Join our Newsletter — 33% off our NHI Course
Home› FAQ› Governance, Ownership & Risk› When does directory synchronisation fall short for access…
Governance, Ownership & Risk

When does directory synchronisation fall short for access governance?

← Back to all FAQ
By NHI Mgmt Group Editorial Team Updated October 8, 2026 Domain: Governance, Ownership & Risk

It falls short when identity changes are mirrored in one directory but permissions remain live in downstream applications, groups, or endpoint contexts. Synchronisation keeps records aligned, but governance requires access removal everywhere it was granted. If revocation is not enforced across the full stack, the lifecycle process is only partially controlled.

Why directory synchronisation is not the same as governance

Directory synchronisation is useful for keeping identities, attributes, and group membership aligned across systems, but it is not a complete access control model. Governance starts where replication ends: proving that a user, service, or account no longer retains access in every place it was granted, including applications, SaaS entitlements, local groups, and endpoint permissions. For the broader identity lifecycle view, see IAM and IGA Basics and the Joiner-Mover-Leaver (JML) Guide.

In practice, synchronisation can keep a directory current while downstream access remains stale. That gap matters because many entitlements are granted outside the directory itself, through application roles, local admin groups, tokens, caches, delegated admin paths, or account-specific exceptions. The result is an identity record that looks accurate while effective access is still broader than intended.

As a governance control, synchronisation is only one input to lifecycle management. It supports provisioning and deprovisioning, but it does not verify that revocation actually propagated to each enforcement point. That is why access governance usually needs explicit review, certification, and closed-loop removal, not just attribute sync. Access Reviews and Certification Guide is the natural next step when you need to close that loop, and the IGA Buyer's Guide is useful when evaluating platforms that must connect those revocation paths.

Where synchronisation breaks down across the stack

The failure mode is usually partial coverage. A directory update may remove a group assignment, but the application may still hold a local role, an API token, a cached session, a synced-but-not-removed entitlement, or a secondary account in a different system. In endpoint contexts, old admin group membership or persisted local privileges can survive even after the source directory has changed.

This is why governance has to treat access as a distributed state, not a single source-of-truth field. If the control only checks whether the directory changed, it misses whether the downstream system actually enforced that change. The same issue appears with movers and leavers: a move may preserve too much access, and a leaver may be removed from the directory while residual permissions continue to function elsewhere.

That is also where role and entitlement design matters. If access is granted too widely at the role level, synchronisation can faithfully replicate the wrong access everywhere. The Role Mining and Role Design Guide is relevant because overbroad roles make downstream cleanup harder, not easier, and SoD conflicts can survive directory updates if the real grant lives in the target system.

What good access governance requires beyond sync

Good governance needs authoritative lifecycle events, connector coverage, and evidence that removal succeeded in the target system. That usually means revocation workflows, entitlement reconciliation, periodic access review, and exception handling for systems that cannot be fully automated. The directory should be treated as one control plane, not the whole control plane.

Practitioners should verify three things before trusting sync-based governance: first, that every important downstream system is connected; second, that revocation is authoritative rather than advisory; and third, that any delay or failure in propagation is visible and remediated. Where applications keep their own roles or caches, the organisation needs a reconciliation process that compares intended access with effective access, not just directory state.

When this gets overlooked, the problem is usually not that the directory was wrong. The problem is that the access model was fragmented. The Identity Visibility and Intelligence Platforms (IVIP) Guide is useful here because visibility over effective access is what exposes the gap between synced identity data and actual permissions.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

NIST SP 800-53 Rev 5, NIST CSF 2.0 and CIS Controls v8 set the technical controls, while ISO/IEC 27001:2022 defines the regulatory obligations.

FrameworkControl / ReferenceRelevance
NIST SP 800-53 Rev 5AC-2 — Account ManagementDirectory sync and access removal are account lifecycle controls.
AC-6 — Least PrivilegeOverbroad downstream permissions make synced identities retain excess access.
IA-5 — Authenticator ManagementResidual tokens and credentials can survive identity changes after directory sync.
Recommendation — Reconcile account changes and revoke stale access across all connected systems. Limit each account to the minimum permissions needed in every target system. Track and revoke authenticators when access is removed or roles change.
NIST CSF 2.0PR.AA-01 — Identities and credentials are issued, managed, verified, revoked, and audited for authorized users, services, and devicesThe question is about ensuring revocation and governance beyond directory mirroring.
Recommendation — Ensure revocation processes reach every system that can still authenticate or authorize access.
CIS Controls v8CIS-5 — Account ManagementSynchronisation gaps are account-management failures when access persists downstream.
Recommendation — Inventory accounts and remove access in all systems when lifecycle events occur.
ISO/IEC 27001:2022A.5.16 — Identity managementIdentity state must align with actual access across connected systems.
A.5.18 — Access rightsRevocation must cover rights assigned outside the directory.
A.8.2 — Privileged access rightsEndpoint and application admin rights can persist after directory changes.
Recommendation — Maintain authoritative identity records and reconcile them against effective access. Review, update, and withdraw access rights across every relevant platform. Control and remove privileged rights in downstream environments, not just in the directory.

Practitioner Guidance

What to verify: Treat any system that can grant access outside the directory as a separate revocation target. If you cannot prove that removal from the directory also removed access in the application, endpoint, or privileged context, the control is incomplete.

Decision rule: If a system issues its own roles, tokens, local groups, or cached access, require explicit deprovisioning or reconciliation there rather than assuming directory sync will clear it.

Practitioner takeaway: Synchronisation is evidence that records match, not evidence that access is gone; governance is only real when every place that can exercise the privilege has been checked or revoked.

Free weekly newsletter

Subscribe to the NHI & AI Identity Journal

The latest on NHI and Agentic AI security – articles, research, breaches, news and events every week.

Bonus 33% off our NHI Course when you subscribe.

NHIMG Editorial Note
Reviewed and updated by the NHIMG editorial team on October 8, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org