Home · Solutions · Other solutions

Solution · Other solutions

Access decided by the policy, granted in minutes, and evidenced without a spreadsheet

Application access granted by policy in minutes, with proof

Standard access packages are granted within policy, sensitive roles pass named approvers, robots provision the applications without SCIM, and every grant carries its evidence and its expiry.

DepartmentalMicrosoft TeamsHuman in the loopDeterministic automation
550access requests a month are typed into tickets at this illustrative engineering group. Six in ten ask for a role the written policy already describes.

Executive summary

Challenge

Access is granted from interpreted emails, approvals are chased, and the auditor finds the evidence missing.

What changes

We start from the client's own access policy and turn it into access packages in Microsoft Entra ID Governance: bundles such as "site engineer.

Business value

Standard access arrives in minutes, because a policy decides instead of an email chain.

Systems involved

Microsoft Entra ID and Microsoft Entra ID Governance; SCIM-connected SaaS applications; the ERP

Business problem

Identity & access

Requests arrive as sentences. "Give Anna the same as Piotr" is interpreted by an administrator who knows the systems but has never read the policy, because the policy is a document and the request form is a text box. Approval is chased by email, and when a project is blocked the administrator grants first and asks later.

Each application has its own administrator, console and idea of what a role is, so one request fans out into four grants on four days, and the application owner is rarely consulted. Nothing records when the access should end, so it does not end. Evidence lives in mailboxes, where auditors find it missing. Policy, request and grant were never connected, and every audit tests the connection.

How it works today

  1. PersonA manager asks the service desk for "the same access as a colleague"; the desk turns the sentence into a ticket
  2. PersonAn administrator translates the sentence into roles, from memory
  3. WaitingThe ticket waits for the manager's approval by email, usually two to five days
  4. SystemThe administrator grants in each console in turn: directory, ERP, project system, CAD licence server
  5. Risk of errorThe application owner is not asked, so role combinations the policy forbids appear without anyone deciding
  6. Risk of errorEvidence is pasted into the ticket if somebody remembers, no end date is recorded, and the auditor's sample finds the gap
PersonWaitingSystemRisk of error

Why the current process costs more than it appears

The most expensive part of this process has no cost line.

  • Waiting is the visible cost: a project controller who cannot post in the ERP for a week is a week of somebody else's work.
  • Access granted without the application owner breaks segregation of duties silently; nobody designed the conflict and nobody sees it.
  • Rights with no end date accumulate, and every accumulated right is one more a stolen password can use.
  • Audit preparation becomes a quarterly reconstruction project, and the finding recurs because its cause is structural.

Cost of inaction

Twelve months of the standard share handled by people≈ €123,552
Four audits a year of approval evidence rebuilt by hand, 160 hours≈ €8,320
Three audit years from now, both together≈ €395,616

Accumulation is the number this table cannot show. Every new application adds a console to the fan-out, every hire adds requests, and the access estate grows by grants minus removals, which today means by nearly every grant. The finding recurs with a sharper tone each time; twelve months on, the company has more accounts with more rights and evidence that still depends on who remembered to paste the approval.

Illustrative scenario

A plausible organisation with realistic proportions. The figures are there to be recalculated on your data; they are not a client result.

Organisation

An engineering and construction group, 2,800 employees, about 60 business applications behind Microsoft Entra ID; roughly 20 SaaS applications connected through SCIM; the ERP, the project-management system and the CAD licence server have no provisioning interface.

Volume

About 550 access requests a month; six in ten ask for a standard role the written policy already describes; four audits a year.

Current process

Free-text tickets interpreted by an administrator, approval chased by email, grants made by hand in each console, evidence pasted into the ticket when remembered.

Bottleneck

Around 36 minutes of combined handling per request across desk, administrator, application administrators and evidence; about 40 hours per audit rebuilding evidence.

Solution

Access packages in Microsoft Entra ID Governance execute the written policy; SCIM applications are provisioned by Microsoft Entra ID; UiPath Robots provision the other three; a register in UiPath Data Fabric holds request, approvals, grant and expiry; exceptions reach the administrator in Microsoft Teams.

Potential outcome

In the modelled case six requests in ten are granted within policy with nobody handling them, every grant carries an end date, and the auditor's sample becomes an export. Illustrative throughout; nothing here was measured at a client.

Proposed solution

We start from the client's own access policy and turn it into access packages in Microsoft Entra ID Governance: bundles such as "site engineer, standard" or "project controller", each naming its roles, requesters, approvers, maximum duration and review cycle. A standard, low-risk package is granted directly and recorded as a policy decision; anything sensitive cannot complete without the manager, the application owner and, where the policy says so, security. Licence note: entitlement management needs Microsoft Entra ID P2 or Microsoft Entra ID Governance.

