Joiner-Mover-Leaver: How Microsoft Entra ID Governance Closes the Identity Lifecycle Gap for Canadian SMBs
One in three employed Canadian professionals plan to look for a new job in the first half of 2026. Among technology workers, that figure reaches 43%, according to a 2026 survey of Canadian job-seekers published by Robert Half / HCA Magazine. That level of labour mobility is not unusual — but it creates a security and compliance problem that most Canadian SMBs are not managing with any consistency: what happens to a former employee's access the day after they leave?
The answer at most organizations is "not much, at least not immediately." Research cited by ShieldNet360's 2026 offboarding guide found that 89% of employees retain access to sensitive corporate applications well after departure. Only 20% of organizations have any formal process for revoking API keys and service accounts when an employee leaves — and shared credentials may never get rotated at all.
For Canadian SMBs, this is not just an operational gap. It is a PIPEDA exposure. PIPEDA's Safeguard Principle (Principle 7) requires organizations to protect personal information with security safeguards appropriate to the sensitivity of the data. Leaving active credentials in place for departed employees — credentials that reach systems containing customer personal information, employee records, or financial data — is a failure of that principle that is difficult to defend to the Office of the Privacy Commissioner if a breach follows.
Microsoft Entra ID Governance is the Microsoft identity platform's answer to this problem. For Canadian SMBs already running on Microsoft 365, it is the most accessible path to automating the joiner, mover, and leaver workflows that keep your identity environment governed — and your PIPEDA posture defensible.
The Three Failure Modes
Identity lifecycle failures at SMBs cluster around three patterns, each with a distinct risk profile.
Orphaned accounts. When an employee leaves, their Entra ID account remains active unless IT explicitly disables it. In a small team with no formal offboarding checklist, that account may remain open for days, weeks, or indefinitely. An active account — especially one whose password has not been cycled — is a standing invitation for unauthorized access. According to the Verizon 2026 Data Breach Investigations Report, which analyzed more than 22,000 confirmed breaches, internal actors appeared in 12% of breaches. The same report found that third-party involvement in breaches reached 48% in 2026 — up from 30% the prior year. Many third-party compromise paths begin with credentials tied to inactive or stale accounts.
Privilege creep. Employees accumulate access rights over their tenure. A team lead who started in operations gets added to a SharePoint site, a billing distribution group, a project management tool, a CRM admin role. When they move to a new position, old access rarely gets revoked — removing it requires work and rarely makes anyone's priority list. A 2025 identity governance survey cited by CloudEagle.ai found that 1 in 2 employees retain excessive privileges relative to their current role, and only 5% of organizations enforce strict least-privilege policies. Over a five-year tenure with three role changes, an employee's access may span every system their past teams touched — none of it malicious, all of it a liability when that account is compromised.
Mover gaps. Internal transfers are the least visible failure point. When an employee moves from HR to Finance, IT may update their job title but leave their previous group memberships intact. The new role adds permissions; the old role keeps them. No individual in this chain is making a bad decision — it is just that the system does not automatically remove what it no longer needs to grant.
PIPEDA and the Access Control Requirement
PIPEDA's Safeguard Principle is deliberately flexible. It does not prescribe specific controls — it requires safeguards "appropriate to the sensitivity of the information." But the Office of the Privacy Commissioner of Canada's guidance is clear on access: "Access to personal information shall be restricted to those employees who need it to perform their job functions." This is a least-privilege requirement embedded in Canada's federal privacy law — not a recommendation from a security framework.
When the OPC investigates a breach and finds that the compromising access belonged to a departed employee whose account was never disabled, or to a user who had accumulated six years of access grants across three role changes, the absence of any formal lifecycle process is a finding against the organization. The OPC received 693 breach reports from businesses in its 2024-2025 reporting year. Access control failures appear repeatedly in the underlying causes.
The CCCS Baseline Cyber Security Controls for Small and Medium Organizations (ITSM.10.089) — the document that defines appropriate security safeguards for Canadian SMBs, directly referenced in PIPEDA's language about security obligations — explicitly requires organizations to manage user accounts and access rights throughout the account lifecycle. This means provisioning on hire, adjusting on role change, and revoking on departure. Manual processes satisfy this requirement only when they are actually executed consistently — which the data suggests they rarely are.
