Operating guide · Identity

Rebuilding joiner, mover and leaver controls

An identity-lifecycle design connecting approvals, applications, devices and completion records.

Where things stand

The operating problem

An organisation uses Microsoft 365 alongside several business applications. New starters are copied from colleagues, role changes rarely remove old access and leaver tasks arrive through informal messages.

A better working position

Authorised business events trigger role-based provisioning and deprovisioning with named approval, timely completion, exception recording and periodic reconciliation across identities, applications, guests and devices.

Gaps to close

  • Provide access quickly without copying excess privilege
  • Remove access consistently during role changes and exits
  • Reduce licence waste
  • Create evidence without adding a heavy workflow

Decisions to settle

  • Authoritative people source
  • Role owners and exception approval
  • Urgent termination channel
  • Automation boundaries and failure handling

How to know it is working

  • Test joiner receives only approved role access
  • Test mover loses incompatible previous access
  • Test leaver sessions and application access are removed
  • Periodic reconciliation finds seeded discrepancies

Working documents

  • Lifecycle workflow
  • Role and application matrix
  • Urgent termination card
  • Application-owner register
  • Reconciliation report template

Putting the routine in place

  1. 01

    Process and access map

    Map triggers, approvers, role templates, systems, devices, data and urgent termination requirements.

  2. 02

    Minimum viable workflow

    Create one controlled request, approval and completion record with role templates and exceptions.

  3. 03

    Application coverage

    Extend beyond Microsoft 365 to software-as-a-service applications, shared secrets, delegated access, physical assets and third parties.

  4. 04

    Reconciliation

    Compare people, identities, licences, guests and privilege regularly and report unresolved exceptions.

Useful operational references

  1. Microsoft Learn — Identity lifecycle management
  2. Australian Signals Directorate, Australian Cyber Security Centre — Implementing multi-factor authentication
  3. Australian Signals Directorate, Australian Cyber Security Centre — Small business cyber security guide

A practical next step

Plan the work around the real environment.

Share what is not working, what is changing or what decision needs to be made. Technical answers can come after the business context is clear.