Join our Newsletter — 33% off our NHI Course
Home› FAQ› NHI Lifecycle Management› What happens when provisioning changes are not reconciled…
NHI Lifecycle Management

What happens when provisioning changes are not reconciled back into target systems?

← Back to all FAQ
By NHI Mgmt Group Editorial Team Updated September 27, 2026 Domain: NHI Lifecycle Management

When provisioning updates are not reflected in the target systems, the organisation ends up with two competing realities: the approved access model and the access that actually exists. That creates stale permissions, audit exceptions, and ongoing confusion for security teams. Reconciliation is what closes that loop by re-importing the live state and confirming that policy changes were actually applied.

How reconciliation turns provisioning into a closed control loop

Provisioning is only reliable when the target system’s live state is re-imported and compared against the intended policy state. Without that reconciliation step, the IAM or governance layer can say access was changed while the application, directory, or cloud service still reflects the old entitlement. The result is not just drift, it is an unresolved control gap that keeps decisions and reality out of sync.

That mismatch is especially important where access is replicated across multiple systems, because a failed update in one target can leave a user, service, or privileged account with permissions that no longer match the approved model. In practice, reconciliation is what confirms whether the change actually landed, whether downstream connectors behaved as expected, and whether exception handling is needed.

When reconciliation succeeds, it becomes the evidence that provisioning is not merely requested but enforced. It also helps distinguish genuine policy design from a connector failure, a delayed sync, or a partial update that would otherwise stay hidden until an audit, incident, or access review exposes it.

What stale target state does to access governance

Unreconciled changes create stale permissions, orphaned entitlements, and false confidence in certifications. A review can appear clean on paper while the target system still grants access, which means the organisation may continue operating with privileges that should have been removed or narrowed. That is why reconciliation matters most after moves, role changes, offboarding, emergency access removal, and privilege reduction.

This also affects detective controls. If the governance system thinks an entitlement was removed, security teams may stop watching for it, rotate adjacent controls too early, or assume the access path is closed. When the target state is not verified, access reviews become weaker, incident scoping becomes slower, and separation-of-duties exceptions can persist unnoticed.

In environments with automated provisioning, the live target state must be treated as the source of truth for closure, even when the approved record suggests the change was successful. A reconciliation failure is therefore an operational signal, not a paperwork issue.

Why un-reconciled provisioning is a security problem, not just an admin problem

Reconciliation gaps are a common path to privilege creep because old access survives longer than intended, often in places that are not checked every day. They also make access removals less trustworthy, which is a serious problem when the access involves administrative roles, application entitlements, shared accounts, or machine credentials that can be reused elsewhere. For broader lifecycle context, see Joiner-Mover-Leaver (JML) Guide and IAM and IGA Basics.

It also weakens auditability. If the control plane cannot prove the target system matched the approved change set, then the organisation has to rely on process claims rather than observed state. That is a familiar failure mode in identity governance, because the control objective is not simply to request provisioning, but to verify that entitlement state was actually changed and stayed changed.

Where lifecycle events are involved, the risk escalates quickly. Offboarding that is not reconciled can leave old access alive, and mover events can leave users with both their new role and the access tied to their old role. That is how policy drift becomes active exposure.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

NIST SP 800-53 Rev 5 sets the technical controls, while ISO/IEC 27001:2022 defines the regulatory obligations.

FrameworkControl / ReferenceRelevance
NIST SP 800-53 Rev 5AC-2 — Account ManagementReconciliation supports account and entitlement lifecycle accuracy.
AC-6 — Least PrivilegeStale target state preserves excess access beyond approved need.
AU-2 — Event LoggingChange and reconciliation evidence depends on recorded provisioning activity.
Recommendation — Verify account changes and review live access state after provisioning updates. Reconcile entitlements promptly to remove access beyond least privilege. Log provisioning outcomes and reconciliation results for auditability.
ISO/IEC 27001:2022A.5.16 — Identity managementIdentity records must align with actual access in target systems.
A.5.18 — Access rightsAccess rights need periodic verification against live system state.
Recommendation — Maintain identity records that reflect current access in target systems. Review and confirm access rights after provisioning changes.

Practitioner Guidance

What to verify: Treat every provisioning change as incomplete until the target system has been re-imported and matched against the intended entitlement state. If the platform cannot show post-change validation, treat the access outcome as uncertain rather than successful.

What to prioritise: Focus first on high-impact changes, especially privileged access, offboarding, role reductions, and shared or reused credentials. Those are the changes most likely to create security exposure when the live state diverges from the record.

What good looks like: A mature process produces a clear reconciliation result, a reason for any mismatch, and a durable trail showing whether the change was applied, delayed, or failed. The useful signal is not just that provisioning ran, but that the target state was confirmed.

Practitioner takeaway: If reconciliation is missing, do not assume the entitlement change happened, because the organisation may be operating on an approved model that no longer matches who can actually do what.

Deepen Your Knowledge

Sign up to our weekly newsletter — get 33% off our NHI Foundation Level Course

    NHIMG Editorial Note
    Reviewed and updated by the NHIMG editorial team on September 27, 2026.
    NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org