Who has access to what, why, and who approved it? Entra ID Governance gives you an answer an auditor will accept.
We implement Microsoft Entra ID Governance for Indian organizations: access reviews that actually run and complete, entitlement management with approval flows and expiry, joiner-mover-leaver automation driven by your HR data, and just-in-time privileged access through PIM. Evidence for ISO 27001, SOC 2, RBI and SEBI reviews produced as a by-product of normal operation. Remote-first from Gachibowli, Hyderabad, serving all of India.
- Joiner-mover-leaverAutomated from HR data
- Access packagesOwner-approved, with expiry
- PIMJust-in-time admin roles
- Audit evidenceISO 27001 and SOC 2 ready
Eight governance capabilities, built around three lifecycles.
Access reviews that run, complete, and produce evidence
Recurring reviews where group members, application assignments and guest accounts are recertified by someone who can actually judge them: the manager, the resource owner, or the users themselves attesting. We scope each review so the reviewer sees a list they can genuinely assess, configure auto-removal for non-response so reviews cannot silently rot, and keep the completed record as the recertification evidence your auditor asks for. A review that completes twice a year beats a quarterly one nobody finishes.
Entitlement management: access as packages, not group requests
Instead of a user requesting membership of a group whose name means nothing to them, they request an access package that represents a real function: a project, a client engagement, a finance role. The package bundles group memberships, Teams, application roles and SharePoint access, routes the request through one or more approval stages, and carries an expiry date. Access ends on schedule unless it is renewed, which quietly removes the single largest source of permission sprawl.
Lifecycle workflows: joiner, mover, leaver automated
Workflows triggered by employment attributes: a joiner workflow that prepares the account, sends a temporary access pass to the manager and grants starter access before day one; a mover workflow that reprovisions when department or role changes; a leaver workflow that disables sign-in, revokes sessions, removes group memberships and licences on the last working day. The trigger comes from the attribute data your HR process already maintains, not from an email someone may or may not send.
Privileged Identity Management: eligible, not standing, admin
PIM converts permanent admin role assignments into eligible ones. An engineer activates Global Administrator or Exchange Administrator for a bounded window, with justification, MFA and optional approval, and the role deactivates automatically afterwards. Every activation is logged. The difference between eleven standing Global Admins and two, with the rest eligible on request, is the difference auditors and attackers both notice first.
Separation of duties, enforced at request time
Entitlement management can mark access packages as incompatible, so a person holding one cannot request the other. The classic case is the ability to both create and approve a payment, or to administer a system and approve their own access to it. Enforcing the check when access is requested is a materially stronger control than discovering the combination during an audit, and it is the version an ISO 27001 or SOC 2 assessor prefers to see.
Vendor and guest governance with automatic removal
External collaborators are the population nobody reviews. Entitlement management lets you define which partner organizations may request access, what they get, who approves it, and for how long. When the access expires or is revoked, the B2B guest account is removed automatically. For Indian organizations working with implementation partners, outsourced accountants, auditors and client-side users, this closes a gap that manual processes never close.
HR-driven provisioning as the authoritative source
The signal that somebody joined, changed role or left should come from the system that already knows: your HR platform. Entra supports inbound provisioning from HR sources into both on-premises Active Directory and Entra ID, and where a direct connector does not exist we build the attribute pipeline that feeds lifecycle workflows reliably. Once employment status drives identity status, the leaver problem stops depending on anybody remembering.
Reporting and evidence packs for your auditors
Completed access review histories, access package approval chains, PIM activation logs, deprovisioning records tied to leaver dates. We configure the tenant so this evidence can be produced on demand and map it to the controls your framework names: ISO 27001 access control requirements, SOC 2 logical access criteria, RBI and SEBI expectations on user access management and privileged access. The evidence accumulates as a by-product of the process operating, not as a scramble before fieldwork.
Somebody who resigned months ago still has access to something. Almost certainly.
In most Indian organizations the leaver process is an email to IT, sent sometime around the last working day, actioned when someone sees it. The account gets disabled. What does not happen: application role assignments removed, group memberships cleaned up, shared mailbox access revoked, guest accounts in partner tenants closed, and licences reclaimed. Disabling the account is not deprovisioning. The gap between the two is where audit findings and insider risk both live, and with attrition rates in Indian IT and services businesses, the gap compounds every month.
- A disabled account with live application entitlements is re-enabled in one click, by anyone with the rights to do it, with all its old access intact.
- Leavers who were admins are worse: standing privileged roles survive unless someone remembers to check role assignments separately from the account.
