Practitioner's guide to the future of identity — new maturity model
Access the guide

A fast-growing managed security provider finds 217 orphaned accounts on day one

217 disabled accounts still had live access. It took one query to find them. Oleria connected to Entra ID and SharePoint on the first day, surfaced orphaned access and dormant sites, and helped the provider prepare for SOC 2 while it doubled its headcount.

Watch video

1

Day

Actionable identity findings on the first day of deployment

217

Disabled accounts

Still holding group access and resource privileges, identified and revoked

331

Dormant SharePoint sites

Inactive for 90+ days, cataloged along with 140 externally shared assets and 70 anonymous links

Industry

Cybersecurity and IT services

Use Cases

Identity hygiene

NHI security

Offboarding security

SOC 2 readiness

Size

Mid-market

Headcount doubling

About the organization

The provider delivers threat detection, identity management, and cloud security governance to enterprise clients across North America. It doubled its workforce in a short period while running its own operations on Microsoft Entra ID, SharePoint Online, and Salesforce.

The challenge

Growth outpaced the manual onboarding and offboarding processes that served the company when it was smaller. With a SOC 2 audit ahead, the lean internal security team needed a complete view of access across Entra ID and SharePoint.

  • Offboarding gaps. Manual offboarding left 217 disabled user accounts with active group permissions and resource access.
  • SharePoint sprawl. 331 SharePoint sites had been dormant for more than 90 days, holding 140 externally shared assets and 70 anonymous access links.
  • Review workload. Access reviews took many hours of manual effort without usage context, putting pressure on the SOC 2 timeline.
  • Activity anomalies. Without correlated identity activity, anomalous logins, such as a US user signing in from a Japanese IP address, could go unnoticed.

"Oleria delivered value on day one, surfacing orphaned accounts and dormant SharePoint sites our existing tools missed. Our team automated identity hygiene, secured external sharing, and streamlined SOC 2 readiness while the company doubled in size."

Manager, Security Operations, managed security services provider

“People are really, really good at sharing things — but not so good at revoking those privileges once they’re no longer needed.”

Peter Clay
CISO, Aireon

The solution

The provider deployed Oleria across Microsoft Entra ID, SharePoint Online, and Salesforce. Oleria connected natively within minutes, mapped permission paths, analyzed live activity, and surfaced dormant access on the first day.

  • Same-day access graph across Entra ID and SharePoint Online, covering nested groups, direct entitlements, and site-level permissions within hours.
  • Leaver detection cross-references directory status with resource rights to find former employees who keep access, with one-click revocation and ticketing integration.
  • SharePoint sharing audit catalogs dormant sites and flags external and anonymous sharing links.
  • Anomaly detection uses geolocation and authentication data to flag inconsistent logins, and caught suspicious access during early deployment.

Business outcomes

The provider now runs identity hygiene continuously and is audit-ready without adding security headcount.

  • Day-one visibility. Cross-platform permission visibility on the first day exposed gaps that existing tools had missed.
  • Offboarding gaps closed. Live access was revoked across 217 disabled accounts during a period of 100% headcount growth.
  • Smaller SharePoint attack surface. 331 dormant sites and 210 external and anonymous shares are cataloged and under active review.
  • Early threat detection. Automated alerts flagged geographically suspicious logins without manual log analysis.
  • Faster SOC 2 preparation. Activity-backed evidence simplified access certifications and kept security operations lean.

Key takeaways

  • Fast growth strains manual offboarding first, and orphaned access is where it shows.
  • Native connectors produce actionable findings on the first day of deployment.
  • Usage evidence shortens SOC 2 access reviews for lean teams.

“If you ask any CISO, ‘How many files have you shared outside the company?'. . . most don't have answers — or they don’t have easy ways to answer those questions. In Oleria, I can answer those questions with a click.”

Mark Carter
CIO and CISO
Vimeo

“Having visibility and the ability to remove that share or that file access...is a real differentiator.”

Kevin Towey
Director, Security GRCP
Vimeo

“Oleria allows our business to focus on driving revenue, and less on checking compliance boxes.”

Kevin Towey
Director, Security GRCP
Vimeo