Join our Newsletter — 33% off our NHI Course
Home FAQ Governance, Ownership & Risk Why do ERP migrations often expose weaknesses in…
Governance, Ownership & Risk

Why do ERP migrations often expose weaknesses in identity and access control?

← Back to all FAQ
By NHI Mgmt Group Editorial Team Updated August 26, 2026 Domain: Governance, Ownership & Risk

ERP migrations surface hidden access issues because legacy roles, emergency access, and scattered approvals are carried into a new operating model. Hybrid environments create overlap between old and new controls, which makes entitlements harder to validate and audit. The risk increases when teams treat access review as a one-time task instead of a recurring governance process tied to migration milestones.

Why This Matters for Security Teams

ERP migrations are not just application cutovers. They are identity reshuffles that reveal where access was never cleanly owned, reviewed, or removed. Legacy ERP roles often carry forward with broad entitlements, while temporary migration access and emergency approvals pile on top. That creates a control gap between what the new platform says is true and what users and service accounts can actually do.

NHIMG research shows the scale of the problem in identity-heavy environments: Ultimate Guide to NHIs reports that only 5.7% of organisations have full visibility into their service accounts, and 97% of NHIs carry excessive privileges. Those findings map closely to ERP programmes because migration teams often inherit hidden service accounts, integration tokens, and approval paths that were never documented with enough precision. Current guidance from the OWASP Non-Human Identity Top 10 reinforces that unmanaged machine access is a recurring weakness, not an edge case.

In practice, many security teams encounter the entitlement problem only after the new ERP is already live and an audit, outage, or fraud review forces a backward look at who still has access.

How It Works in Practice

The failure mode usually starts before go-live. Access is copied from the legacy ERP into the target environment to keep the project moving, then refined through spreadsheets, temporary groups, and one-off exceptions. That approach may preserve business continuity, but it also preserves bad assumptions. A role that once made sense for an old process may map to far more authority in the new system, especially when the target ERP consolidates functions or exposes shared services.

Practitioners should treat migration access as a controlled identity lifecycle rather than a checkbox review. That means inventorying every human and non-human identity in scope, mapping entitlements to business tasks, and identifying where compensating controls are being used in place of a real authorization model. NIST’s NIST SP 800-53 Rev 5 Security and Privacy Controls remains a practical baseline for access control, separation of duties, and auditability. For ERP programmes, those control expectations should be applied to temporary migration groups, break-glass access, API keys, batch jobs, and integration accounts, not only to named employees.

  • Define owners for every privileged ERP role before migration waves begin.
  • Separate migration access from steady-state access and expire it on a fixed schedule.
  • Review service accounts, interfaces, and automated jobs with the same rigour as human users.
  • Validate that emergency access is logged, time-bound, and reconciled after use.

NHIMG’s 52 NHI Breaches Analysis highlights how often forgotten credentials and excessive privileges become the path of least resistance once systems are interconnected. These controls tend to break down when migrations span multiple business units and cutover timelines force teams to accept inherited entitlements without full recertification.

Common Variations and Edge Cases

Tighter access governance often increases migration overhead, requiring organisations to balance speed against assurance. That tradeoff becomes sharper in hybrid ERP environments, where the old system remains active for reporting, reconciliation, or phased decommissioning. In those cases, the real risk is not only duplicate access but conflicting control logic: a user may be restricted in one system and privileged in another, or a service account may survive in both until final cleanup.

Best practice is evolving around recurring review checkpoints tied to migration milestones rather than a single post-cutover signoff. That is especially important for indirect access paths such as middleware, RPA bots, job schedulers, and shared admin accounts. Where teams rely on third-party implementers, the approval chain should be explicit and time-limited, because external access is often the least visible part of the model. The CIS Controls v8 supports this approach through inventory, access control, and continuous account management practices.

For organisations that already struggle with identity sprawl, the most useful question is not whether access was granted during migration, but whether the environment can prove that each entitlement still has a current business need. NHIMG’s Ultimate Guide to NHIs — Key Challenges and Risks is a useful reference point for understanding why hidden machine identities and stale secrets so often outlive the project that created them.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

OWASP Non-Human Identity Top 10 and OWASP Agentic AI Top 10 address the attack and risk surface, while NIST CSF 2.0, NIST SP 800-63 and NIST Zero Trust (SP 800-207) set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
OWASP Non-Human Identity Top 10NHI-01ERP migrations often inherit unmanaged service accounts and stale machine access.
NIST CSF 2.0PR.AC-4Migration entitlements must be reviewed and limited to valid business need.
NIST SP 800-63Stronger identity proofing and session controls help reduce risky access inheritance.
NIST Zero Trust (SP 800-207)Hybrid ERP cutovers benefit from continuous verification instead of implicit trust.
OWASP Agentic AI Top 10A-04Automated migration scripts and agents can become overprivileged execution paths.

Inventory every non-human identity, assign ownership, and remove unused or unapproved access before cutover.

NHIMG Editorial Note
Reviewed and updated by the NHIMG editorial team on August 26, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org