Identity Governance and Administration (IGA) is a core IAM discipline combining identity provisioning (lifecycle management and account changes across directories, apps, and databases) with access governance (regulatory compliance, segregation of duties, access reviews). Traditional IGA has focused on on-premises applications and static entitlements—what access is allowed—driven largely by auditor attention to financial risk and least-privilege compliance. The text argues this is now too narrow: business access risk includes fraudulent access to intellectual property and personally identifiable information, and static entitlements do not reveal how access is actually used at runtime.
Modern IGA must therefore expand in two directions: breadth of coverage (all applications across cloud and on-premises, and all user types from employees to partners and consumers) and depth of control (beyond entitlement management into runtime controls). Needed controls include adaptive, risk- and context-based authentication, user behavior analytics for anomaly detection, device security, threat intelligence, and integrated privileged access management for highly privileged infrastructure and business accounts—prime targets for both external and internal attackers.
Because enterprise IT has become cloud-centric (while remaining hybrid), the text positions IGA as a “cloud first” core function. Running IGA as a cloud service improves integration with adjacent cloud-native capabilities such as threat intelligence, device management, CASB functions, and cloud authentication/SSO, while still requiring strong connectivity back to on-premises “legacy” services.
Microsoft’s approach centers on Azure AD Identity Governance, combining directory and conditional access with lifecycle management integrations (including Workday and Microsoft Identity Manager for on-premises connectivity), access reviews, and privileged identity management, integrated within Microsoft EMS alongside Cloud App Security, Defender ATP, Intune, Azure Information Protection, and Azure Security Center. An action plan proposes revisiting IT, IAM, and IGA strategies to define broader risk-based requirements and implement an integrated security architecture.
See All Locations
See All Locations