The 2026 IBM Cost of a Data Breach Report (Canada) sets Canadian average breach costs at CA$7.11 million — the highest since the study began. Organizations that extensively deployed AI in their security operations averaged CA$5.5 million per breach, compared with CA$8.91 million at organizations with no AI deployment. Governance automation — which prevents the conditions that turn a compromised credential into a full breach — is part of what produces that gap.
What Microsoft Entra ID Governance Does
Microsoft Entra ID Governance is a set of identity lifecycle and access governance capabilities built on Microsoft Entra ID. It is distinct from Microsoft Entra ID Protection, which handles risk-based conditional access and sign-in risk detection. Governance is specifically designed to automate the joiner, mover, and leaver workflows that most SMBs currently handle through ad hoc IT ticketing — or do not handle at all.
Four components are most relevant for a Canadian SMB:
Lifecycle Workflows
Lifecycle Workflows automate provisioning and deprovisioning tasks triggered by HR events — typically via Microsoft Entra's HR source integrations or manual triggers in the admin centre. A joiner workflow can provision a new user's account, add them to the correct security groups, assign Microsoft 365 licences, and send a welcome message — automatically, before their first day. A leaver workflow can disable the account, revoke active sessions across all devices, remove Microsoft 365 licences, and notify the departing employee's manager to claim file ownership — within minutes of the HR record updating, without IT having to run a checklist.
For organizations where offboarding currently means "IT submits a ticket when HR remembers to tell them," this is the most operationally significant component. It closes the window between departure and deprovisioning from days or weeks to minutes.
Access Reviews
Access Reviews enforce least privilege through scheduled recurring audits. You configure a review to ask managers, resource owners, or users themselves whether a specific access assignment remains appropriate. Reviews can run weekly, monthly, quarterly, or annually — and if a reviewer does not respond within the configured window, access can be automatically revoked on the assumption that no response means no longer needed.
Organizations that implement Access Reviews typically see a 30–50% reduction in unnecessary access permissions within the first review cycle, according to Microsoft's implementation documentation on Entra ID Governance access reviews. For a Canadian SMB with no formal access review process, running the first quarterly review for administrator roles and SharePoint site owners is usually enough to surface a decade of accumulated access that no one intended to keep.
Privileged Identity Management
Privileged Identity Management (PIM) replaces standing administrative access with time-limited, approval-gated elevation. Instead of an IT administrator holding permanent Global Administrator rights over your Microsoft 365 tenant, they request activation when they need it — for a defined window such as four hours — the request is logged, and access expires automatically.
The CCCS baseline explicitly requires minimizing standing privileged access. PIM is the Microsoft platform's native mechanism for meeting that requirement. For a small IT team where two or three people share administrative responsibilities, PIM also produces an audit trail: every use of privileged access is time-stamped, attributed, and reviewable. When an incident response requires you to establish what administrative actions were taken and by whom, that log is what makes the reconstruction possible.
Entitlement Management
Entitlement Management allows you to define access packages — bundles of resources appropriate to a role or project — and let users or managers request them through a self-service portal with approval workflows. A new project that requires access to three SharePoint sites, a Teams channel, and a Power BI workspace can be packaged and assigned via a request workflow that expires when the project ends.
Entitlement Management also governs time-limited guest access for partners and contractors, with automatic expiry — eliminating the guest account sprawl that is common in Microsoft 365 environments where external collaborators accumulate without anyone tracking when their engagement ended.
Licensing: What You Need
Entra ID Governance features require Microsoft Entra ID P2 licences for users in scope. P1 licences — which are included with Microsoft 365 Business Premium — provide Conditional Access and basic identity protection but do not include Lifecycle Workflows, Access Reviews, PIM, or Entitlement Management.
| Feature | M365 Business Premium (P1 included) | Requires Entra ID P2 |
|---|---|---|
| Conditional Access | Yes | — |
| Multi-Factor Authentication | Yes | — |
| Self-Service Password Reset | Yes | — |
| Lifecycle Workflows | No | Yes |
| Access Reviews | No | Yes |
| Privileged Identity Management | No | Yes |
| Entitlement Management | No | Yes |
Microsoft Entra ID P2 is available standalone at approximately US$9.00 per user per month. For SMBs on Microsoft 365 Business Premium, the most common approach is a targeted P2 add-on applied to high-risk user categories rather than the full organization: IT administrators, finance team members with access to sensitive systems, HR staff with privileged data access, and anyone with SharePoint site collection or Exchange administrative roles. Applying P2 selectively to the users whose access carries the most risk — rather than purchasing it per-seat across a 50-person team — is a practical cost management decision. For organizations on Microsoft 365 E5, P2 is already included.
