Home · Solutions · Other solutions
Solution · Other solutionsAccess decided by the policy, granted in minutes, and evidenced without a spreadsheet
Application access granted by policy in minutes, with proof
Standard access packages are granted within policy, sensitive roles pass named approvers, robots provision the applications without SCIM, and every grant carries its evidence and its expiry.
Executive summary
Access is granted from interpreted emails, approvals are chased, and the auditor finds the evidence missing.
We start from the client's own access policy and turn it into access packages in Microsoft Entra ID Governance: bundles such as "site engineer.
Standard access arrives in minutes, because a policy decides instead of an email chain.
Microsoft Entra ID and Microsoft Entra ID Governance; SCIM-connected SaaS applications; the ERP
Business problem
Identity & access
Requests arrive as sentences. "Give Anna the same as Piotr" is interpreted by an administrator who knows the systems but has never read the policy, because the policy is a document and the request form is a text box. Approval is chased by email, and when a project is blocked the administrator grants first and asks later.
Each application has its own administrator, console and idea of what a role is, so one request fans out into four grants on four days, and the application owner is rarely consulted. Nothing records when the access should end, so it does not end. Evidence lives in mailboxes, where auditors find it missing. Policy, request and grant were never connected, and every audit tests the connection.
How it works today
- PersonA manager asks the service desk for "the same access as a colleague"; the desk turns the sentence into a ticket
- PersonAn administrator translates the sentence into roles, from memory
- WaitingThe ticket waits for the manager's approval by email, usually two to five days
- SystemThe administrator grants in each console in turn: directory, ERP, project system, CAD licence server
- Risk of errorThe application owner is not asked, so role combinations the policy forbids appear without anyone deciding
- Risk of errorEvidence is pasted into the ticket if somebody remembers, no end date is recorded, and the auditor's sample finds the gap
Why the current process costs more than it appears
The most expensive part of this process has no cost line.
- Waiting is the visible cost: a project controller who cannot post in the ERP for a week is a week of somebody else's work.
- Access granted without the application owner breaks segregation of duties silently; nobody designed the conflict and nobody sees it.
- Rights with no end date accumulate, and every accumulated right is one more a stolen password can use.
- Audit preparation becomes a quarterly reconstruction project, and the finding recurs because its cause is structural.
Cost of inaction
Accumulation is the number this table cannot show. Every new application adds a console to the fan-out, every hire adds requests, and the access estate grows by grants minus removals, which today means by nearly every grant. The finding recurs with a sharper tone each time; twelve months on, the company has more accounts with more rights and evidence that still depends on who remembered to paste the approval.
A plausible organisation with realistic proportions. The figures are there to be recalculated on your data; they are not a client result.
An engineering and construction group, 2,800 employees, about 60 business applications behind Microsoft Entra ID; roughly 20 SaaS applications connected through SCIM; the ERP, the project-management system and the CAD licence server have no provisioning interface.
About 550 access requests a month; six in ten ask for a standard role the written policy already describes; four audits a year.
Free-text tickets interpreted by an administrator, approval chased by email, grants made by hand in each console, evidence pasted into the ticket when remembered.
Around 36 minutes of combined handling per request across desk, administrator, application administrators and evidence; about 40 hours per audit rebuilding evidence.
Access packages in Microsoft Entra ID Governance execute the written policy; SCIM applications are provisioned by Microsoft Entra ID; UiPath Robots provision the other three; a register in UiPath Data Fabric holds request, approvals, grant and expiry; exceptions reach the administrator in Microsoft Teams.
In the modelled case six requests in ten are granted within policy with nobody handling them, every grant carries an end date, and the auditor's sample becomes an export. Illustrative throughout; nothing here was measured at a client.
Proposed solution
We start from the client's own access policy and turn it into access packages in Microsoft Entra ID Governance: bundles such as "site engineer, standard" or "project controller", each naming its roles, requesters, approvers, maximum duration and review cycle. A standard, low-risk package is granted directly and recorded as a policy decision; anything sensitive cannot complete without the manager, the application owner and, where the policy says so, security. Licence note: entitlement management needs Microsoft Entra ID P2 or Microsoft Entra ID Governance.
SCIM-connected applications are provisioned by Microsoft Entra ID itself. For the other three, the approved assignment produces a group-membership event that starts a UiPath workflow: a robot creates the user and the role through the administration interface, reads the result back and writes it, with the expiry date, to a register in UiPath Data Fabric; the same robots remove the access at expiry. Microsoft Teams carries the approver reminders, the ready message, and a UiPath Action Center task for the administrator when a request fits no package or a grant fails.
