Practitioner's guide to the future of identity — new maturity model
Access the guide

A Fortune 100 telecommunications provider maps hidden access across 250,000+ cloud accounts

One top-level group expanded into 160+ nested subgroups. Oleria mapped every inherited access path across Entra ID, SharePoint, and Salesforce, helped the provider remediate access for 34,000+ disabled users, and automated cleanup of 118,000+ empty groups.

Watch video

51,000+

Non-human identities

Inventoried across Entra ID, SharePoint Online, and Salesforce

34,176

Disabled users

Group memberships that outlived employment, remediated

118,990

Empty groups

Retired through automated cleanup

Industry

Telecommunications

Use Cases

NHI governance

Nested group access security

Usage-aware access reviews

Size

50,000+ employees,

251,000+ active accounts

About the organization

The company delivers 5G wireless, broadband, and enterprise connectivity across the United States. Tens of thousands of employees and contractors support its network, customer service, and retail operations. Its workloads span regulated environments governed by FCC, CPNI, SOX, and PCI DSS requirements.

The challenge

At this scale, native directory tools present a flat view of groups that run many layers deep. The true reach of a single group assignment was hard to see, and activity volume made it difficult to separate routine events from ones that mattered.

  • Nested group reach. In Entra ID, one top-level group expanded into more than 160 nested subgroups, each granting inherited access to sensitive systems.
  • Access that outlived employment. 34,176 disabled users still held group memberships, and 30,104 disabled users kept access paths to enterprise SaaS applications.
  • Group and ownership sprawl. The directory held 118,990 empty groups, and 625,275 SharePoint resources had no assigned internal owner, which slowed certifications.
  • External sharing. More than 22,000 assets were shared externally, including documents labeled confidential, with 29,500+ guest accounts active.
  • Signal volume. 511 million monthly activity events and 80 million failed logins made it hard to isolate the events that needed attention.

"Oleria gives us visibility into our multi-cloud environment that we did not have before, revealing nested group relationships and non-human identity risks that were previously invisible. Combining activity intelligence with permission mapping lets us secure sensitive data and run access reviews at enterprise scale."

Senior Director, Enterprise Identity and Access Management, Fortune 100 telecommunications provider

“People are really, really good at sharing things — but not so good at revoking those privileges once they’re no longer needed.”

Peter Clay
CISO, Aireon

The solution

Oleria connected natively to the provider's Entra ID, SharePoint Online, and Salesforce environments to build a central Access Knowledge Graph. The platform expands nested groups to map exact access paths, correlates identities with live usage, and runs continuous posture checks across millions of resources.

  • Nested group graphing expands and visualizes multi-tier hierarchies, exposing inherited access across hundreds of thousands of accounts and service credentials.
  • Usage-aware access reviews show managers actual usage and identity status, with one-click revocation in place of IT tickets.
  • Sensitivity-label sharing controls flag and revoke unauthorized external sharing of internal and confidential assets.
  • Activity correlation processes 511 million monthly events with geolocation data and highlights anomalies such as login spikes and application impersonation.
  • Non-human identity lifecycle tracking brings service accounts, API tokens, and integration pipelines under continuous oversight.

Business outcomes

The provider now governs access with a complete map of who can reach what, and how.

  • Offboarding gaps closed. Lingering SaaS access was revoked for 30,104 disabled accounts, and group access was remediated for 34,176.
  • Group sprawl reduced. Automated cleanup retired 118,990 empty groups, removing directory clutter that complicated every review.
  • Faster investigations. Correlated telemetry cut incident investigation time from days to minutes.
  • Audit-ready evidence. Usage-backed access evidence supports continuous readiness for FCC CPNI, SOX, and PCI DSS requirements.

Key takeaways

  • Nested groups hide real access, and expanding them is the first step to governing it.
  • Disabled accounts with live group or SaaS access are the most direct leaver risk to close.
  • Correlating activity with permissions turns billions of log events into a short list of actions.

“If you ask any CISO, ‘How many files have you shared outside the company?'. . . most don't have answers — or they don’t have easy ways to answer those questions. In Oleria, I can answer those questions with a click.”

Mark Carter
CIO and CISO
Vimeo

“Having visibility and the ability to remove that share or that file access...is a real differentiator.”

Kevin Towey
Director, Security GRCP
Vimeo

“Oleria allows our business to focus on driving revenue, and less on checking compliance boxes.”

Kevin Towey
Director, Security GRCP
Vimeo