not only slower, it is harder to govern. When setup is fragmented across help desks, endpoint teams, and application owners, no single control point reliably confirms that the right access, configuration, and ownership are all in place. That weakens auditability and makes it harder to prove that the organisation is applying the same standard to every joiner.
The governance weakness becomes more visible when people change roles, move between environments, or leave. If onboarding was never automated, offboarding and re-provisioning often inherit the same ad hoc patterns. The organisation then risks preserving outdated access, repeating old configuration errors, or missing the signal that a device and its associated access should no longer match the same trust level.
For teams building a durable onboarding process, lifecycle handling should be treated as a control plane, not an administrative task. NHI Lifecycle Management Guide is useful because it frames provisioning, rotation, and offboarding as connected lifecycle decisions rather than isolated tickets.
Risk and Threat Considerations
Manual onboarding widens the window in which an identity exists without the intended device controls, or a device exists without the intended identity controls. That creates exposure to misconfiguration, excessive privilege, and unintended persistence of access paths, especially when exceptions are used to keep work moving.
Failure mechanism: The process depends on human coordination instead of enforced policy, so identity state, device state, and access state drift apart. Attackers and insiders benefit from that drift because it is harder to detect, easier to exploit, and often left unreviewed once the user is productive.
Impact: Organisations can end up with weakly governed onboarding, delayed removal of stale access, and a larger blast radius when a device, account, or exception is compromised. The same conditions also make investigations harder because there is no consistent baseline to compare against.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
NIST CSF 2.0, NIST SP 800-53 Rev 5 and CIS Controls v8 set the technical controls, while ISO/IEC 27001:2022 defines the regulatory obligations.
| Framework | Control / Reference | Relevance |
|---|---|---|
| NIST CSF 2.0 | PR.AA-05 — Identity Management, Authentication and Access Control | Manual onboarding creates identity and access drift that this control is meant to prevent. |
| ID.AM-01 — Physical Devices and Systems Inventoried | Device setup depends on knowing which devices exist and how they are managed. | |
| Recommendation — Automate account and access provisioning so identity state stays synchronized with policy. Maintain an accurate device inventory before onboarding users onto endpoints. | ||
| NIST SP 800-53 Rev 5 | IA-5 — Authenticator Management | Onboarding often fails when credentials and authenticators are issued and tracked manually. |
| Recommendation — Automate authenticator issuance, rotation, and revocation through governed lifecycle controls. | ||
| ISO/IEC 27001:2022 | A.5.15 — Access control | Manual onboarding can bypass consistent access control decisions and approvals. |
| Recommendation — Define and enforce standard access approval and provisioning rules for all new users. | ||
| CIS Controls v8 | CIS-5 — Account Management | The issue is fundamentally about inconsistent account creation, modification, and removal. |
| Recommendation — Standardise account lifecycle handling and remove manual exceptions from provisioning. | ||
Practitioner Guidance
What to prioritise: Treat onboarding as a policy-enforced workflow, not a sequence of manual handoffs. The first objective is to make the default path repeatable enough that exceptions are rare, visible, and time-bound.
What to verify: Confirm that account creation, device trust, baseline configuration, and access assignment are all tied to one governed process with an auditable outcome. If any of those steps can be completed independently without a control check, the process is still relying on manual reconciliation.
Common mistake: Teams often automate the ticket but keep the decision manual. That reduces visible effort without fixing the underlying drift between identity and endpoint state.
Practitioner takeaway: The real measure of onboarding quality is not how fast a user gets in, but whether the organisation can prove that every new user enters through the same controlled path with no silent exceptions.
Related resources from NHI Mgmt Group
- What do sponsors get wrong when they rely on manual user onboarding for site applications?
- What do organisations get wrong when they rely on manual access reviews instead of intelligent identity analytics?
- What do organisations get wrong when they rely only on manual compliance reporting in financial services?
- What do organisations get wrong when they rely on manual offboarding checks?
Deepen Your Knowledge
Reviewed and updated by the NHIMG editorial team on September 25, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org