When the main issue is who can access what, when, and for how long rather than unsupported federation or a broken authentication layer. If the IdP already meets sign-in needs, adding governance is usually faster, cheaper, and less disruptive than replacing the foundation.
Why the access-governance question comes before an IdP migration
Organisations should prioritise access governance when the real problem is entitlement sprawl, weak ownership, stale access, or poor review discipline rather than a broken sign-in layer. An IdP migration changes where users authenticate; access governance changes whether the right identities still have the right access after onboarding, movement, exceptions, and offboarding.
That distinction matters because the fastest path to risk reduction is usually to control existing access paths first. If the current IAM and IGA Basics model is already workable for authentication, then the bigger security gain comes from tightening authorisation, review, and recertification before you re-platform the login experience.
In practice, access governance is the better first investment when teams can already enforce federation, MFA, and basic session controls but still cannot answer simple questions such as who has access, why they have it, and whether it should still exist. That is especially true when privilege accumulation has occurred over time, because migration alone does not remove accumulated entitlements or fix role design.
Strong governance also gives you a cleaner decision boundary for a later migration. If you migrate before you understand roles, exceptions, service accounts, and dormant access, you often recreate the same access problem on the new platform, only with more disruption and a larger change-management burden.
What access governance fixes that an IdP migration usually does not
Access governance addresses the lifecycle of access: provisioning, review, recertification, revocation, ownership, and separation of duties. That is why resources such as the Access Reviews and Certification Guide are more relevant than a migration project when the concern is entitlement hygiene rather than authentication plumbing.
A migration may improve usability or consolidate identity infrastructure, but it does not by itself decide whether a finance approver still needs an ERP entitlement, whether a contractor account should have been removed, or whether a service credential has outlived the system that created it. Those are governance questions, and they usually require better inventory, ownership, and review evidence.
Governance is also the place to normalise roles and reduce ad hoc exceptions. A strong role model and a disciplined review process create a repeatable way to answer access questions across applications, while an IdP migration mostly changes how the front door works. If the organisation already has a stable front door, redesigning the door before the rooms behind it are organised is often the wrong sequence.
This is why lifecycle control matters so much. The Joiner-Mover-Leaver (JML) Guide is a useful lens here, because the biggest gains often come from removing old-role access and revoking stale credentials, not from replacing an IdP that is otherwise functioning.
When an IdP migration should still come first
An IdP migration should move ahead of governance only when the current identity foundation is actively blocking secure access decisions. Examples include broken federation, unreliable MFA, unsupported protocol dependencies, or an IdP posture that cannot meet basic administrative security and session protection needs. In those cases, governance work sits on top of a fragile base and will not hold.
The same is true if the organisation cannot trust the authentication layer to represent the right user or session. If sign-in is failing, tokens are weak, recovery is unsafe, or the federation trust itself is compromised, the access review process becomes less meaningful because the underlying identity assertions are no longer dependable.
When the IdP is the weak point, the migration becomes a control-enabling project rather than a convenience project. That is why a hard break in federation, token security, or admin protection justifies sequencing the migration ahead of governance cleanup. Once the foundation is trustworthy, governance can do the heavier work of entitlement reduction and access recertification.
Risk and Threat Considerations
The risk in choosing the wrong sequence is that organisations spend time modernising sign-in while leaving privilege creep, orphaned access, and weak review controls untouched. That creates a false sense of improvement because authentication looks cleaner even though the blast radius of existing access has not changed.
Failure mechanism: a migration can rehouse the same overprivileged accounts, stale entitlements, and poorly owned access paths inside a new identity platform without actually reducing exposure. If governance is delayed, attackers or insiders can still exploit excess access even after the IdP is replaced.
Impact: the organisation pays migration cost but preserves the same authorisation risk, and may also introduce transition risk through duplicated identities, temporary exceptions, and incomplete cutover controls.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
NIST SP 800-53 Rev 5 sets the technical controls, while ISO/IEC 27001:2022 defines the regulatory obligations.
| Framework | Control / Reference | Relevance |
|---|---|---|
| NIST SP 800-53 Rev 5 | AC-2 — Account Management | Covers account lifecycle and access revocation, central to governance before migration. |
| AC-6 — Least Privilege | Directly addresses entitlement sprawl and excessive access, the core governance problem here. | |
| IA-5 — Authenticator Management | Applies when the IdP itself is weak and authenticator handling drives migration priority. | |
| Recommendation — Tighten account lifecycle controls before re-platforming the IdP. Reduce standing access before changing identity infrastructure. Migrate first when authenticator management is the limiting control. | ||
| ISO/IEC 27001:2022 | A.5.15 — Access control | Supports governing who can access what as a distinct control objective. |
| A.5.16 — Identity management | Covers identity lifecycle and ownership, which determine whether governance or migration comes first. | |
| Recommendation — Use access control governance to clean up entitlements before migration. Establish identity ownership and lifecycle clarity before redesigning the IdP. | ||
Practitioner Guidance
What to prioritise: start with the control that reduces current exposure fastest. If sign-in works and the issue is entitlement quality, recertification, role cleanup, and offboarding discipline should come before an IdP replacement.
What to verify: confirm whether the current IdP is actually failing authentication, federation, or admin protection, or whether the pain is mainly in access review, ownership, and revocation. If the latter is true, treat migration as secondary.
Decision rule: if users can authenticate reliably and the main unanswered question is access legitimacy, fix governance first; if the identity layer is structurally untrustworthy, migrate the IdP first and then govern the resulting access model.
Practitioner takeaway: the right sequence is the one that reduces material risk earliest, and in many enterprises that means governing access before changing the sign-in platform.
Related resources from NHI Mgmt Group
- Should organisations prioritise external exposure or internal credential governance first?
- When should organisations prioritise NHI lifecycle governance over more access tooling?
- When should organisations prioritise access governance over software spend optimisation?
- When should organisations prioritise lifecycle governance over new access features?
Deepen Your Knowledge
Free weekly newsletter
Subscribe to the NHI & AI Identity Journal
The latest on NHI and Agentic AI security – articles, research, breaches, news and events every week.
Bonus 33% off our NHI Course when you subscribe.
Reviewed and updated by the NHIMG editorial team on October 7, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org