- Auditors test this directly. The standard request is a list of leavers from HR for the audit period, cross-checked against access removal records. If you cannot produce the second list, that is the finding.
- A lifecycle workflow triggered by the employee leave date closes all of it on schedule: sign-in blocked, sessions revoked, memberships and licences removed, with a record of each action.
Four disciplines that keep governance from becoming a two-year programme.
Leavers and guests first, role models later
The leaver path and the guest lifecycle carry the most risk, are the easiest to automate, and show results in weeks. Designing a complete organization-wide role model first is how these projects consume a year without shipping anything, and the model is usually stale before it is finished. We automate the concrete risk first and let the model grow from what works.
A few access packages done properly, not forty done badly
Entitlement management works when packages reflect real business functions with real owners who understand what they approve. Three or four well-designed packages covering genuinely sensitive access outperform a wholesale migration of your existing group structure, which only moves the existing mess into a new interface.
Reviews scoped so reviewers actually complete them
A review that presents two hundred rows to a manager gets approved in bulk and evidences nothing. We scope each review to what one person can honestly assess, enable the recommendation signals the platform provides, set auto-apply for non-response, and pick a cadence that survives more than one cycle. Real evidence comes from reviews that complete.
Built for the auditor who will ask
Every configuration decision is made with the evidence request in mind: can we produce the completed review, the approval chain, the PIM activation log, the deprovisioning record tied to the HR leave date? That is what an ISO 27001 auditor, a SOC 2 examiner, or an RBI-regulated client running vendor due diligence actually asks for, and we set the tenant up so the answer is an export, not an archaeology project.
Six Indian situations where manual access management has already failed.
BFSI under RBI supervision
Banks, NBFCs, and fintechs operating under RBI cyber security and IT governance expectations are examined on how access is granted, changed, removed, and recertified, with privileged access a standing focus area. Entra ID Governance produces the user access review records and just-in-time privileged access evidence those examinations ask for, as a by-product of normal operation rather than a pre-inspection assembly job.
SEBI-regulated intermediaries
Brokers, asset managers, RTAs, and other intermediaries under the SEBI cyber security framework need demonstrable access control, periodic review of user rights, and hard control over privileged accounts. We map the governance configuration to the framework clauses so the compliance officer can point at a control and its evidence rather than a policy document and a hope.
GCCs and captives governed from two directions
Global capability centres answer to the parent company audit programme and to Indian requirements simultaneously, and typically run high headcount with steady rotation. HR-driven lifecycle automation and access packages per function scale to that churn, and produce evidence in the shape the parent SOC 2 or ISO programme already expects.
IT services and SaaS companies facing client due diligence
Enterprise clients send security questionnaires before they sign, and access lifecycle questions appear in nearly all of them: how access is approved, how leavers are removed, how admin access is controlled. Companies pursuing SOC 2 or ISO 27001 to unblock those deals get most of the access-control evidence directly from a governed Entra tenant.
Organizations above roughly 100 staff with real churn
Below a certain size, one careful IT person can hold the access picture in their head. Above roughly a hundred staff with normal Indian attrition, that stops being true, silently. Movers accumulate access, leavers leave residue, and nobody can answer who has access to what. Governance automation is the difference between the picture degrading monthly and correcting monthly.
Companies with vendor and partner ecosystems
Implementation partners, outsourced finance teams, statutory auditors, client-side collaborators: external accounts arrive for a project and stay forever. Entitlement management adds approved external users as guests with a defined expiry and removes them automatically when it passes, which is the only version of guest hygiene that survives contact with a busy quarter.
How access is actually managed in most Indian organizations.
| Feature | Governance automated | Manual and documented | Ad hoc |
|---|---|---|---|
Joiners provisioned from an authoritative HR source | Yes | No | No |
Movers have old access removed, not just new access added | Yes | Rarely | No |
Leavers fully deprovisioned across applications on the last day | Yes | Partly | No |
Access approved by the business owner who can judge it | Yes | Sometimes | No |
Access expires on schedule unless renewed | Yes | No | No |
Guests and vendor accounts removed automatically | Yes | No | No |
Admin roles just-in-time, activation logged | Yes | No | No |
Separation of duties enforced at request time | Yes | No | No |
Recurring access reviews with completion evidence | Yes | Partly | No |
An auditor can verify the controls operate | Yes | Partly | No |
What P2 includes, and what needs the Governance licence.
| Capability | Entra ID P2 | Entra ID Governance licence | |
|---|---|---|---|
| Access reviews of groups and applications | Included | Included, with machine-learning assisted recommendations | |
| Entitlement management, core access packages | Included | Included | |
| Privileged Identity Management | Included | Included | |
| Lifecycle workflows (joiner, mover, leaver) | Not included | Included | |
| Separation of duties checks in entitlement management | Not included | Included | |
| Custom extensions calling your own processes | Not included | Included | |
| PIM for Groups | Included | Included | |
| Guest access governance with automatic removal | Core scenarios | Full scenarios, including conversion and expiry policies |
Five steps, with something working in the first month.
