When Active Directory Is No Longer Enough for Account Management

Author: Julia Grits, Netwrix Brand Manager

Most companies use Active Directory as the foundation for user authentication and access control to corporate resources. It is a proven tool that has remained a de facto standard for many years. However, with the growing number of information systems, the shift to the cloud, and stricter security requirements, AD increasingly performs only a fraction of the necessary tasks. Because identities are no longer just about employees.

When people talk about account management, it almost always used to mean an employee. Today, organizations simultaneously manage employees, contractors, service accounts, applications, APIs, containers, robots, and other non-human identities. Each of these objects receives access rights that must be controlled throughout their entire lifecycle. And in a large organization, the number of service and machine identities can exceed the number of employees!

And the “most interesting” part for the IT team is that each type has its own rules for lifecycles, access approvals, and controls. Because all this diversity has long gone beyond AD into various systems:

  • Entra ID
  • Corporate cloud email like Microsoft 365 or Google Workspace
  • CRM and ERP systems
  • HR platforms
  • ITSM solutions
  • File storages
  • Various types of cloud services
  • Industry-specific business applications
  • Linux and Unix systems
  • Databases
  • VPN and network equipment
  • Business applications with their own local identities, etc.

And the more the business scales, the more often AD ceases to be the single source of “truth”, becoming a component of a large ecosystem. That is why IGA (Identity Governance and Administration) solutions work not with a single directory, but with the entire set of identities, regardless of where they are stored.

Let’s dig into where the line is drawn between Active Directory and modern Identity Governance and Administration solutions, and why many organizations today use them together rather than instead of each other.

No One Is Saying That AD Is a Bad Option

For over twenty years, Microsoft Active Directory has remained one of the key components of IT infrastructure. For most organizations, it is the central directory of users, groups, and computers, providing a single point of authentication and centralized administration of domain resources.

Admins can easily create and manage identities, organize them into groups, apply security policies, control access to network resources, etc.

AD does its job when you need to ensure:

  • centralized storage of identities
  • authentication and authorization of users in the domain
  • application of group policies to manage security settings
  • delegation of administrative privileges
  • support for standard protocols such as LDAP, Kerberos, and DNS

However, it is important to understand that AD was created primarily as a directory and authentication service, not as an account lifecycle management system. Yes, the directory knows who this user is and whether they can log into the system, but where questions like “Why does this account have exactly this access?”, “Who approved it?”, “When should it be changed or revoked?” begin – it can no longer answer.

It is at this stage that you should consider another class of solutions – Identity Governance and Administration (IGA). This is not a replacement for Active Directory, but its logical complement that takes into account the requirements of business, information security, and compliance.

Where it falls short

1

An employee works in 15 systems

2

Besides AD, there are Microsoft 365, CRM, ERP, Service Desk, HRM, VPN, SaaS…

3

Permissions are approved via email

4

Administrators create accounts manually

5

After a change of position, access rights accumulate

6

After termination, individual permissions may remain active

Signs That a Company Has Outgrown Just Active Directory

For small companies, AD capabilities are often sufficient. And this is absolutely valid; there is no need to reinvent the wheel. But as the business grows, the number of employees, information systems, business processes, and security requirements increases. At a certain point, account administration ceases to be merely a technical task and turns into a separate management process.

Here is a small checklist of whether you need an Identity Governance and Administration solution:

  • Users work in multiple systems.
  • Account creation and modification are done manually. IT specialists spend a lot of time creating users, assigning rights, and making changes after employee transfers or terminations.
  • There is no single source of access rights. It is difficult to quickly answer the question: who currently has access to a specific system, who approved it, and on what basis.
  • Access accumulates over time. After a change in position or functional duties, employees often retain old rights that are no longer needed for their work.
  • The company regularly undergoes audits. Preparing information for auditors takes a lot of time, as data has to be collected from different systems and verified manually.
  • Approval processes are not standardized. Access requests come through email, messengers, or verbal agreements, which complicates control and subsequent audits.

If you recognized at least a few of these points, then it is probably time to think about a new level of account management and implement an Identity Governance and Administration (IGA) solution, for example, Netwrix Identity Manager.

Just Active Directory or with IGA? Real Joiner-Mover-Leaver Scenarios

Imagine a new sales manager joins the company.