Getting Started: Three Steps
1. Audit your current identity risk surface. Before configuring any governance workflow, understand what you are governing. In the Microsoft Entra admin centre, pull a sign-in activity report filtered to accounts that have not signed in within 90 days — these are your orphaned account candidates. Run a separate report on users with Global Administrator, Exchange Administrator, SharePoint Administrator, and any custom privileged roles. Compare both against your current HR roster. The gap between what your HR system considers active and what Entra shows as active is your immediate exposure.
2. Automate the leaver workflow first. The highest-impact, lowest-complexity starting point is automating the leaver process. A basic Lifecycle Workflow — triggered by an account disable event in Entra ID or by an HR termination date — that revokes sessions, removes Microsoft 365 licences, disables the account, and notifies the manager closes the most dangerous failure mode before you tackle the more complex joiner and mover scenarios. This single workflow, configured and tested, eliminates the "departed employee with active credentials" risk that is otherwise entirely dependent on someone remembering to submit a ticket.
3. Schedule a quarterly Access Review for administrator roles. Privileged roles should be reviewed most frequently. Configure an Access Review targeting Global Administrator, Application Administrator, and any custom privileged roles, running on a quarterly cadence, with automatic revocation of any role not explicitly re-confirmed by the reviewer. This is the minimum viable access governance process for an SMB without a dedicated security team — and it satisfies the CCCS baseline requirement for managing privileged access while producing the audit trail the OPC would expect to see if it asked how you manage administrative access to systems containing personal information.
Sources
- Verizon. *2026 Data Breach Investigations Report.* verizon.com
- IBM. *IBM Report: Canada's Data Breach Costs Hit Record High as Attacks Target Critical Infrastructure.* canada.newsroom.ibm.com (July 29, 2026)
- Robert Half / HCA Magazine. *1 in 3 Canadian Workers Plan to Leave Their Job in Early 2026.* hcamag.com
- ShieldNet360. *How to Revoke Employee Access When Offboarding (2026 Guide).* shieldnet360.com
- CloudEagle.ai. *What Is Privilege Creep and How to Prevent It?* cloudeagle.ai
- Abnormal AI. *62% of Breaches Involved the Human Element: Key Takeaways From Verizon 2026 DBIR.* abnormal.ai
- Microsoft Learn. *What Are Access Reviews? — Microsoft Entra ID Governance.* learn.microsoft.com
- Microsoft Learn. *Microsoft Entra ID Governance Licensing Fundamentals.* learn.microsoft.com
- Canadian Centre for Cyber Security. *Baseline Cyber Security Controls for Small and Medium Organizations (ITSM.10.089).* cyber.gc.ca
- Office of the Privacy Commissioner of Canada. *PIPEDA Principle 7 — Safeguards.* priv.gc.ca
- Office of the Privacy Commissioner of Canada. *2024-2025 Annual Report.* priv.gc.ca
Identity governance is one of the highest-leverage investments a Canadian SMB can make — it closes the offboarding gaps that create PIPEDA liability, enforces least privilege across a growing workforce, and produces the audit trail that turns a security incident from a months-long investigation into a half-day reconstruction. Cloud Forces helps Canadian SMBs design and deploy Microsoft Entra ID Governance configurations — from identity risk assessments and Lifecycle Workflow implementation through Access Reviews, PIM configuration, and Entitlement Management for contractors and guests. Explore our Cybersecurity services or contact us to begin with an identity risk assessment that maps your current access exposure against your PIPEDA obligations.
Anton Kuznetsov is the founder and principal engineer of Cloud Forces, the Toronto firm he started in 2018 to make custom software and AI practical and affordable for Canadian SMEs. He works hands-on across application development, cloud architecture, and the production systems Cloud Forces runs for its clients.
Ready to bring AI to your business?
Book a free AI Readiness Consultation — no commitment required.
Book Free Consultation