Microsoft Entra ID Governance entitlement management (access packages, approval stages, time-limited assignments); Microsoft Entra ID automatic user provisioning (SCIM); access reviews; UiPath Orchestrator queues, event triggers, credential store and audit log; UiPath Action Center tasks in Microsoft Teams; UiPath Data Fabric entities with audit; Microsoft Teams connector in UiPath Integration Service
The package catalogue mapped from the written policy; robots that create, change and remove accounts and roles in the three applications without SCIM, with read-back; the register and its evidence export; removal at expiry; exception handling; the Teams messages
Assignment and group-membership events from Microsoft Entra ID through the Graph-based identity connector in UiPath Integration Service (the connector still carries the name Microsoft Azure Active Directory); the ERP, the project-management system and the CAD licence server through their administration interfaces or APIs
How the automated process works
- PersonA manager or employee picks an access package from the catalogue, with reason and duration
- AutomationThe package policy decides: a standard, low-risk package is granted within policy; anything else goes to the approvers the policy names
- PersonFor sensitive packages the manager, the application owner and, where required, security approve; the reminder reaches them in Teams and Microsoft Entra ID Governance records the decision
- SystemSCIM-connected applications are provisioned by Microsoft Entra ID; the other three become items in an Orchestrator queue
- AutomationA robot creates the account and role, reads the result back, writes it to the register with the expiry date, and tells the requester in Teams; at expiry it removes what it created
- PersonA failed grant, or a request that fits no package, becomes an Action Center task in Teams for the IT administrator, who decides
Human-in-the-loop model
Automation handles
- Presenting the request as a choice of packages, not a text box
- Evaluating the policy: direct grant, or which approvers must decide
- Provisioning through Microsoft Entra ID or through robots, with read-back
- Recording request, approvals, grant and expiry, and removing access when the date arrives
People decide
- Approvals for sensitive roles: the manager, the application owner and security, each by name
- Who owns each package, what it contains and what the policy treats as low risk
- Requests that fit no package, decided by the IT administrator in Teams
Before and after
Systems and integrations
We do not add technology to make an architecture look serious. Every element below has a specific job in this process.
Inputs
- access package requests from the My Access portal
- assignment and group-membership events from Microsoft Entra ID
- the written access policy
Automation layer
- UiPath Orchestrator
- UiPath Robots
- UiPath Integration Service
- UiPath Action Center
- UiPath Data Fabric
Target systems
- Microsoft Entra ID and Microsoft Entra ID Governance
- SCIM-connected SaaS applications
- the ERP
- the project-management system
- the CAD licence server
Human touchpoints: approval stages in the access package policy; Action Center tasks in Microsoft Teams; status and reminders in Teams; the evidence export
Technologies used
access packages, approval stages, time-limited assignments with automatic removal
Acreates, updates and removes accounts in the connected SaaS applications
Aprovision and remove accounts and roles in the three applications without SCIM; queues, retries, audit log; credentials from Azure Key Vault
Apicks up assignment events from Microsoft Entra ID; posts status and reminders in Teams
Aexception tasks for the IT administrator, completed without leaving Teams
Athe register: request, approvals, grant time, expiry, removal; the evidence export
AIllustrative economic model
What it is worth, with the arithmetic shown.
A policy can only release the work it can decide, so the volume below is 330 rather than 550: the six requests in ten that fall inside a standard package. Thirty-six minutes is the combined handling across desk, administrator, application administrators and evidence filing; €52 an hour is a fully loaded IT specialist in Central Europe. The four audits a year sit under the cost of inaction. Every figure is illustrative.
Run the numbers on your data
An illustrative estimate from your own inputs. It models released capacity; it is not a promise of savings.
Business benefits
- Standard access arrives in minutes, because a policy decides instead of an email chain
- The "granted as per phone call" route closes: a sensitive role cannot exist without the approvers the policy names, recorded against the grant
- The auditor's sample becomes a query on the register instead of a fortnight of reconstruction, and the finding closes
- Every grant carries an end date, and the three applications without SCIM sit inside the same flow, so the connector's reach no longer bounds the control
The management view
- The policy is enforced at request time rather than described in a document: forbidden role combinations are checked before the grant, not after the audit
- Evidence exists by default, in the shape the auditor asks for: who requested, who approved, when, for how long
- "Who has access to what" has one answer, which is where every incident review starts
Board-level KPIs
Security and governance
Control is not an add-on.