- 1
Assess the current state
1-2 weeks
Tenant review, licence entitlement check, standing admin count, guest account census, and a cross-check of recent leavers against what they can still reach. Output: a concrete gap picture against the question "who has access to what, why, and who approved it", plus a sequenced plan.
- 2
Automate the leaver path
1-2 weeks
Lifecycle workflows triggered by the employee leave date: block sign-in, revoke sessions, remove group memberships and licences, notify the manager, and record every action. This is the highest risk closed for the least work, and it addresses the finding auditors raise most often.
- 3
Bring guests and vendors under entitlement management
1-2 weeks
Define which partner organizations may request access, what they can hold, who approves it, and for how long. Existing stale guests are reviewed and cleared. From here, external access expires and removes itself instead of accumulating.
- 4
Package sensitive access and enable PIM
2-3 weeks
Three or four access packages for genuinely sensitive functions, with owner approval and expiry, plus separation of duties checks where incompatible combinations exist. In parallel, standing admin roles convert to PIM eligible assignments with activation windows, justification, and approvals for the highest tiers.
- 5
Turn on reviews and connect the joiner-mover path
Ongoing
Recurring access reviews scoped for honest completion, evidence exports mapped to your framework, and then HR-driven provisioning for joiners and movers, which is the largest piece and lands best once everything else is already running. We can operate the whole cycle for you under a managed agreement with a 30 minutes response SLA.
Entra ID Governance, the questions Indian teams actually ask.
Fifteen questions that tell you whether you need this.
What is manual today
- How does IT learn that somebody has joined?If the answer is an email or a ticket, that is the first gap.
- How does IT learn that somebody changed role or department?The mover event is the one nobody handles, and it is where access accumulates.
- How does IT learn that somebody has left, and how long after their last day?Measure it against your last five leavers. The honest number is usually days.
- Who approves an access request today?If it is IT, they are guessing. IT cannot know whether a request is reasonable.
- When did you last remove a guest or vendor account without being asked to?In most tenants, the answer is never.
What to automate first
- Does an authoritative source of employment status exist?An HR platform, or even a maintained attribute set, is enough to drive lifecycle workflows.
- Which applications hold access worth packaging?Start with three or four genuinely sensitive ones, not everything.
- Do you work with external firms regularly?Guest lifecycle automation is often the quickest visible win.
- Are there role combinations that must never co-exist?Payment creation and approval is the classic. Separation of duties can enforce it at request time.
- How many people hold standing admin roles right now?Count them. The number is nearly always higher than anyone believed.
The audit driver
- Are you pursuing or maintaining ISO 27001 or SOC 2?Both examine access provisioning, recertification and privileged access directly.
- Are you regulated by RBI or SEBI, or serving clients who are?User access management and privileged access controls appear in both regimes and flow down through vendor due diligence.
- Do enterprise clients send you security questionnaires?Access lifecycle questions appear in nearly all of them.
- Can you evidence a completed access review today?Evidence, not an assertion that one happened.
- Does the DPDP Act apply to personal data you hold?Reasonable security safeguards include controlling and evidencing who can reach personal data.
The pages around this one.
Microsoft Entra ID
The platform deployment underneath governance: SSO, MFA, conditional access, and hybrid identity done properly first.
Learn moreConditional Access
The real-time policy layer that decides whether a sign-in proceeds. Governance decides whether the access should exist at all.
Learn moreAudit Readiness Assessment
The pre-audit dry run for ISO 27001, SOC 2, and DPDP reviews. Governance evidence slots straight into its access control sections.
Learn moreStart with everybody who left in the last twelve months.
Pull the list from HR, then check what each person can still reach, not just whether the account is disabled. That exercise takes a day, it is uncomfortable in a useful way, and it decides whether this work is urgent or merely sensible. We can run it with you as the first step of a governance assessment. Enquiries get a reply within 4 business hours.
Related Services
Explore more solutions that work great with this service