Meet us at secIT digital on September 29 + 30

Read the article
Start for free now

Solution · Identity Security & Governance

Manage and protect identities intelligently.

Bring identities, roles and access rights into alignment. migRaven.MAX combines Identity Management (IDM), Identity and Access Management (IAM) and Governance: You create clear roles, control entry, change and exit, and keep permissions aligned with the task at hand. Max AI supports your decisions based on your existing environment.

Faster time to productivity

Prepare and provision accounts and matching access for new entries.

Fewer access risks

Identify unnecessary permissions and withdraw them in a targeted way during changes or exits.

Noticeably relieve IT

Standardize recurring tasks and involve business owners.

Trace decisions

Document reasons, approvals and results in context.

The problem

People, accounts and permissions grow apart

New tasks bring new permissions. Without clear rules, previous access remains in place – distributed across local systems, cloud services and applications.

Permissions keep growing.

At entry, existing accounts are copied as a template. After a change, old groups and access remain.

Accounts are left behind.

One person uses several accounts and applications. Deactivation in Active Directory does not automatically complete the entire exit process.

Responsibility is unclear.

Who decides on an access right? Who takes over groups, resources or the management of external guests?

Coordination takes time.

Tickets, emails and individual scripts distribute tasks across several teams. The overall status and the reasons for changes are difficult to trace.
The solution with migRaven.MAX

Managing identities, access and responsibility together

migRaven.MAX combines the view of existing accounts and permissions with their management. This creates a continuous process from analysis through role assignment to regular review – across systems for Active Directory and file servers, Entra ID and Microsoft 365, as well as connected applications.

Identity & Data Security
Zero Trust active

0Tage

Time-to-Value

12.480

Identities

0%

davon NHI

IdentitiesZugriffspfadData

M. Weber

Marketing

Agentur Nord

Extern

svc-backup01

NHI · Dienstkonto

api-crm-sync

NHI · Token

FS · Marketing

Data class verified

Schreiben

SharePoint · Kampagnen

Data class verified

Lesen

FS · Finanzen

Data class verified

Verweigert

CRM · Kontakte

Data class verified

Lesen
AI-supported role and persona mining0 %
Marketing-RedaktionVertrieb-InnendienstHR-PayrollIT-Betrieb
  • Manage identities

    Assign accounts to a person, create, change, pause and deactivate them according to defined specifications.

  • Assign access appropriately

    Use role profiles for basic needs and have specific permissions managed by the responsible business units.

  • Maintain control permanently

    Review and approve changes, define responsibilities and regularly review permissions.

Transparency and role models

Develop clear roles from grown permissions

A sound identity and access management starts with your existing environment. migRaven.MAX combines inventory, clean-up and role mining. This allows you to develop professionally reviewed role profiles from grown permissions – as a basis for reliable management and the automation of recurring tasks.

  • 1 · Zusammenhänge verstehen

    View accounts, groups, roles and resources together. Make direct and indirect permission paths as well as linked accounts visible.

  • 2 · Altlasten bereinigen

    Resolve unnecessary memberships, orphaned groups and unclear responsibilities before they are carried over into new processes.

  • 3 · Rollenprofile ableiten

    Use Role Mining to analyze existing group memberships and derive role profiles for business review.

  • 4 · Vorgaben anwenden

    Personas define policies for account types. Role profiles control matching group memberships; multiple profiles map cross-functional tasks.

Rollenmodell · Vertrieb Innendienst27 Konten analysiert

0

Konten betrachtet

0

Altlasten bereinigt

0

Rollenprofile

Role Mining · gemeinsame Mitgliedschaften
G_Vertrieb_RW0 %
G_CRM_User0 %
G_Angebote_RO0 %
G_Marketing_RO23 %
Schwelle 80 % · darunter Einzelfall statt Rolle
Persona „Innendienst“ → Rollenprofile
Vertrieb-Basis3 Gruppen
CRM-Nutzer2 Gruppen · 1 Lizenz
Projektleitung+2 Gruppenzusätzlich
3 verwaiste Gruppen entfernt
11 überflüssige Mitgliedschaften entzogen
Vorschlag: 3 Gruppen → Rollenprofil „Vertrieb Innendienst“fachliche Prüfung offen
Identity Lifecycle

Create a reliable process for every change

Five process templates connect the necessary steps. Dates, transition periods and approvals ensure that changes remain plannable.