Only Active Directory:

  • HR notifies IT about the new employee
  • the administrator creates an account in Active Directory
  • separately adds the user to the required groups
  • creates a Microsoft 365 mailbox
  • configures access to CRM, ERP, corporate portal, VPN, and other systems
  • sends logins and passwords to the new employee

Even if certain stages are automated by scripts, the process often remains distributed among several administrators and different systems.

With IGA:

  • HR creates a record for the new employee in the HR system
  • the IGA system automatically determines their role, triggers the necessary business process, creates accounts in all required systems, assigns appropriate access rights, and, if necessary, sends approval requests
  • by their first working day, the employee already has all the necessary accesses

Business result: faster onboarding, less manual work, and no risk of forgetting to grant some important access.

Scenario 2. An employee moves to another department

The sales manager becomes the head of the department.

Only Active Directory:

  • the administrator adds new security groups, but old rights often remain
  • years later, the employee might have access to systems that are no longer needed for their work (this phenomenon is called Privilege Creep – the gradual accumulation of excessive access rights)

With IGA:

  • the system automatically analyzes the employee’s new role
  • revokes accesses that are no longer needed
  • assigns new ones according to company policies

If certain rights require approval, the corresponding workflow is triggered automatically.

Business result: the user has only the accesses necessary to perform their current duties, which reduces the risks of internal incidents and simplifies audits.

Scenario 3. An employee leaves

This is one of the most critical processes from a security standpoint.

Only Active Directory:

  • the domain account can be blocked immediately, but the company often uses dozens of other systems – CRM, ERP, cloud services, VPN, document management systems, industry solutions
  • if the revocation of accesses is done manually, there is always a risk that some account will remain active

With IGA:

  • after the employee’s status changes in the HR system, an automated deactivation process is launched
  • the system revokes access to all connected information systems in accordance with predefined rules, and all actions taken are logged for future audits

Business result: the risk of unauthorized access after an employee leaves is minimized, and the time required for the IT department to perform this procedure is reduced.

What Does the Evolution from Active Directory to IGA Look Like?

So, to briefly summarize everything mentioned above – these are different systems with different tasks.

Let’s break down what modern IGA solutions can add, because they do not replace Active Directory, but use it as one of the data sources and automate business processes around identities.

Work StageBasic AD CapabilitiesWhat IGA Adds
Creation and StorageStores identities and objects in the domainManages the full account lifecycle (onboarding, role change, termination) across all systems, including AD
Access ModelingManages static groups and rights within ADWorks with business roles, access catalogs, policies; automatically assigns rights based on role, position, department
AuthenticationVerifies user credentials, grants access to domain resourcesIntegrates with IAM/SSO, MFA, but focuses not on login, but on who gets what rights and why
System CoverageMostly one domain/forest, at most a few integrated systemsWorks with all business systems (AD, ERP, CRM, clouds, SaaS) as target access systems
Business ContextDoes not know positions, processes, responsible parties; sees only technical objectsPulls data from HR and other authoritative sources, ties access to position, department, processes
Control and AuditEvent logging is present, but lacks a full-fledged governance layerSupports Access Reviews, rights certification, SoD, compliance policies, scenarios like “who approved, when, on what basis”
Access ApprovalMostly manual requests in Service Desk or to adminsProvides a self-service portal, manages approval processes (workflow), access duration, delegation
AutomationScripts, GPOs, separate consoles – point automationCentralized workflows, rules, connectors to systems; automation of business processes around access

If simplified to one sentence, Active Directory answers the question “Who is this?”, while IGA answers “Why does this account have this exact access and what should happen to it next?”.

We have already written the basics about the IGA class of systems, I won’t repeat it, I invite you to read the article “Guide to Identity Governance and Administration (IGA)” with a description and frequently asked questions regarding these systems. Plus, it also describes the difference between IGA, IAM, and PAM.

So, If We Compare?

Don’t. Do not do this, because comparing Active Directory and IGA, as I hope you have already understood, is simply incorrect, as they solve different tasks. What to choose if scaling requires new processes? Both!

  • Active Directory is responsible for authentication, the user directory, and basic access administration.
  • IGA system manages business processes around identity: it determines who should get access, to which systems, on what basis, who must approve it, and when this access needs to be changed or revoked.

That is why in modern infrastructure, these solutions do not compete with each other, but complement one another: AD provides the technical foundation, while IGA, such as Netwrix Identity Manager, provides control, automation, and management throughout the entire lifecycle of identities and accesses.

IGA raises the level of maturity: from simple registration of accounts in the directory to governance.

Get Netwrix Identity Manager Demo



    Subscribe to news