- Sensitive roles cannot be granted outside the flow: Microsoft Entra ID Governance enforces the named approvers, and forbidden role combinations are checked at request time
- Robots hold provisioning rights only, under a dedicated service account per application; passwords are fetched at run time from Azure Key Vault through the Orchestrator credential store, and every action is logged against its request
- The register is append-only for requests, approvals and grants: a correction is a new record, never an edit
- Processing stays in the EU region of UiPath Automation Cloud and inside your Microsoft 365 tenant under the EU Data Boundary; access reviews cover what stays permanent
Why now
Auditors and cyber insurers have moved from "is there a policy" to "show me the grant, the approver and the end date"; the last finding was about evidence, and the next one will be a repeat
Entitlement management, approval policies and access reviews are standard in Microsoft Entra ID Governance, already in the tenant; what stayed hard, the applications with no interface, is ordinary robot work
The modelled €10,296 a month of handling continues for as long as the desk interprets sentences
Relevant executive roles
Access becomes a governed service with a catalogue and a register instead of a queue of interpreted emails
The policy is executed at request time; sensitive roles carry named approvals and every grant expires by design
Administrators stop chasing approvals across four consoles, and the ERP-roles expert stops being a single point of failure
Audit evidence is an export, and the finding closes at the next cycle
Common questions and objections
For the SCIM-connected applications, largely yes; where an application exposes a SQL, LDAP or SCIM endpoint, the on-premises provisioning connectors of Microsoft Entra ID may cover it too, and the robot step retires. The applications without any interface are where the tickets still come from, and robots put them inside the same policy, expiry and register.
Ten packages cover most of the volume in most companies; we start with the roles behind one quarter of requests and let the exception queue show which comes next.
It is more control, in writing. The policy states what is low risk and those requests are granted as recorded policy decisions; everything else gets the named approvers, every time.
When this is not the right solution
- Fewer than a hundred access requests a month and a handful of applications: a documented role matrix and a disciplined desk cost less than the licences
- No written access policy and no owner willing to write one; that is the first project
- An identity governance platform migration is under way, or every application is already SCIM-connected with packages in place; then the gap is adoption
A question for the next management meeting
Access that is correct but unevidenced fails the audit exactly like access that is wrong: for the next sample of 25 accounts, could this company produce the requester, the approver, the date and the end date of each grant from a system rather than from a mailbox?
Implementation approach
What we deliver, and what we need from you to start.
We deliver
- Analysis of one quarter of requests and the access matrix, to find the ten roles behind most of the volume
- Package and policy design with the CISO and the application owners: contents, approvers, durations, what counts as low risk
- Microsoft Entra ID Governance configuration, and robots for the three applications without SCIM, with read-back and exception handling
- The register, the evidence export, removal at expiry, the Teams messages, and a pilot on one business unit
We need from you
- The written access policy, or the owner who will write it, and the current access matrix
- Named owners for each application in scope, and the Microsoft Entra ID Governance licence decision
- Administrative accounts for the robots, scoped to provisioning, and one quarter of request tickets
Stages
Discovery
Requests, matrix, approvers used in practice, the SCIM and non-SCIM split
Design
Package catalogue, policy mapping, approval stages, durations, security model
Build
Microsoft Entra ID Governance configuration, robots per application, register, Teams tasks
Validation
Historical requests replayed against the packages; provisioning tested in test systems
Go-live
One business unit with the ticket route still open, then the desk switched to the catalogue
Departmental. Effort follows the number of applications without an interface, the distance between written policy and practice, and whether owners can be named.
Nine of 25 sampled accounts had a ticket but no approver. Right access, failed evidence.
Show us your access-request form and the access matrix behind it. In a half-day workshop we draft the first three access packages with you and mark which applications need a robot.
Draft three access packages with usThe neighbouring process usually has the same problem
Managers sign off on entitlements they cannot read, and nobody withdraws what nobody uses.
View solution Other solutionsAdmin rights that exist only for the task and the hourRights granted for a four-hour task stay for a career, in systems that cannot expire them.
View solution Other solutionsContractor access that ends when the contract endsProcurement closes the purchase order. Nobody tells IT. The contractor keeps the VPN for a year.
View solutionIndustries we deliver this in most oftenManufacturing & industryTransport & logisticsServices & ITShared services