Why IAM Maturity, Not Access Control Alone, Determines Breach Resilience

In August this year, news broke that the threat actor using the moniker “TheHatman” claimed responsibility for stealing over three million employee records from nine established companies, including McDonald’s Corporation, Tata Consultancy Services (TCS), and Vodafone, through lapses in their Azure tenant. 

It’s still unclear how the attacker stole a trove of data from established companies so quickly. But TheHatman attributed the data theft to “compromised credentials.” 

The breach is another reason why identity maturity shouldn’t be limited to access controls. Identity security has evolved beyond solving the “who has access to what” dilemma that access controls and many legacy identity and access management (IAM) systems typically solve. Instead, identity security must extend to understanding what your access is doing and how you can proactively spot and stop identity-related vulnerabilities and threats in real time before attackers like TheHatman exploit them. 

The Access Control Blindspot

One lesson security teams should take from the Azure campaign breach is that using a modern identity provider doesn’t automatically make your identity posture resilient or free from the same problems that legacy IAM platforms have. 

Azure is a cloud-based platform that offers security capabilities, but identity management isn’t automatic just because it’s a modern solution. It still requires security teams to implement the following identity security measures: 

    • Conditional access policies to enforce strict access control
    • MFA enforcement across tenants and users, entitlement management for automated onboarding and offboarding
    • Identity protections that flag compromised sign-ins and accounts. 

Failure to do any of these means your organization is likely to experience the same underlisted blind spots affecting traditional IAM: 

    • Unknown identities: Victim organizations had thousands of service accounts, many unmapped and unowned.
    • Ungoverned permissions: Directory export had no access restrictions. Any valid credential could read it.
    • Weak credential hygiene: Static credentials persisted for years. MFA was optional for admins.
    • No lifecycle discipline: Stale accounts were never decommissioned. Permission reviews were quarterly or absent.
    • Reactive incident response: Detection took weeks. The response took longer.

These blind spots create a “golden hour” chance for attackers to steal credentials, have unsanctioned access to sensitive resources, and go unnoticed in the internal environment until a breach happens. 

The Azure campaign wasn’t just successful because credentials were stolen (this happens often even with modern IAM systems), but because the organizations weren’t actively monitoring their identities and permissions to spot anomalies and proactively contain threats.

The Three Pillars of Identity Resilience

Moving beyond traditional IAM requires three interconnected capabilities:

1. Visibility: Taking the inventory as a starting point

The running principle in cybersecurity is that you can’t protect what you don’t know. And that mantra sits comfortably in IAM, too. 

And visibility is the first step to understanding the assets you need to govern. It helps security teams uncover where identities live, how to manage scope (resources they access and permission level), and assign ownership and accountability to identities. It creates the “access graph” essential for preventing escalation and, in the case of a breach, for tracking the attack chain. 

In general, visibility asks these questions and provides the answers: 

    • What number of human and non-human identities (NHIs) do we have? (The typical answer is “more than we thought.”)
    • Where do my identities live?
    • Who owns them? Often, nobody knows.
    • What do they have access to? (Usually, more than they should)

Visibility begins with automated identity discovery throughout the entire environment (cloud, on-premises, or hybrid), including API integrations. And visibility isn’t a one-time process: it should be continuous and timely to keep up with the latest identities and access permissions. 

For example, in a system with effective visibility, the compromised credential, account, or sign-in responsible for the Azure campaign breach should have been flagged as a security threat at the point of entry.

2. Intelligence: From a stock list to a proper understanding

Without context, raw inventory is just mere numbers. The real deal is ensuring effective data sharing among the inventoried assets, identities, and resources. That data creates the intelligence that turns information or alerts into actionable steps. 

Intelligence establishes a standard acceptable baseline behavior to expect from identities. For example, a service account accessing one million directory records all at once is abnormal. Similarly, it should be an anomaly for a global administrator to log in from two geographically distant locations within minutes. Also, a credential appearing in a dark web leak is unacceptable behavior. All these behaviors signal imminent threats. 

But signals are only useful if they lead to actionable steps. This is where intelligence comes in. Intelligence works in three critical steps: 

    • Risk scoring: All anomalies aren’t the same. When assessing how urgent an alert should be, the privilege level, data sensitivity, and the degree of behavioral deviation are key factors. 
    • Threat intelligence integration: Dark web monitoring, infostealer feeds, and industry threat reports need to be mapped back to your identities in real-time.
    • Predictive insights: Experienced organizations anticipate the attacker’s next steps. It answers this question: “This account has been gathering reconnaissance; what will the attacker do next?”

In the Azure campaign, for example, intelligence should have flagged the following: 

    • A service account or any credential trying to access hundreds of thousands of employee directory records (data exfiltration baseline exceeded)
    • Impossible travel (admin account signing in from multiple countries in minutes)
    • Bulk secrets extraction (multiple credentials accessed by single account)

3. Action: Progressing from intelligence to containment

Insights aren’t useful if they don’t lead to containment at machine speed. The traditional incident response approach that relies on human intervention after being alerted is too slow. By the time that happens, the attackers would have moved laterally or extracted the data, as we saw with the Azure campaign breach.  

