The value of adding Microsoft administration and governance to your IGA environment

Most identity governance and administration (IGA) programs do a good job answering one question: who should have access to what. The platform provisions accounts, runs certifications, enforces segregation of duties and feeds compliance reporting. After the request has been approved and the account exists in Active Directory, the IGA tool typically stops looking. What happens inside the directory after that is somebody else’s problem.

In a recent One Identity session, pre-sales architects Reto Bachmann and Frederic Courtois explained why that hand-off is the gap most organizations underestimate.

“The IGA governs who should have access to what and stops normally at the Active Directory or on the Entra level, but it’s not going deeper,” Bachmann said. Account-layer activity, group permissions, delegated rights, change history. None of it sits inside the IGA tool’s view.

That, in Bachmann’s words, is “a blind spot on the account layer, which also could create risk.”

Why the blind spot in IGA matters

Active Directory is the most attacked identity system on the planet, and attackers target exactly the layer the IGA tool doesn’t see. They look for admin accounts, dormant computer accounts and accounts that retained privileges they no longer need. From any of those, they can pivot toward the keys of the kingdom. An IGA tool that stops at the directory boundary cannot see them coming.

The blind spot widens in hybrid environments. On-prem AD and Entra ID running together means more objects, more identity types and more places for permissions to drift. In multi-domain enterprises, the operational complexity multiplies further. One customer showcased in the webinar runs nearly 50 domains across global business units. An IGA tool was not built for the volume or specificity of that work.

What Active Roles adds

This is what Active Roles by One Identity does. It sits between the administrators and the Microsoft directories (AD, Entra ID, AD LDS) and governs the activity the IGA layer doesn’t see.

In practice, that means a few specific things.

  1. Delegation through reusable access templates, so every change to admin rights is scoped and auditable across domains.

  1. Policy enforcement at the moment of change, not after the fact. As Courtois put it: “Any way you change or create an object, Active Roles will evaluate the policies.”

  1. Privilege constraints during creation, so a service account with risky combinations of attributes (password-never-expires plus elevated permissions) gets blocked before it exists. And,

  1. Reporting that gives compliance teams the audit trail they actually need: 60-plus reports out of the box, subscribable, and publishable to Power BI.

How the two products work together

Adding Active Roles to an IGA deployment isn’t replacing the IGA tool. It’s assigning each tool the work it does best. Identity Manager by One Identity handles the access governance layer: who should have access, segregation of duties, attestation, the joiner-mover-leaver lifecycle. Active Roles handles the directory governance layer: how administrators interact with the directories, what changes are allowed, what audit trail comes out.

Bachmann’s analogy is useful. It’s like SAP. Identity Manager can manage SAP role memberships and entitlements, but it doesn’t create roles inside SAP itself. The same principle applies here. The IGA tool governs the access; the directory tool governs the directory.

For customers running both, a clear pattern shows up. Administrators do day-to-day AD work directly in Active Roles and sync the results back to Identity Manager. The reason is operational: changes to IGA-managed workflows require regression testing every time, and AD admin changes happen too often for that. Active Roles handles the high-frequency work. Identity Manager handles the high-impact governance.

The hybrid identity reality

The value of using these two complementary products is more evident when you consider the reality that hybrid identity isn't going away. On-prem AD will be running in most enterprises for years. Entra ID is already everywhere. Both Active Roles and Identity Manager are built to govern both environments without forcing a choice. Cleaner AD (managed by Active Roles) syncs to cleaner Entra ID. Cleaner identity data (managed by Identity Manager) flows to cleaner downstream systems.

Where to start

If you’re running an IGA program today and you’ve never specifically asked what governs the directories themselves, that’s a conversation worth having. The on-demand session walks through the integration with customer examples, the complementarity table and the AI roadmap for both products.

See: Microsoft administration and governance.

Blog Post CTA Image

Anonymous
Related Content