Automation Control Framework

The migration is done. Now the real work begins.

ACF is not an out-of-the-box product. ACF is a flexible framework tailored for Microsoft Enterprise environments — for operational IT management and migrations. It picks up where projects leave off: migrations, carve-ins/-outs, and organisational change.

The reality after the migration

ACF addresses the problems that remain once the project closes.

Identities remain

After migrations and reorganisations, accounts are technically there — but rarely cleanly maintained.

Permissions propagate

Access rights are inherited, accumulated, and forgotten. The risk grows year after year.

Processes no longer scale manually

What was manageable by hand at 100 users becomes a treadmill at 5,000.

Ownership turns fuzzy

Who is the owner? Who reviews? Day-to-day operations let responsibility slip.

Where ACF is used

The pattern is always the same: the tech runs — but it isn't manageable. ACF is deployed when organisations …

… have one or more migrations behind them

M&A, carve-outs, tenant consolidations — the legacy stays behind.

… are running hybrid or multi-tenant setups

Running cloud and on-premises in parallel demands consistent control.

… operate large, organically grown Entra ID / AD

Historically grown structures without clear governance.

… face operational risk or audit pressure

When ISO 9001, internal audits or compliance demand answers.

… can no longer run lifecycle processes manually

Onboarding, offboarding, reviews — no longer feasible by hand.

What ACF does

Seven capability areas — each focused on what operations actually need.

01

User & Identity Lifecycle Management

Establish, operate, and retire identities cleanly.

What

Automation of the entire user lifecycle including license assignment, notifications, and control through defined processes.

Why

After migrations or reorganisations, user accounts are often technically correct but procedurally unclear.

Typical benefit
  • Clean onboarding and offboarding
  • Clear ownership
  • Less or no manual rework

What

Synchronisation of defined attributes from an HR master data system to AD and/or Entra ID, including calculated attributes (e.g. display names, extension attributes).

Why

Identity becomes operationally stable only once HR data is structured and consistently usable.

Typical benefit
  • Consistent identities
  • Fewer special cases
  • Stable foundation for automation

What

Control, review, deactivation and deletion of external identities including sponsor notifications.

Why

B2B accounts are created quickly — and rarely go away on their own. A clearly registered owner is often missing.

Typical benefit
  • Reduced legacy
  • Better security hygiene
  • Audit confidence
02

Group & Permission Management

Keep structures clean without anyone chasing them by hand.

What

Rule-based management of dynamic groups including central rule definition and automatic membership changes.

Why

Manually maintained groups do not scale reliably in large environments.

Typical benefit
  • Reproducible group logic
  • Fewer errors
  • Transparent rules

What

Lifecycle control for Teams, Planner, Yammer, Distribution Lists and Security Groups.

Why

M365 objects are created by business users quickly — governance often arrives too late.

Typical benefit
  • Controlled object landscape
  • Clear ownership
  • Structured decommissioning

What

Automated management of AD groups including bulk changes, delta groups and API integration.

Why

Hybrid environments require consistent control across cloud and on-premises.

Typical benefit
  • Less manual effort
  • Clean transitions
  • Less drift

What

Enforcement of defined owner structures, e.g. at least two owners per group.

Why

Permissions without responsible owners are an operational risk.

Typical benefit
  • Clear accountability
  • Better reviews
  • Fewer forgotten groups

What

Automated reports and self-service actions for owners to clean up groups that are no longer needed.

Why

Cleanup only works when responsibility is made tangible.

Typical benefit
  • Relieves IT
  • Higher business participation
  • Sustainable cleanup
03

Security-Related Automation

Catch silent failure risks early.

What

Automated notifications before password expiry — including sponsor involvement.

Why

Production or rarely used accounts otherwise surface only during incidents.

Typical benefit
  • Fewer unplanned outages
  • Sponsor involvement
  • Early warning for critical accounts

What

Monitoring and notification for expiring secrets in Entra ID App Registrations.

Why

Expired secrets translate directly into service outages.

Typical benefit
  • No surprises
  • Stable API integrations
  • Plannable renewal

What

Automated, secure provisioning of temporary credentials.

Why

Emergency access must be fast — but controlled.

Typical benefit
  • Rapid recovery
  • Controlled process
  • Audit-grade trace
04

Compliance & Governance

Audit-ready structures without spreadsheet rituals.

What

Individually defined access reviews by department, owner or context — including custom reporting and long-term retention of results for audit purposes.

Why

Standard reviews fall short in complex environments. Long-term retention of results for later audits is especially critical.

Typical benefit
  • Context-specific reviews
  • Solid audit trail
  • Long retention

What

Monitoring and control of licenses (E5, F5, Project, Visio, Copilot).

Why

License costs creep in — transparency is often missing.

Typical benefit
  • Cost transparency
  • Targeted cleanup
  • Predictable license footprint

What

Audit-ready reports, e.g. for ISO 9001 or internal audits.

Why

Traceability is at the heart of modern IT governance.

Typical benefit
  • Audit confidence
  • Repeatable reports
  • Solid evidence
05

Certificate & Key Management

Operate security-critical artefacts automatically.

What

Synchronisation of certificates from trust centres into target systems and APIs.

Why

Certificates are security-critical — barely manageable by hand.

Typical benefit
  • Consistent distribution
  • No forgotten rollovers
  • Reduced outage risk

What

Provisioning of public keys for secure email communication.

Why

Encryption often fails on missing operational integration.

Typical benefit
  • Working S/MIME communication
  • No manual key distribution
  • More stable security processes
06

Reporting & Transparency

Solid data for operational decisions.

What

Flexible, context-specific reports on identities, groups, access and usage.

Why

Operational decisions need solid data.

Typical benefit
  • Reliable decision basis
  • Repeatable analytics
  • Adaptable to context

What

Analysis of app usage and sign-ins down to day and user level.

Why

The foundation for chargeback models, cleanup and security analysis.

Typical benefit
  • Clear usage picture
  • Basis for chargeback
  • Security analysis
07

Migration-Related Automation

Where migration projects fail without automation.

What

Analysis and re-ACLing of file shares during carve-outs, mergers or cloud moves.

Why

Permissions are one of the most critical points in file migrations.

Typical benefit
  • Clean ACL handover
  • Reduced migration risk
  • Predictable cutover

ACF doesn't make sure your systems run.

ACF makes sure they stay manageable.

Interested?

Contact us today for more information or to schedule a demo. We look forward to hearing from you!

Microsoft Azure Cognitive Services Icon