Cybersecurity

Identity & Access Management

In on day one. Out the same day.

Identity and access management (IAM) is how people get accounts, get the right level of access, and lose it the day they leave. It covers joining, changing role, leaving, administrator separation, single sign-on and regular access reviews. happier IT builds and runs it for Canadian organizations of roughly 15 to 200 people. Nearly all of them have a good joining process and no leaving process.

Who it's for

Access is easy to grant and nobody owns taking it away.

Every organization has a process for day one, because somebody complains if it does not work. Nobody complains about a leaver keeping their remote access.

Nobody can list your former staff accounts. Not out of negligence, because accounts are created by whoever is asked and disabled by whoever remembers. The list exists in three systems and agrees in none of them.

Access accumulates and never sheds. Someone moves from operations to finance and keeps both sets of permissions. Five years and two moves later they can reach almost everything, and nobody ever decided that.

Everyone is an administrator. Usually because one piece of software needed it once, and the quickest fix was applied to everyone. Entirely fixable, and nobody’s fault.

There is a shared login. The reception mailbox, the accounting package, the social accounts, the firewall. One password known by nine people, at least one of whom left in the spring.

The offboarding checklist

Ask for yours. Where one exists it usually covers the laptop and the email account and stops there: not the remote access, not the phone system, not the line-of-business application, not the shared password vault, not the building fob, not the account with your accounting software vendor.

Writing that list is an afternoon of work. Not having it is a gap we find often.

What's included

What good access management consists of.

Most of this is process rather than product, which is why it tends to be skipped and why it is cheap.

  • A joiners, movers and leavers process

    One route for creating access, one for changing it when someone moves role, and one for removing it. Movers are the neglected middle case, and the one that quietly produces people who can reach everything.

  • Least privilege as the starting position

    People get the access their role needs and nothing inherited from a predecessor. Access beyond the standard set is requested, approved by a named person, and given an expiry date where the reason is temporary.

  • Administrator accounts kept separate

    Nobody administers the environment from the account they use for email. Separate administrator accounts, used deliberately, with a stronger second check, a hardware key or an authenticator app rather than a text message.

  • Single sign-on where it exists

    SSO means one identity across your applications, so access is switched off in one place rather than eleven. It also removes the password reuse that credential leaks depend on. Not every small vendor supports it, and we will tell you which of yours does not.

  • Conditional access and device trust

    Rules that consider the device and the circumstances of a sign-in rather than only the password. Configured in your <a href="/cybersecurity/microsoft-365-security/">Microsoft 365 tenancy</a>, where most organizations of this size already own the licence for it.

  • Shared and service accounts under control

    The logins that belong to no one: put in a password manager, given a named owner, documented, and rotated when someone with access leaves. Service accounts get the same treatment plus a note of what breaks if the password changes.

  • Quarterly access reviews

    Each manager receives a plain list of who on their team has what, and confirms or removes. It takes about an hour a quarter and it is the only mechanism that reliably catches accumulated access.

  • Same-day offboarding, run from a checklist

    Accounts disabled rather than deleted, sessions revoked, tokens invalidated, mail delegated to a manager, devices collected, shared passwords rotated. Timed with the conversation, not the following Monday.

How it works

Fix leaving first. It is the fastest win here.

Counter-intuitive order, and the right one: stopping the leak matters more than tidying the pool.

  1. Map who has what

    Every account across your directory, your cloud applications, remote access and the systems with their own separate logins, matched against your current staff list. The mismatch between those two lists is the first deliverable, and it is usually longer than expected.

  2. Build the leaving process

    A written checklist covering every system, agreed with whoever handles HR, with a trigger that starts it automatically. Then we run it against the dormant accounts the map turned up, disabling rather than deleting so nothing is lost.

  3. Then tidy the standing access

    Administrator rights reduced to named separate accounts, shared logins moved into a password manager, standard role profiles defined so the next joiner gets the right access by default, and the first quarterly review scheduled.

What it costs

Included in managed IT. The project part is quoted once.

The ongoing cost is small because most of this is process. The one-off cost is the first cleanup, and it depends entirely on how long the drift has run.

Joiner and leaver handling, access reviews and administrator separation are inside happier IT’s managed IT Setting up a new starter and removing a leaver are not billable events with us, because charging for offboarding is a good way to discourage it.

Two real licence costs sit alongside it. A password manager for shared credentials is a small per-user monthly fee. Single sign-on sometimes sits behind a higher tier with third-party vendors, and we will show you which of your applications charge for it.

The cheapest hour in security

Disabling dormant accounts costs nothing and removes standing access that nobody is watching. It is in week one of every happier IT onboarding, before anything is purchased.

If you do one thing after reading this page, get the list of accounts and compare it to your payroll.

Why us for this

Identity is where most incidents start and end.

The unglamorous truth is that a working password on an account with too much access explains a great deal of what goes wrong, and both halves of that sentence are fixed with process rather than product. That is why identity sits ahead of most security purchases in our advice.

happier IT watches sign-in activity from our own security operations centre in Canada, staffed by our employees, with agreed authority to disable an account without waking you. Staffed hours: 24/7, with the Surrey office on Monday to Friday, 8:00 am to 5:00 pm Pacific.

When a credential turns up through dark web monitoring, this is where the response happens: reset, revoke, check for changes, confirm reuse. The monitoring is the alarm; access management is the thing the alarm is attached to.

Go deeper

Questions

What people ask before they sign anything.

What is identity and access management?

It is the set of processes and tools that decide who has an account, what that account can reach, and how both change over time. In an organization of 15 to 200 people it is mostly four things: a consistent way to create access, a way to adjust it when someone changes role, a reliable way to remove it, and a periodic check that what people have still matches what they do.

What is least privilege?

Least privilege means each account carries only the access its work requires, and nothing more. In practice it shows up as ordinary staff working in accounts that cannot install software or reach every shared folder, and administrators using a separate account for administrative work. The benefit is containment: whatever happens to an account is limited to what that account could already do.

How quickly should we remove access when someone leaves?

Same day, timed to the conversation rather than to the paperwork. For a planned departure that means disabling accounts and revoking active sessions at the agreed hour, not at the end of the week. Note that disabling and revoking are two different actions: an account can be disabled while an already-established session keeps working, which surprises people. Disable, revoke, then reassign the mailbox.

Do we need single sign-on?

If you run more than a handful of applications with their own separate logins, yes, it removes password reuse and gives you one place to switch someone off. Below that threshold, a shared password manager plus multi-factor authentication gets most of the value for a fraction of the cost. Be aware that some vendors charge substantially more for the tier that includes single sign-on, which is a real factor in the decision.

What about contractors and seasonal staff?

Give them accounts with an expiry date set at creation. It is the single most effective habit in this whole area, because it makes the default outcome correct: if nobody renews it, access ends by itself. For construction, agriculture and anything with a season, it prevents the annual accumulation of accounts belonging to people who may or may not return.

What does identity and access management cost?

Beyond that the only real costs are a password manager and, occasionally, a vendor tier that includes single sign-on.

Want to know what this would look like for you?

A 30-minute call. No slides, no audit fee, no obligation. We ask what is breaking and tell you honestly whether we are the right fit.