SCIM-connected applications are provisioned by Microsoft Entra ID itself. For the other three, the approved assignment produces a group-membership event that starts a UiPath workflow: a robot creates the user and the role through the administration interface, reads the result back and writes it, with the expiry date, to a register in UiPath Data Fabric; the same robots remove the access at expiry. Microsoft Teams carries the approver reminders, the ready message, and a UiPath Action Center task for the administrator when a request fits no package or a grant fails.

Native capabilities used

Microsoft Entra ID Governance entitlement management (access packages, approval stages, time-limited assignments); Microsoft Entra ID automatic user provisioning (SCIM); access reviews; UiPath Orchestrator queues, event triggers, credential store and audit log; UiPath Action Center tasks in Microsoft Teams; UiPath Data Fabric entities with audit; Microsoft Teams connector in UiPath Integration Service

What we build

The package catalogue mapped from the written policy; robots that create, change and remove accounts and roles in the three applications without SCIM, with read-back; the register and its evidence export; removal at expiry; exception handling; the Teams messages

Custom integration

Assignment and group-membership events from Microsoft Entra ID through the Graph-based identity connector in UiPath Integration Service (the connector still carries the name Microsoft Azure Active Directory); the ERP, the project-management system and the CAD licence server through their administration interfaces or APIs

How the automated process works

  1. PersonA manager or employee picks an access package from the catalogue, with reason and duration
  2. AutomationThe package policy decides: a standard, low-risk package is granted within policy; anything else goes to the approvers the policy names
  3. PersonFor sensitive packages the manager, the application owner and, where required, security approve; the reminder reaches them in Teams and Microsoft Entra ID Governance records the decision
  4. SystemSCIM-connected applications are provisioned by Microsoft Entra ID; the other three become items in an Orchestrator queue
  5. AutomationA robot creates the account and role, reads the result back, writes it to the register with the expiry date, and tells the requester in Teams; at expiry it removes what it created
  6. PersonA failed grant, or a request that fits no package, becomes an Action Center task in Teams for the IT administrator, who decides
PersonAutomationSystem

Human-in-the-loop model

Automation handles

  • Presenting the request as a choice of packages, not a text box
  • Evaluating the policy: direct grant, or which approvers must decide
  • Provisioning through Microsoft Entra ID or through robots, with read-back
  • Recording request, approvals, grant and expiry, and removing access when the date arrives

People decide

  • Approvals for sensitive roles: the manager, the application owner and security, each by name
  • Who owns each package, what it contains and what the policy treats as low risk
  • Requests that fit no package, decided by the IT administrator in Teams

Before and after

BeforeAfter
Time from request to working accessdays, set by the slowest approverminutes for standard packages
Grants without a named approverfound in the audit samplenone; direct grants recorded as policy decisions
Evidence for 25 sampled accountsdays of reconstruction from mailboxesone export from the register

Systems and integrations

We do not add technology to make an architecture look serious. Every element below has a specific job in this process.

Inputs

  • access package requests from the My Access portal
  • assignment and group-membership events from Microsoft Entra ID
  • the written access policy

Automation layer

  • UiPath Orchestrator
  • UiPath Robots
  • UiPath Integration Service
  • UiPath Action Center
  • UiPath Data Fabric

Target systems

  • Microsoft Entra ID and Microsoft Entra ID Governance
  • SCIM-connected SaaS applications
  • the ERP
  • the project-management system
  • the CAD licence server

Human touchpoints: approval stages in the access package policy; Action Center tasks in Microsoft Teams; status and reminders in Teams; the evidence export

access package requests from the My Access portalUiPath OrchestratorUiPath RobotsMicrosoft Entra IDapproval stages in the access package policy

Technologies used

Microsoft Entra ID Governance (entitlement management)

access packages, approval stages, time-limited assignments with automatic removal

A
Microsoft Entra ID (automatic user provisioning, SCIM)

creates, updates and removes accounts in the connected SaaS applications

A
UiPath Robots + UiPath Orchestrator

provision and remove accounts and roles in the three applications without SCIM; queues, retries, audit log; credentials from Azure Key Vault

A
UiPath Integration Service (identity and Microsoft Teams connectors)

picks up assignment events from Microsoft Entra ID; posts status and reminders in Teams

A
UiPath Action Center in Microsoft Teams

exception tasks for the IT administrator, completed without leaving Teams

A
UiPath Data Fabric (formerly Data Service)

the register: request, approvals, grant time, expiry, removal; the evidence export

A
Averified product capability (vendor documentation)

Illustrative economic model

What it is worth, with the arithmetic shown.

Illustrative model
330 standard requests a month (six in ten of 550) × 36 minutes of handling= 198 h / month
198 h × €52 fully loaded hourly cost= €10,296 / month
× 12 months≈ €123,552 / year
Annual desk and administrator capacity released (illustrative)≈ €123,552

A policy can only release the work it can decide, so the volume below is 330 rather than 550: the six requests in ten that fall inside a standard package. Thirty-six minutes is the combined handling across desk, administrator, application administrators and evidence filing; €52 an hour is a fully loaded IT specialist in Central Europe. The four audits a year sit under the cost of inaction. Every figure is illustrative.

