CASE STUDY 02 • FICTIONAL ENTERPRISE SCENARIO

Enterprise Azure IAM Transformation

A structured identity and access management transformation for a fictional banking environment, designed to demonstrate how I assess identity risk, prioritise control weaknesses and translate findings into a target-state governance roadmap.

EXECUTIVE BRIEF

Identity risk is a business-control problem, not just an account problem.

The scenario begins with a bank facing excessive privilege, weak authentication, stale access, unmanaged guests, direct role assignments, credential risk, poor logging and absent ownership. The objective is to consolidate evidence, determine which weaknesses create the greatest exposure and propose a practical target state.

Disclosure: This is a fictional portfolio project completed from a supplied business scenario. It is not client work or employment experience.

CURRENT-STATE ASSESSMENT

Start with what exists, who owns it and what cannot yet be proven.

The assessment consolidates the identity inventory, baseline controls, existing evidence and gaps. Risks are evaluated through likelihood, impact, control weakness, accountable owner and proposed treatment.

INVENTORYIdentities & access paths

Users, privileged roles, guests, groups, service principals and workload identities.

ASSURANCEAuthentication controls

MFA coverage, Conditional Access, exceptions and legacy authentication exposure.

PRIVILEGEAdministrative access

Standing privilege, direct assignments, role scope and just-in-time opportunities.

GOVERNANCEOwnership & reviews

Access lifecycle, attestations, guest reviews, logging and evidence accountability.

PRIORITY RISKS

Prioritise the control failures that can compound.

  • Excessive privilege: broad or standing access increases blast radius after compromise.
  • Weak authentication: inconsistent MFA or weak policy coverage increases account takeover risk.
  • Stale access: inactive users and outdated entitlements undermine least privilege.
  • Unmanaged guests: external identities without owners or review cycles create persistent access paths.
  • Direct assignments: access granted outside governed group structures makes review and removal harder.
  • Poor evidence: control effectiveness cannot be defended when ownership, logging and attestation are absent.

TARGET DESIGN

Move from permanent access to governed, contextual access.

The target state uses group-based RBAC, stronger authentication, Conditional Access, Privileged Identity Management, recurring access reviews, better workload identity practices and clear evidence ownership.

RBACGroup-based access

Reduce direct role assignment and make entitlement management more reviewable.

CA + MFAContext-aware access

Protect sign-ins with policy based on user, device, risk and application context.

PIMJust-in-time privilege

Replace unnecessary standing administrative access with eligible, time-bound activation.

REVIEWSContinuous attestation

Require owners to periodically confirm whether access is still justified.

IMPLEMENTATION ROADMAP

Sequence remediation so high-risk access is controlled first.

The roadmap begins with inventory and emergency privilege controls, then strengthens authentication, restructures assignments, introduces access reviews and PIM, improves logging, formalises ownership and moves towards measurable identity governance.

ETHICAL PORTFOLIO PRESENTATION

Demonstrate capability without inventing employment history.

Every screenshot, artefact and interview explanation connected to this project should retain the fictional-project disclosure. The value is in showing how the assessment was performed, what decisions were made, what was produced and what was learned.