Join our Newsletter — 33% off our NHI Course
Home› FAQ› Governance, Ownership & Risk› What should organisations do when AD access is…
Governance, Ownership & Risk

What should organisations do when AD access is still tied to tickets and spreadsheets?

← Back to all FAQ
By NHI Mgmt Group Editorial Team Updated October 6, 2026 Domain: Governance, Ownership & Risk

Move the lifecycle to an authoritative workflow that links joiner, mover, and leaver events to provisioning and deprovisioning. Tickets can remain the request channel, but they should not be the control plane. The control plane has to be the governed identity record, with approvals and removals tracked centrally.

Why tickets and spreadsheets stop being enough for AD lifecycle control

Tickets and spreadsheets are fine as intake and tracking aids, but they do not create a reliable control plane for access. The problem is not only operational delay, it is loss of authoritative state: who should have access, who still has it, and whether removal actually happened. When that state lives outside the governed identity record, joiner, mover, and leaver actions become hard to enforce consistently.

The practical shift is to treat the ticket as a request, not as the system of record. Provisioning, modification, and deprovisioning should be driven from an authoritative workflow that can update access centrally, preserve approvals, and support auditability across the full lifecycle. That makes the identity record the source of truth rather than a collection of disconnected artefacts.

What changes when the identity record becomes the control plane?

Once the identity record is authoritative, access decisions become lifecycle events instead of one-off manual tasks. A mover event can trigger entitlement changes, a leaver event can trigger revocation, and approvals can be tied to the same governed record that reflects the current access state. This reduces the common gap where a ticket closes but the underlying account or entitlement remains active.

The key design point is separation of concerns. Requests may still arrive through service management, but the enforcement point should be identity governance, directory workflow, or PAM-adjacent controls that can execute and verify the change. That is what turns a process into a control.

For organisations that need a prescriptive control model, CIS Controls v8 is useful for framing account management and access control as operational safeguards, while NIST SP 800-53 Rev 5 Security and Privacy Controls aligns well where identity lifecycle, access enforcement, and audit evidence all need to be demonstrable. In mature identity programs, this is also where ISO/IEC 27001:2022 Information Security Management helps anchor the need for repeatable access governance rather than ad hoc administration.

What good looks like in practice

Good practice is not “fewer tickets”, it is a shorter and more reliable path from request to verified state change. A strong model has one governed identity record, automated provisioning and deprovisioning where possible, explicit approval history, and evidence that removals were completed rather than merely requested. The access state should be reconstructible without chasing email threads or spreadsheet versions.

For organisations modernising the workflow, the useful question is whether the process can prove three things: the request was authorised, the change was executed against the real system, and the resulting access state matches policy. If any of those are missing, the ticket is only recording intent. For workflow design and control validation, NCSC UK Advice and Guidance is a helpful reference point for operational discipline, and NIST Cybersecurity Framework 2.0 provides a broader governance lens for establishing, operating, and checking the control.

Risk and Threat Considerations

When AD access is still managed through tickets and spreadsheets, the main risk is stale or unverified access. That creates a control gap where leavers may retain accounts, movers may keep old entitlements, and privileged access may persist long after the business need has ended. In a compromise scenario, the same gap makes it harder to see whether access was intentionally granted or simply never removed.

Failure mechanism: Manual handoffs and disconnected records let provisioning and deprovisioning drift apart, so the directory can remain out of sync with the approved access decision.

Impact: Orphaned access, privilege accumulation, delayed revocation, and weaker audit evidence, all of which increase the blast radius of both insider misuse and account compromise.

For threat modelling, this is closely related to privilege persistence and lateral movement risk. The longer access survives beyond the business need, the more opportunity exists for abuse, especially where service accounts, admin groups, or shared credentials are involved. MITRE ATT&CK Enterprise Matrix is a useful lens for thinking about how stale access supports credential access, privilege escalation, and downstream movement.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

MITRE ATT&CK addresses the attack surface, NIST SP 800-53 Rev 5 and CIS Controls v8 set the technical controls, and ISO/IEC 27001:2022 defines the regulatory obligations.

FrameworkControl / ReferenceRelevance
NIST SP 800-53 Rev 5AC-2 — Account ManagementAD lifecycle control depends on governed account creation, change, and removal.
AC-6 — Least PrivilegeTickets and spreadsheets often leave excess access in place beyond business need.
Recommendation — Use AC-2 to automate account lifecycle actions and verify revocation from the authoritative record. Apply AC-6 to restrict entitlements and remove unnecessary AD privileges promptly.
CIS Controls v8CIS-5 — Account ManagementThis question is fundamentally about controlling user account lifecycle and access governance.
Recommendation — Implement account lifecycle controls so requests do not become the control plane.
ISO/IEC 27001:2022A.5.15 — Access controlAn authoritative workflow is an access-control governance requirement, not just an admin convenience.
Recommendation — Define access-control rules that require centrally governed provisioning and removal.
MITRE ATT&CKT1078 — Valid AccountsStale AD access can be abused as valid accounts for persistence and lateral movement.
Recommendation — Monitor for valid-account abuse and reduce exposure by revoking unused access quickly.

Practitioner Guidance

What to prioritise: Move first on leaver and privilege-change events, because those have the highest exposure if they fail. If the workflow can only be improved in one area initially, start where revocation and elevated access are most time-sensitive.

What to verify: Confirm that every access change has a source request, an approver, an execution record, and post-change state verification. If you cannot show the before-and-after account state from the authoritative record, the control is not yet trustworthy.

Common mistake: Preserving spreadsheet ownership because it feels easier than changing the directory or governance workflow. The spreadsheet may remain useful for exception tracking, but it should never be the place where access truth lives.

Practitioner takeaway: The goal is not to eliminate tickets, it is to ensure that human request handling sits above a governed identity workflow that can actually enforce, verify, and evidence the change.

Free weekly newsletter

Subscribe to the NHI & AI Identity Journal

The latest on NHI and Agentic AI security – articles, research, breaches, news and events every week.

Bonus 33% off our NHI Course when you subscribe.

NHIMG Editorial Note
Reviewed and updated by the NHIMG editorial team on October 6, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org