For years, organisations have invested heavily in firewalls, endpoint protection and network security. Yet one of the most common sources of security exposure often receives far less attention: how people join, move around and leave the business. The uncomfortable reality is that many security incidents do not begin with a sophisticated attack. They begin with an identity that has more access than it should, permissions that no longer align with a user's role, or access that was never removed in the first place. As organisations accelerate digital transformation and embrace Zero Trust principles, the joiner, mover and leaver (JML) process has become a security issue, not simply an HR or IT administration task. The organisations that recognise this shift will be far better positioned to reduce risk, improve compliance and support future growth.

The problem isn't negligence. It's manual process
Most organisations do not have excessive access because someone made a poor decision. They have excessive access because people are busy. A manager forgets to submit a request. An IT administrator misses a deprovisioning task. A role change happens without anyone reviewing existing permissions. None of these scenarios are unusual. In fact, they are predictable outcomes of manual processes. Consider a typical employee journey. An employee joins the organisation and receives access to the systems they need. A year later they move departments and receive additional permissions. Six months after that they join a project team. Eventually they become a manager and gain further access. At every stage, permissions are added. Very rarely are old permissions removed. Over time, employees can accumulate access rights from every role they have ever held. The result is identity drift, where access no longer reflects current responsibilities. What begins as administrative convenience gradually becomes a security risk.
The modern attacker doesn't need to break in
The traditional security model assumed attackers would attempt to penetrate a network perimeter. Today's threat landscape looks very different. Attackers increasingly target identities because a compromised account often provides a faster route to valuable data than exploiting infrastructure vulnerabilities. When an account contains excessive permissions, the impact of credential theft becomes significantly greater. An attacker who compromises an overprivileged account gains access to everything that user can reach. In some cases, that may include sensitive data, critical business applications or systems completely unrelated to the employee's current role. The breach may begin with a phishing email, but the damage is amplified by years of unmanaged access accumulation. Identity has become the control plane of modern security. How organisations create, modify and remove access directly influences their overall security posture.
Movers are often the hidden risk
Leavers typically receive the most attention. Boards understand the danger of former employees retaining access. Auditors regularly assess offboarding processes. Security teams monitor dormant accounts. Movers receive far less scrutiny. Yet employees changing departments often introduce greater long-term risk than leavers. When someone changes roles internally, new permissions are frequently granted automatically, while existing permissions remain untouched. Over several years, an individual can accumulate a level of access that no single role would ever justify. The challenge is rarely visible on a day-to-day basis. Nothing appears broken. Productivity remains unaffected. The issue often remains hidden until an audit uncovers it, or until a compromised account exposes the problem. In many organisations, access sprawl develops gradually and silently. That makes it particularly dangerous.
Governance matters more than provisioning
Many organisations attempt to address parts of the problem through scripting or bespoke automation. Whilst these approaches can help automate individual tasks, they do not necessarily create governance. Security leaders should be asking a different question: Can we demonstrate who has access, why they have it, who approved it, and when it should be removed? That question goes beyond automation. It requires policy-driven governance, clear ownership and auditable decision-making.

Why Microsoft Entra changes the equation
Microsoft Entra Identity Governance enables organisations to manage identity lifecycle processes through policy rather than tickets, emails and manual intervention. Instead of relying on individuals to remember tasks, organisations can connect identity decisions directly to authoritative business events, usually originating within their HR system. In practice, that means:
- New employees receive access automatically based on role and approved access packages.
- Internal role changes trigger reviews and adjustments to permissions.
- Leaving employees are deprovisioned based on HR events rather than manual requests.
- Elevated privileges are granted only when required through just-in-time access models.
- Access reviews continuously validate whether permissions remain appropriate.
The real value is not the technology itself. The value is predictability. When access decisions are driven by policy and automation rather than memory and individual effort, organisations significantly reduce the opportunity for security gaps to emerge through everyday business processes.
Identity governance is becoming a business requirement
Many security initiatives are justified purely through risk reduction. Identity governance is different. It also improves employee experience, operational efficiency and compliance readiness. New starters become productive faster because the right access is available from day one. Managers spend less time chasing requests. Security teams gain greater confidence that permissions reflect genuine business need. Auditors receive clear evidence of access decisions and approval workflows. These outcomes support both security objectives and wider business priorities. That combination makes identity governance one of the most practical investments organisations can make.
The next challenge is already arriving
There is another reason identity governance deserves attention now. Human identities are no longer the only identities organisations must manage. Service accounts, automation platforms, AI agents and other non-human identities are proliferating across enterprise environments. These identities introduce their own governance challenges and access requirements. Before organisations can effectively govern non-human identities, they must first demonstrate control over human identity lifecycle management. JML processes provide the foundation. Without that foundation, future identity governance initiatives become significantly more difficult.
Why Trustmarque Ultima?
Technology alone does not solve identity governance challenges. The biggest obstacles are often understanding current processes, aligning stakeholders, navigating licensing requirements and translating governance principles into practical outcomes. Trustmarque Ultima specialises in helping organisations strengthen security through practical Microsoft-first solutions. Our security, identity and compliance specialists work with customers to understand how access is currently managed, identify areas of risk and build a roadmap that aligns security requirements with operational reality. Our focus is not on implementing technology for its own sake. It is on helping organisations establish an identity lifecycle that is governed, auditable and aligned to modern security principles, whilst ensuring employees have the access they need to be productive. Whether you are beginning your identity governance journey or looking to mature existing capabilities, our objective remains the same: helping the right people receive the right access at the right time, for the right reasons.
Ready to assess your identity governance maturity?
Most organisations already have elements of identity governance in place. The challenge is understanding where the gaps are, how much risk they introduce and which improvements should be prioritised first. Our
Identity Governance and Joiner, Mover and Leaver Readiness Assessment provides a practical evaluation of your current environment and helps you:
- Identify identity lifecycle risks and process gaps
- Review onboarding, role change and offboarding processes
- Assess governance, compliance and audit readiness
- Understand Microsoft Entra capability and licensing requirements
- Develop a prioritised roadmap for improvement
You'll leave with a clear picture of your current maturity, actionable recommendations and a practical path towards a more secure and governed approach to identity management.
If you're not confident that your joiner, mover and leaver processes would stand up to a security incident, audit or compliance review, now is the time to take a closer look. Speak to Trustmarque Ultima about an Identity Governance and JML Readiness Assessment and discover how Microsoft Entra Identity Governance can help you reduce risk, improve operational efficiency and build a stronger foundation for Zero Trust.
Final thought
The goal is not simply to automate onboarding or accelerate account provisioning. The goal is confidence. Confidence that every identity has the right access, at the right time, for the right reason. Organisations that achieve that are not simply improving security. They are creating a governance model capable of supporting future growth, stronger compliance and the next generation of digital business. Because in modern cyber security, identity is no longer an administrative function. It is one of your most important security controls.