Run the numbers on your data

hours released per month
of annual capacity released

An illustrative estimate from your own inputs. It models released capacity; it is not a promise of savings.

Business benefits

  • Standard access arrives in minutes, because a policy decides instead of an email chain
  • The "granted as per phone call" route closes: a sensitive role cannot exist without the approvers the policy names, recorded against the grant
  • The auditor's sample becomes a query on the register instead of a fortnight of reconstruction, and the finding closes
  • Every grant carries an end date, and the three applications without SCIM sit inside the same flow, so the connector's reach no longer bounds the control

The management view

  • The policy is enforced at request time rather than described in a document: forbidden role combinations are checked before the grant, not after the audit
  • Evidence exists by default, in the shape the auditor asks for: who requested, who approved, when, for how long
  • "Who has access to what" has one answer, which is where every incident review starts

Board-level KPIs

share of requests granted within policymedian time from request to working accessgrants without a recorded approverassignments past expiry still activehours of audit preparation per cycle

Security and governance

Control is not an add-on.

  • Sensitive roles cannot be granted outside the flow: Microsoft Entra ID Governance enforces the named approvers, and forbidden role combinations are checked at request time
  • Robots hold provisioning rights only, under a dedicated service account per application; passwords are fetched at run time from Azure Key Vault through the Orchestrator credential store, and every action is logged against its request
  • The register is append-only for requests, approvals and grants: a correction is a new record, never an edit
  • Processing stays in the EU region of UiPath Automation Cloud and inside your Microsoft 365 tenant under the EU Data Boundary; access reviews cover what stays permanent

Why now

01

Auditors and cyber insurers have moved from "is there a policy" to "show me the grant, the approver and the end date"; the last finding was about evidence, and the next one will be a repeat

02

Entitlement management, approval policies and access reviews are standard in Microsoft Entra ID Governance, already in the tenant; what stayed hard, the applications with no interface, is ordinary robot work

03

The modelled €10,296 a month of handling continues for as long as the desk interprets sentences

Relevant executive roles

CIO

Access becomes a governed service with a catalogue and a register instead of a queue of interpreted emails

CISO

The policy is executed at request time; sensitive roles carry named approvals and every grant expires by design

IT Director

Administrators stop chasing approvals across four consoles, and the ERP-roles expert stops being a single point of failure

Compliance Officer

Audit evidence is an export, and the finding closes at the next cycle

Common questions and objections

Microsoft Entra ID Governance can do this on its own, can't it?

For the SCIM-connected applications, largely yes; where an application exposes a SQL, LDAP or SCIM endpoint, the on-premises provisioning connectors of Microsoft Entra ID may cover it too, and the robot step retires. The applications without any interface are where the tickets still come from, and robots put them inside the same policy, expiry and register.

Defining the packages will take forever.

Ten packages cover most of the volume in most companies; we start with the roles behind one quarter of requests and let the exception queue show which comes next.

Granting without approval sounds like less control.

It is more control, in writing. The policy states what is low risk and those requests are granted as recorded policy decisions; everything else gets the named approvers, every time.

When this is not the right solution

  • Fewer than a hundred access requests a month and a handful of applications: a documented role matrix and a disciplined desk cost less than the licences
  • No written access policy and no owner willing to write one; that is the first project
  • An identity governance platform migration is under way, or every application is already SCIM-connected with packages in place; then the gap is adoption

A question for the next management meeting

Access that is correct but unevidenced fails the audit exactly like access that is wrong: for the next sample of 25 accounts, could this company produce the requester, the approver, the date and the end date of each grant from a system rather than from a mailbox?

Implementation approach

What we deliver, and what we need from you to start.

We deliver

  • Analysis of one quarter of requests and the access matrix, to find the ten roles behind most of the volume
  • Package and policy design with the CISO and the application owners: contents, approvers, durations, what counts as low risk
  • Microsoft Entra ID Governance configuration, and robots for the three applications without SCIM, with read-back and exception handling
  • The register, the evidence export, removal at expiry, the Teams messages, and a pilot on one business unit

We need from you

  • The written access policy, or the owner who will write it, and the current access matrix
  • Named owners for each application in scope, and the Microsoft Entra ID Governance licence decision
  • Administrative accounts for the robots, scoped to provisioning, and one quarter of request tickets

Stages

Discovery

Requests, matrix, approvers used in practice, the SCIM and non-SCIM split

Design

Package catalogue, policy mapping, approval stages, durations, security model

Build

Microsoft Entra ID Governance configuration, robots per application, register, Teams tasks

Validation

Historical requests replayed against the packages; provisioning tested in test systems

Go-live

One business unit with the ticket route still open, then the desk switched to the catalogue

Departmental. Effort follows the number of applications without an interface, the distance between written policy and practice, and whether owners can be named.