SEC536: Adversarial AI - Penetration Testing AI Systems


Experience SANS training through course previews.
Learn MoreLet us help.
Contact usBecome a member for instant access to our free resources.
Sign UpWe're here to help.
Contact UsOrganizations with complex, multi-system environments face significant challenges in managing identity lifecycle, access provisioning, and governance at scale, and typically rely on dedicated platforms or homegrown codebases to address these needs. However, the evolution of Microsoft Entra ID and its Governance capabilities raises the question of whether a standalone IGA solution is necessary for organizations already invested in the Microsoft ecosystem.
This research evaluates the viability of using Entra ID Governance as a primary IAM/IGA solution through a proof-of-concept implementation modeled on a moderately complex organization with multiple systems of record. Using criteria aligned with industry-standard IGA capabilities, the study maps governance requirements to native Entra features. It tests their effectiveness across identity lifecycle management, access provisioning, reconciliation, and audit processes.
Findings indicate that Entra ID Governance can fulfill core IGA functions without middleware by leveraging lifecycle workflows, access packages, and API-driven integrations. However, limitations in real-time processing, service thresholds, and attribute flexibility must be considered. The results suggest that organizations can reduce architectural complexity and accelerate adoption by consolidating identity governance within Entra ID, provided their operational requirements align with the platform’s current capabilities.


















