Ask any business about access control and they will talk about offboarding. It is the visible case, it has a clear trigger, and everyone understands the risk. Meanwhile the person who has moved between three departments in five years is quietly holding every permission from every role they ever had, and nobody has looked.
The three events
| Event | Trigger | Usually handled | Actually risky |
|---|---|---|---|
| Joiner | Start date | Yes, because someone cannot work without it | Copying access from a colleague |
| Mover | Internal role change | Rarely, because there is no urgency | Old access is never removed |
| Leaver | Last day | Usually, though often late | Contractors and shared accounts |
Why the joiner case goes wrong
The failure here is copying. Somebody asks IT to give the new starter the same access as an existing colleague, because it is fast and it works. It also copies every exception that colleague accumulated, including permissions they should not have had. Do this for three years and access has no relationship to role at all.
The fix is role-based groups. Define what a role needs once, grant that, and let the exceptions be visible as exceptions rather than propagating silently.
The mover case is the real problem
An internal move has no urgency attached to removal. The new access is needed immediately, so it gets granted. The old access is not hurting anyone, so nobody removes it. There is no ticket, no trigger, and often no notification to IT that the move happened at all.
- Require HR to notify IT of internal moves, not just joiners and leavers
- Treat a move as a leave-and-join: remove all previous role groups, then add the new ones
- Never handle a move by simply adding the new access
- Review the resulting access with the new line manager, who is the person who knows what the role needs
The quiet accumulation
Someone who has changed roles twice and never had access removed often holds more permissions than anyone in the business intended, including their own manager. It rarely shows up until an audit or an incident.
The leaver case, and where it still fails
- 1Disable the account rather than deleting it, so data ownership and audit trail survive
- 2Revoke active sessions, because disabling an account does not always kill a live session immediately
- 3Remove group memberships rather than relying on the disabled account alone
- 4Transfer ownership of files and any shared resources before archiving
- 5Wipe or selectively wipe company data from devices
- 6Handle contractors and third parties, which is where most missed access lives
Contractors are the recurring gap. There is often no formal end date, no HR record, and no trigger. Set an expiry at the point the account is created rather than intending to remove it later.
Making it hold
- Access granted to groups only, so all three events become group membership changes
- HR as the trigger for all three events, not a ticket someone remembers to raise
- Time-limited accounts for anyone who is not a permanent employee
- A periodic access review where managers confirm their own team, since IT cannot judge business need
- Reporting on accounts with no recent sign-in, which surfaces the ones everybody forgot
Not sure who has access to what?
We map current access, rebuild it around roles, and wire joiner, mover and leaver into your HR process so it happens by default rather than by memory.
Frequently asked questions
Why is the mover case worse than the leaver?
Because it has no urgency and no trigger. New access is granted immediately because someone cannot work without it, while old access harms nobody today so nobody removes it. Repeated over years, staff accumulate permissions far beyond their current role.
Should we delete or disable a leaver's account?
Disable rather than delete. Deleting can break file ownership, remove audit history and orphan shared resources. Disable, revoke sessions, remove group memberships, transfer ownership of data, then archive according to your retention policy.
How do we handle contractors?
Set an expiry date at the moment the account is created, scoped to only the systems genuinely needed. Contractors are the most commonly missed category because there is often no HR record and no defined leaving date to trigger removal.
Is disabling the account enough?
Not on its own. A disabled account may still have live sessions, and group memberships persist. Revoke active sessions explicitly and remove group memberships, particularly where those groups grant access to third-party systems outside your directory.
How often should access be reviewed?
Quarterly for fast-changing businesses, twice yearly otherwise. Managers should review their own team, because IT can see who has access but cannot judge whether a particular person still needs a particular system for their current role.
Usman K.
· IT Support LeadIT support lead at Azizi Technologies. Manages 24/7 helpdesk, Microsoft 365 migrations, server administration, and managed IT contracts for Dubai SMBs. Microsoft Certified. Mentioned by name in client reviews for fast resolution.
Need a quote for Identity & Access Management Dubai?
WhatsApp this article plus your device or site. We reply with next steps and a written quote.