In this context, action should be automated based on predefined policies. In this context, high-risk activities, such as bulk exfiltration of sensitive data, should be mapped to a block policy before the act is committed, not after. If a sign-in or account is suspicious, the active session and account should be revoked pending internal audit. 

You can automate action by doing the following: 

    • Escalation automation: Route alerts to the right team with context. For example, CISO for admin compromise, SOC for anomalies, and compliance for policy violations. 
    • Remediation agents: Employ AI-driven systems that respond to known attack patterns without human intervention. 

You Need IAM Maturity to Build Security Resilience

An IAM system with automated detection and remediation capabilities that can repel attacks doesn’t happen at once. It’s a painstaking process, and organizations can track their maturity level using the IAM Maturity Model.

Your maturity level can fall into any of the following levels:

Level 1 (Initial): Identity management is handled on an ad hoc basis, with no inventory, no monitoring, and no policies. The response to a breach involves guesswork based on forensic investigation. The risk level is very high and similar to that of many of the victims in the Azure campaign.

Level 2 (Repeatable): Basic discovery along with documented procedures. You are aware that your identities exist, but governance is inconsistent. Monitoring is mainly carried out by hand. The level of risk is high since some breaches will be detected, but the response will be slow. 

Level 3 (Defined): The discovery process is standardized, policies are enforced in a systematic manner, and continuous monitoring is available. More than 80% of identities comply with policy. The risk level is medium, and detection occurs within hours, with a response taking place within a day.

Level 4 (Managed): Policy enforcement is carried out in real time and automatically, with any anomalies causing immediate containment. The incident response takes place within one hour. The risk level is low, and attackers encounter immediate resistance.

Level 5 (Optimized): The system can carry out autonomous threat response and ongoing learning. It can predict and prevent attacks without human intervention. The level carries a minimal risk level. 

The victims of the Azure campaign breach were probably at level 1 or 2, which accounts for their lack of visibility, inability to detect anomalies, and a dwell time that lasted for weeks. Organizations at level 3 and above would have prevented most of the damage.

What Identity Maturity Progression Looks Like

Reaching identity maturity is best done in five phases (Discover, Govern, Secure, Manage, and Remediate). Each phase builds on the one that comes before it. You cannot govern identities and assets you have not discovered. And identity-related threat remediation will struggle without identity governance and controls. Although the progression is sequential, the benefits are exponential since at each stage breach risk is reduced and response times are sped up.

  • Phase 1 (Discover): List all the identities, including humans and NHIs. Determine the owner (who can access it) and scope (what resources they can access) for each identity. The result, in terms of maturity, will be complete visibility.
  • Phase 2 (Govern): Every identity should follow least privilege policies and role-based access controls. Active controls, such as automated joiner-mover-leaver and just-in-time access, should exist to prevent overprivileged access and protect high-risk accounts. The result will be policy-driven access control.
  • Phase 3 (Secure): Enforce MFA for administrative accounts, remove long-lived credentials, implement automated credential rotation, and check for compromised credentials. The result is credential hygiene at scale.
  • Phase 4 (Manage): Set up a continuous access review to revoke expired permissions and identities. Automate lifecycle management to offboard inactive or expired accounts and access. Keep audit records. Put change controls in place. The maturity outcome is effective day-to-day identity management.
  • Phase 5 (Remediate): Set up controls, such as identity threat detection and remediation (ITDR) and automated incident response, for real-time threat detection, monitoring, and containment. Conduct post-incident analysis on contained threats to improve resilience against attacks in the wild.

In the Azure campaign situation, a mature organization at Phase 3 would have spotted the directory exfiltration within hours and would have contained it. An organization in Phase 4 would likely have prevented the situation through real-time threat monitoring. An organization at Phase 5 would have uncovered and addressed the vulnerabilities to prevent the attack. 

In general, organizations in Phase 3+ record this maturity scoring:

Access Control Isn’t the Only IAM Control You Need

Traditional IAM systems overfocus on access permissions. The system wasn’t designed to stop dynamic credential-based attacks because of a lack of visibility across assets and resources and an inability to monitor sessions and access beyond the front-door authentication. 

Filling that gap involves methodically enhancing visibility, gaining intelligence to understand anomalous behavior even with valid credentials, and automated response to contain threats. It also means recognizing that breach resilience is a journey towards maturity, not a single-project effort.

The Azure campaign breach showed that having modern identity tools isn’t enough. It’s more about having the self-discipline to know what you have, the intelligence to spot what’s abnormal, and the ability to stop it quickly.

How does your IAM program measure up?

What area should be your first priority?

Simeio’s advisory and benchmarking service team provides a clear, quantifiable assessment of your identity management system, highlighting both strengths and areas for improvement. Schedule a session now to explore critical aspects of your identity fabric from onboarding to risk management. Gain a clear roadmap for enhancing your identity platform, closing gaps, and strengthening your enterprise’s security foundation.