
Summary: The identity provider is the highest-stakes surface in any enterprise identity environment — a compromised Okta Super Admin or Entra ID Global Administrator can rewrite policy, modify MFA, and grant access to anything. Oleria Trustfusion, an AI-native identity security platform, brings identity provider admin review into the standard governance program with Group Membership campaigns scoped to IdP groups — using the same three-signal evidence engine that powers every other Oleria review.
Review who controls your identity provider — the keys to every other system.
Group Membership campaigns scoped to your IdP groups. Same three-signal engine, Dormant Days, Peer Group, HR Changes applied to the highest-stakes identities. Sliceable further by group type & utilization.
IdP access is the highest-stakes identity surface. A Global Admin in Entra can create accounts, change MFA, modify federation, grant themselves access to anything. An Okta Super Admin can rewrite policy. Native IdP review tooling exists but typically runs as a one-time export at quarter-end. By then, three months of admin grants, removes, and re-grants have happened.
Most environments treat IdP governance as a separate process from regular access reviews — a special spreadsheet, a special meeting, a special escalation path. The result: the highest-leverage population in identity gets the least standardized review treatment.

Decisions execute against the IdP. Access removed cleanly; downstream access cleaned up across connected apps. Audit trail captures the path of every removal.
Dormant Days (days since last login), Peer Group match (against other admins of the same tier), HR Changes — applied to admins the same way as every other identity. Okta and Entra both expose login telemetry, so the dormancy signal is fully available for cloud IdP admin reviews.
The same three-signal engine that powers every Oleria review applies to IdP reviews. Recommendations are conservative; the architect makes the call.
IdP group reviews on a regular cadence Achieved
Inactive IdP group users surfaced Continuously via dormancy signal
IdP user sprawl Bounded
Audit findings on IdP groups governance Eliminated

Entra ID Global Admins and Okta Super Admins are the most-leveraged identities in your environment — yet most organizations review them on spreadsheets, quarterly at best. Oleria makes IdP admin review a continuous, evidence-driven control. See how.
AD group reviews live on D-17 (Active Directory Group Membership campaigns). AD does not expose dormancy at the access-review layer, so AD group reviews use peer match + HR change plus AD-specific group context (description, owner) pulled at campaign setup. Oleria's access graph unifies AD and cloud IdP visibility; the review feature splits by directory type.
Each user appears as a line with three-signal evidence — dormant days (days since last login), peer match, HR change for the specific group in review. Reviewer assesses; bulk-accept the matches, examines outliers with an override per line. Removal flows back to the IdP and downstream apps.
Configurable per IdP based on group type, utilization and total users.