Join our Newsletter — 33% off our NHI Course
Home› FAQ› NHI Lifecycle Management› What do organisations get wrong when they rely…
NHI Lifecycle Management

What do organisations get wrong when they rely on manual onboarding and device setup?

← Back to all FAQ
By NHI Mgmt Group Editorial Team Updated September 25, 2026 Domain: NHI Lifecycle Management

The common mistake is depending on preconfigured devices, manual account preparation, and one-off exceptions to get users productive. That approach slows provisioning, increases configuration drift, and creates gaps between identity state and device state. Self-service onboarding, automated sync, and rule-based provisioning reduce those gaps and make lifecycle control more consistent.

Why manual onboarding and device setup break down

Manual onboarding assumes people, devices, and access paths can be assembled correctly one at a time. In practice, that creates a queue of inconsistent decisions: which account gets created first, which device image is trusted, which exceptions are allowed, and who is responsible when the setup drifts from policy. The result is slow provisioning with weak repeatability.

It also turns lifecycle control into a human memory problem. If onboarding depends on a preconfigured laptop, a ticket handoff, or a one-time spreadsheet update, the organisation is no longer managing state consistently. It is relying on people to remember to align identity, device posture, and access at the same time, which is exactly where gaps appear.

What actually goes wrong operationally

The most common failure is state mismatch. The account may exist before the device is hardened, the device may be shipped before the account is ready, or access may be granted before the user has completed all required steps. Each shortcut can be harmless in isolation, but together they produce configuration drift, orphaned exceptions, and avoidable delays in productive use.

Manual setup also makes exceptions sticky. Once a special build, temporary access path, or hand-typed configuration is used to move one user forward, that workaround often survives longer than intended. Over time, the exception becomes the process, and the organisation loses a clean baseline for provisioning, review, and deprovisioning.

That is why automation matters here: self-service onboarding, automated sync, and rule-based provisioning are not just efficiency tools. They are controls that keep identity state and device state aligned so that onboarding does not depend on ad hoc intervention.

Why the problem becomes a lifecycle and governance issue

Manual onboarding is not only slower, it is harder to govern. When setup is fragmented across help desks, endpoint teams, and application owners, no single control point reliably confirms that the right access, configuration, and ownership are all in place. That weakens auditability and makes it harder to prove that the organisation is applying the same standard to every joiner.

The governance weakness becomes more visible when people change roles, move between environments, or leave. If onboarding was never automated, offboarding and re-provisioning often inherit the same ad hoc patterns. The organisation then risks preserving outdated access, repeating old configuration errors, or missing the signal that a device and its associated access should no longer match the same trust level.

For teams building a durable onboarding process, lifecycle handling should be treated as a control plane, not an administrative task. NHI Lifecycle Management Guide is useful because it frames provisioning, rotation, and offboarding as connected lifecycle decisions rather than isolated tickets.

Risk and Threat Considerations

Manual onboarding widens the window in which an identity exists without the intended device controls, or a device exists without the intended identity controls. That creates exposure to misconfiguration, excessive privilege, and unintended persistence of access paths, especially when exceptions are used to keep work moving.

Failure mechanism: The process depends on human coordination instead of enforced policy, so identity state, device state, and access state drift apart. Attackers and insiders benefit from that drift because it is harder to detect, easier to exploit, and often left unreviewed once the user is productive.

Impact: Organisations can end up with weakly governed onboarding, delayed removal of stale access, and a larger blast radius when a device, account, or exception is compromised. The same conditions also make investigations harder because there is no consistent baseline to compare against.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

NIST CSF 2.0, NIST SP 800-53 Rev 5 and CIS Controls v8 set the technical controls, while ISO/IEC 27001:2022 defines the regulatory obligations.

FrameworkControl / ReferenceRelevance
NIST CSF 2.0PR.AA-05 — Identity Management, Authentication and Access ControlManual onboarding creates identity and access drift that this control is meant to prevent.
ID.AM-01 — Physical Devices and Systems InventoriedDevice setup depends on knowing which devices exist and how they are managed.
Recommendation — Automate account and access provisioning so identity state stays synchronized with policy. Maintain an accurate device inventory before onboarding users onto endpoints.
NIST SP 800-53 Rev 5IA-5 — Authenticator ManagementOnboarding often fails when credentials and authenticators are issued and tracked manually.
Recommendation — Automate authenticator issuance, rotation, and revocation through governed lifecycle controls.
ISO/IEC 27001:2022A.5.15 — Access controlManual onboarding can bypass consistent access control decisions and approvals.
Recommendation — Define and enforce standard access approval and provisioning rules for all new users.
CIS Controls v8CIS-5 — Account ManagementThe issue is fundamentally about inconsistent account creation, modification, and removal.
Recommendation — Standardise account lifecycle handling and remove manual exceptions from provisioning.

Practitioner Guidance

What to prioritise: Treat onboarding as a policy-enforced workflow, not a sequence of manual handoffs. The first objective is to make the default path repeatable enough that exceptions are rare, visible, and time-bound.

What to verify: Confirm that account creation, device trust, baseline configuration, and access assignment are all tied to one governed process with an auditable outcome. If any of those steps can be completed independently without a control check, the process is still relying on manual reconciliation.

Common mistake: Teams often automate the ticket but keep the decision manual. That reduces visible effort without fixing the underlying drift between identity and endpoint state.

Practitioner takeaway: The real measure of onboarding quality is not how fast a user gets in, but whether the organisation can prove that every new user enters through the same controlled path with no silent exceptions.

Deepen Your Knowledge

Sign up to our weekly newsletter — get 33% off our NHI Foundation Level Course

    NHIMG Editorial Note
    Reviewed and updated by the NHIMG editorial team on September 25, 2026.
    NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org