MIP and the JML lifecycle: identity that keeps pace
Managed Identity Provider (MIP) is Dual-Strike XISEM’s identity governance surface. It correlates Entra ID, M365, PSA/HR signals, and platform detections so human and non-human identities (NHI) do not drift unnoticed.
Join — provision with evidence
• New hire appears in PSA or HR Gateway (when integrated)
• Entra account created → first sign-in on Asset timeline
• MIP shows provisioned state with expected group memberships
• COBRA² can alert on over-privileged new accounts
Move — role change is the risky beat
Most incidents are not joiners — they are movers:
• Department change without group cleanup
• Old admin roles retained “temporarily”
• License downgrade but retained SharePoint access
MIP highlights delta between expected and actual entitlements after move events.
Leave — deprovision completely
• PSA offboarding ticket closed ≠ Entra disabled (verify both)
• MIP tracks disabled accounts, mailbox forwarding, active sessions
• Pair with Browsing Insights for OAuth grants that survive disable
NHI — service accounts and app registrations
Non-human identities include:
• Azure app registrations with secrets
• Service principals with Graph permissions
• Legacy service accounts with password never expires
MIP NHI panel (public marketing: dual-strike.com/mip) surfaces stale secrets, excessive API scopes, and ownerless apps.
vCISO monthly review (30 min)
1. Leavers last 30 days — all disabled in Entra?
2. Movers — any admin role accumulation?
3. NHI top 10 by privilege — owners assigned?
4. Export gaps to POA&M and PSA remediation project
Related: GDAP onboarding · Conditional Access intelligence · MIP NHI deep dive (post #4)
Identity evidence from Gateways — XISEM does not provision Entra directly.


