50 / 63Identity and Access Management

Identity and access management, including the part where leavers lose access

Canadian identity and access management built on the platform you own, with joiners and leavers handled.

  • CCIE Security-led team
  • Building Canadian directories since 2021
  • Vendor-neutral platform advice
THE WORK

Identity and access management, three pillars, one operator.

Most IAM services stop at the platform. One Canadian team builds it, locks down the admin accounts, and proves access came off.

  1. 1

    Identity platform

    Directory, single sign on, MFA, and conditional access on the licences you already hold. Most Microsoft Entra ID tenants we open already carry the features nobody switched on.

  2. 2

    Privileged access

    Admin accounts vaulted, elevation granted just in time, every session recorded. That's privileged access management (PAM) rather than a stronger login, and it covers the small set of accounts that can change the environment itself.

  3. 3

    Joiners and leavers

    Provisioning, role changes, and identity governance your auditor can read. Joiner, mover, and leaver wired to the directory, so an account dies with the employment that justified it.

THE PROOF

Built to last. Evidence over promises.

Credential abuse still appears in 39% of breaches, more than any other vector, even after falling as the front door (Verizon Data Breach Investigations Report, 2026). Single sign on and privileged access management only pay off when the leaver side of the work is finished too.

IN PRODUCTION

Access Canadian auditors could verify.

Our access review was a spreadsheet somebody exported once a year and nobody believed. When SMEnode ran discovery they found 62 active accounts belonging to people who had left, two of them with domain admin. We didn't need new software. We needed the joiner and leaver process to actually connect to the directory, which is what they built.

SMEnode · Engineering principle
  • CCIE Data Center
  • CCIE Security
  • CCDE Design
  • Canadian data residency
THE DEEP DIVE

Identity and access management in Canada, made real.

Most identity projects buy a platform and never finish the boring half. The boring half is the control, and this is written by the engineer who'll own your directory, not by a product page.

Why credentials still decide the incident.

Credentials are still the thing attackers use most, and the 2026 data is more interesting than the headline. Credential abuse fell to 13% as the initial way in, losing the top spot for the first time in the report's nineteen years, with software flaws taking it at 31%. Count credential abuse anywhere in the attack path, though, and it turns up in 39% of breaches, more than any other vector (source: Verizon Data Breach Investigations Report, 2026). Attackers knock less often and still walk around inside using someone's login.

Finishing the identity platform you already own.

Most Canadian organisations we meet already own a capable identity platform inside their Microsoft licensing and use perhaps a third of it. Single sign on covers the six applications somebody set up and not the twenty that came later. MFA is enabled but exempted for the executives who complained. Conditional access sits at default. An SSO implementation stalls on those decisions rather than on the tooling, and an MFA deployment that ships with an exemption list isn't finished. We build on what you hold and say plainly when a licence tier genuinely needs upgrading, which is less often than a reseller will suggest.

The failure that shows up in incidents: leavers and standing privilege.

Accounts outlive employment because offboarding runs through HR and payroll while the directory sits outside that flow entirely. Admin rights get granted for one migration and never withdrawn. We connect the joiner and leaver process to the directory, vault the privileged accounts, and grant elevation just in time so nobody holds domain admin permanently. Identity governance is what keeps that state true a year later, because a review nobody signs is a spreadsheet. PIPEDA applies here too: an account that shouldn't exist is an access-control failure you'd have to explain.

Zero-Trust vault
THE METHOD

How our privileged access management and identity governance work runs.

Four steps, and step 01 is the one clients remember. Discovery on a real directory finds things nobody expects: service accounts with passwords set in 2019, shared logins for a system three teams use, accounts for contractors whose engagement ended two summers ago. We inventory identities and entitlements before recommending anything, because the shape of the problem decides whether this is a configuration job or a platform job, and those are different quotes.

  1. Step 01

    Inventory identities

    Every human, service, and shared account, what it can reach, when it was last used, and whether its owner still works here.

  2. Step 02

    Build the platform

    Directory hygiene, single sign on across the applications that matter, MFA without the exemption list, and conditional access rules that survive contact with users.

  3. Step 03

    Contain privilege

    Admin accounts into a vault, elevation granted just in time and recorded, and standing domain admin reduced to nobody.

  4. Step 04

    Close the loop

    Joiner, mover, and leaver wired to the directory, plus access reviews that produce a signed record rather than an unread spreadsheet.

QUESTIONS

Identity and access management questions, answered straight.

Answers first, including when not to start. An architect takes the call, not a salesperson.

Usually what you hold is enough. Most Canadian mid-market organisations already have the login, second factor, and policy controls available in their existing Microsoft licensing and are using a fraction of it. A dedicated platform earns its cost when you run many non-Microsoft applications, need fine-grained entitlement reviews, or have regulator-driven separation-of-duties requirements. We'll tell you which case you're in before anyone quotes software.

Scope and blast radius. Identity and access management covers everybody: who exists, what they can reach, how they prove it's them. The privileged side covers the small number of accounts that can change the environment itself, so it needs vaulting, just-in-time elevation, and session recording rather than just a stronger login. Most organisations need the first properly before the second is worth buying, and we'll say if you're the exception.

Weeks, not months, if the directory is clean, and the directory is rarely clean. The technical work is quick. What takes time is deciding which applications matter, agreeing what happens to the people who currently hold exemptions, and testing access policy against real working patterns before it locks somebody out mid-shift. We stage it so no group loses access without warning.

Because we check, rather than trusting a ticket. A revocation that only happens in the directory leaves accounts alive in every application that holds its own local login, which on most estates is more of them than anyone expects. We map where identities are duplicated, wire what can be wired to the directory, and keep a short manual list for what can't. Then the review verifies it instead of assuming.

When your directory is unowned, because someone has to make decisions about roles and nobody can outsource that judgement. When the real driver is a single failed audit finding, which is usually cheaper to fix directly. And when a reorganisation is six weeks out, since roles you define now get redefined before the work lands. Waiting is occasionally the correct advice and we'll give it.

The tenant, the licences, and the documentation behind them. That means a written role model, the access policies and the reason each one exists, the vault plus its break-glass procedure, a joiner and leaver runbook wired to the directory, and review records somebody has signed. Admin rights stay yours, and if you take the work back in house the runbooks come with it.

LET'S CONNECT

A senior engineer replies within an hour, 24/7.