MIP and the JML lifecycle: identity that keeps pace
Subtitle: Join, Move, Leave — plus non-human identity governance in one Managed Identity Provider view.
Managed Identity Provider (MIP) is Dual-Strike XISEM’s identity governance surface. It correlates Entra ID, M365, PSA/HR signals, and platform detections so human and non-human identities (NHI) do not drift unnoticed.
Join — provision with evidence
New hire appears in PSA or HR infeed (when integrated)
Entra account created → first sign-in on Asset timeline
MIP shows provisioned state with expected group memberships
COBRA² can alert on over-privileged new accounts
Move — role change is the risky beat
Most incidents are not joiners — they are movers:
Department change without group cleanup
Old admin roles retained “temporarily”
License downgrade but retained SharePoint access
MIP highlights delta between expected and actual entitlements after move events.
Leave — deprovision completely
PSA offboarding ticket closed ≠ Entra disabled (verify both)
MIP tracks disabled accounts, mailbox forwarding, active sessions
Pair with Browsing Insights for OAuth grants that survive disable
NHI — service accounts and app registrations
Non-human identities include:
Azure app registrations with secrets
Service principals with Graph permissions
Legacy service accounts with password never expires
MIP NHI panel (public marketing: dual-strike.com/mip) surfaces stale secrets, excessive API scopes, and ownerless apps.
vCISO monthly review (30 min)
Leavers last 30 days — all disabled in Entra?
Movers — any admin role accumulation?
NHI top 10 by privilege — owners assigned?
Export gaps to POA&M and PSA remediation project
Related: GDAP onboarding · Conditional Access intelligence · MIP NHI deep dive (post #4)
Identity evidence from infeeds — XISEM does not provision Entra directly.

