IAM review covering SSO coverage, MFA adoption, role proliferation, and orphaned account hygiene for [REDACTED] Group. Engagement ref. ENG-2025-0560.
Plaidnox reviewed the identity landscape for [REDACTED] Group across Microsoft Entra ID (Azure AD), on-premises Active Directory, and 12 SaaS applications. The review identified 14 significant gaps including a 32% MFA coverage gap, 847 orphaned accounts, and role proliferation with 3,200+ custom permission assignments outside of standard groups.
The most critical finding is that 143 accounts with access to patient data systems have never used MFA. These represent an immediate HIPAA and NHS Data Security Standard compliance risk.
| Category | Count | Issues Found | Priority |
|---|---|---|---|
| Regular User Accounts | 6,840 | MFA not enforced for 2,197 | High |
| Privileged Admin Accounts | 312 | 68 with no MFA . 41 inactive 90+ days | Critical |
| Service Accounts | 741 | 214 with excessive permissions | High |
| Orphaned / Stale Accounts | 847 | Active accounts for departed staff | Critical |
| External / Guest Accounts | 500 | No expiry policy enforced | Medium |
| ID | Finding | Priority |
|---|---|---|
| IAM-G01 | 847 orphaned accounts . active AD/Entra accounts for staff with no HR record | Critical |
| IAM-G02 | 143 PHI-access accounts without MFA . direct HIPAA compliance risk | Critical |
| IAM-G03 | No joiner-mover-leaver (JML) process integrated with HR system | High |
| IAM-G04 | SSO coverage at 58% . 5 clinical applications not federated, using local accounts | High |
| IAM-G05 | No Privileged Identity Management (PIM) . admin roles are permanent, not just-in-time | High |
| Action | Timeline | Owner |
|---|---|---|
| Disable all 847 orphaned accounts pending access review | Immediately | IT / HR |
| Enforce MFA via Conditional Access for all PHI-access accounts | Wk 1-2 | IT |
| Integrate HR system with Entra ID for automated JML provisioning | Wk 2-8 | Plaidnox / IT |
| Federate 5 clinical applications via SAML/OIDC to Entra ID SSO | Wk 4-12 | Plaidnox |
| Deploy Azure AD PIM for all Global Admin and privileged roles | Wk 3-6 | Plaidnox / IT |