The organisation’s identity estate was fragmented across its three institutions, with a hybrid Microsoft architecture and only partial single sign-on adoption. The legacy One Identity Manager platform was out of support, with manual provisioning and inconsistent joiner, mover, and leaver processes, creating an end-of-life risk that required urgent remediation.
A dual MFA model using Microsoft Authenticator and DUO introduced operational complexity, with inconsistent enforcement and variable user experience across applications. Oracle PeopleSoft, including HRMS, SIS, and FSCM, remained outside modern authentication coverage along with other LDAP-based applications and could not natively integrate with Microsoft Entra ID without code changes. There was also no unified identity governance in place, with limited Conditional Access, no Privileged Identity Management, and no automated Access Reviews.