Every IT organization runs on a small cast of characters. The help desk analyst racing through tickets. The domain admin holding too many keys. The compliance manager chasing screenshots before an audit. The IT director answering for all of it.
In a recent One Identity session, global IAM strategist Rob Kraczek and principal architect Rich Lambert walked through that cast in detail. Four composite personas, drawn from years inside Microsoft directory environments. The names are made up… the pain isn’t.
Marcus, the help desk analyst
Marcus closes tickets. His scorecard is speed and customer satisfaction, which is why he reaches for the fastest path to “resolved.” When a new hire needs access, he copies an existing user, ideally the new hire’s manager, since that’s almost certain to get them logged in without a follow-up ticket. He doesn’t know what’s in that manager’s account, and he doesn’t need to. That’s how privilege sprawls.
Sarah, the domain owner
Sarah is the walking blast radius. She’s a standing domain admin because she has to be. Marcus escalates to her, HR emails her, and someone has to keep ten different Sarahs across the org from drifting into ten different scripting habits. Her account, if compromised, is the end of the environment. She knows it. She also doesn’t have time to fix it.
James, the compliance manager
James gets the audit request. He needs a clean least-privilege report. What he has is a tangle of OU ACLs nobody can read and a privileged groups list that grew because somebody, somewhere, threw their hands up and added a user to Domain Admins to make a problem go away. The stale accounts only make it worse. His audit evidence is screenshots and spreadsheets.
Linda, the IT director
Linda owns the policy. She also owns the relay race. HR emails IT, IT pings security, security sets up MFA, somebody forgets a step. Same audit findings, audit after audit. She wants more headcount, but she has no visibility into what her team actually does day to day, which means she has no case to make for it.
The pattern under the chaos
Four jobs, four sets of frustrations, one root cause: Microsoft’s native tools weren’t built to be the governance layer for a modern enterprise. They were built so people could log into Windows. Privilege gets handed out at the OU level with ACLs that nobody can read. Provisioning runs on email threads. Deprovisioning runs on someone’s memory. In an M&A world where domains get added, split out, federated and unwound, the whole thing compounds.
Kraczek’s word for it is chaos. Lambert’s is “trying to keep a sinking ship afloat with a manual bilge pump.” Same picture.
Putting an enforcement layer on top
This is where Active Roles by One Identity comes in. It sits between the admins and the directories (AD, AD LDS, Entra and AWS Managed AD) and gives the whole environment a single operational model.
What that looks like in practice:
-
Marcus gets scoped delegation through access templates. He can reset passwords and unlock accounts from a web portal. He can’t accidentally elevate anybody.
-
Sarah loses her standing domain admin rights, because she doesn’t need them anymore. Active Roles delegates the rights she needs without touching a single OU ACL. Provisioning and deprovisioning run automatically against HR data.
-
James gets a full audit trail of every directory change in one place, with policy-enforced standards so deprovisioning is consistent across every domain.
-
Linda gets the policy layer her team can finally enforce, plus reporting she can take to the CISO when it’s time to justify a hire.
Lambert flagged one feature that anyone who has ever made a bad click will appreciate: right-click undo on deprovisioning. If somebody is taken out by accident, you can put them back where they were before anyone notices.
Where to start
If any of those four characters sounded uncomfortably familiar, the webinar is worth your time. The personas are stand-ins, but the patterns they describe (privilege sprawl, standing admin rights, manual deprovisioning, repeat audit findings) are universal across organizations running native Microsoft directory tools at scale.
A streamlined, secure and well-organized directory environment is reachable. It just doesn’t come out of the box.
