When this review is useful
Examine identity lifecycle, privileged access, service accounts and access-review evidence across your selected directories.
Unclear administrative ownership, merger integration, stale access or recurring joiner/mover/leaver exceptions.
The scope should identify the business service, control owner, assessment period and intended report reader. Include supplier dependencies and explain what has changed since the previous review. This prevents an apparently narrow request from silently expanding into an unsupported opinion about the whole organisation.
Assessment procedures to agree
- Reconcile HR or authorised leaver records to directory status using consistent timestamps.
- Separate unique privileged identities from role assignments and check approvals and expiry.
- Inspect review completeness, exception ownership and sampled service-account controls.
Procedures are proposed until the engagement scope is accepted. Record the population used for each sample, the selection rationale and the date on which evidence was collected. Follow exceptions to their cause; do not extrapolate a sample failure rate to the entire estate without a defensible method.
Evidence and context to prepare
- Directory boundaries and authoritative identity source
- Complete populations with pseudonymised stable record IDs
- Lifecycle targets, role approvals and access-review results
Begin with approximate counts and non-sensitive descriptions. Full evidence belongs in an agreed secure channel after confidentiality, access and retention arrangements are settled. Avoid sending passwords, secret values or unnecessary personal records.
Expected outputs
- Traceable lifecycle and privilege findings
- Exception and ownership analysis
- Targeted closure sampling plan
The report should distinguish verified observations from management explanations and open questions. Findings need proportionate recommendations and measurable closure conditions. Management retains responsibility for risk acceptance and changes.
Questions that change effort and coverage
- What is the approved disablement target?
- Do contractors and service accounts follow different processes?
- How are emergency-access accounts controlled?
Assessment boundary
Sampled lifecycle testing does not prove all access is appropriate. Distinguish population size, sample size and observed exceptions in reporting.
Build your audit scoping brief, or send your requirements with an NDA or RFP. High-level context is sufficient for the first conversation.