  • Eintritt · passend ausgestattet starten

    Prepare accounts and activate them on the start date. Persona and role profiles define which base groups and access are needed. A duplicate check helps identify existing accounts.

  • Wechsel · Rechte und Verantwortung anpassen

    Provide new permissions in case of a task, department or location change. The responsible owners review which existing access and responsibilities remain appropriate. Permissions no longer needed are withdrawn after a defined transition period.

  • Beförderung · privilegierte Zugriffe prüfen

    Grant extended permissions deliberately. New privileged access goes through four-eyes approval; transition periods take the ongoing handover into account.

  • Pausieren · Abwesenheit und Rückkehr sicher steuern

    Deactivate accounts in a controlled manner during extended absence, such as parental leave or sabbatical. Depending on the defined procedure, permissions are additionally withdrawn. Before reactivation, those responsible check whether access and responsibilities still match the current task.

  • Austritt · Zugriffe beenden und Verantwortung übergeben

    Take linked accounts, groups, licenses and approvals into account together. Successors confirm the takeover of responsibilities – including for managed guest accounts. Unresolved handovers remain visible. Automated actions and tasks requiring confirmation are tracked within the same process.

Identity Lifecycle · Prozessvorlagen5 Vorlagen aktiv
Eintritt· M. Weberaktiv ab 01.11.

Persona Vertrieb Innendienst · 3 Basisgruppen · Duplikatsprüfung ohne Treffer

Wechsel· Vertrieb → Marketingrunning

Neue Rechte bereitgestellt · Owner-Prüfung 2 offen · Übergangszeit 14 Tage

Beförderung· TeamleitungFreigabe offen

Admins-Marketing (privilegiert) · Vier-Augen-Freigabe 1 / 2

Pausieren· Elternzeitbis 30.04.

Konto deaktiviert · Lizenz entzogen · Prüfung vor Reaktivierung geplant

Austritt· S. Keller1 Auftrag überfällig

11 Gruppen entfernt · Ownership übergeben · CRM-Auftrag an App-Owner

Termine, Übergangszeiten und Freigaben sind je Vorlage festgelegt
Access Management in daily operations

Let access decisions be made where the need is known

Role profiles cover the basic requirements. For project-specific and changing access, data owners and group owners make the business decisions within defined rules. Ownership means business responsibility – being assigned as a data owner does not automatically grant access to the files.

  • Verantwortliche benennen

    Assign responsible persons to data areas, groups and external guest accounts. This makes clear who assesses need and further use.

  • Self-Service ermöglichen

    Manage permissions and create directories and teams based on defined templates. Responsibilities and policies accompany the usage.

  • Zugriffe regelmäßig überprüfen

    Business owners check whether permissions and guest accounts are still needed. Decisions are recorded in a traceable manner.

Owner-PortalOwnership-Abdeckung 87 %
Verantwortliche
FS · VertriebT. Schulz
Teams · Projekt AlphaM. Weber
Gast · agentur-nordS. Keller
SharePoint · Kampagnenohne Owner
Offene Anfragen · Self-Service
Zugriff FS · Vertrieb (Lesen)J. Krause
FreigebenAblehnenLaufzeit 12 Mon.
Team „Kampagne Q1“ aus Vorlageangelegt
Gastzugang agentur-nord verlängernoffen
Rezertifizierung
SharePoint · salesfällig in 9 Tagen
Fileserver · HRrezertifiziert
Owner beurteilen Bedarf — kein Dateizugriff durch die Zuordnung
Controlled Changes

Understand impact. Approve changes. Review results.

Before execution, it becomes visible which systems, accounts and permissions are affected. Decisions and technical implementation remain connected in a traceable process.

  • 1 · Vorschau und Begründung

    Review planned access grants and withdrawals, take indirect effects into account and document the reason for the change.

  • 2 · Freigabe und Ausführung

    Confirm changes via the designated approval process and execute them on schedule through the central action queue.

  • 3 · Vollständig abschließen und nachweisen

    Track technical steps and open tasks. A process is only complete once the required decisions, handovers, and manual tasks have also been completed. Reasons, approvals, and results remain traceable.

Änderung #4711 · Wechsel Vertrieb → MarketingVorschau

0+

Zugänge

0−

Entzug

0

Systeme

0

indirekt betroffen

1Vorschau & Begründung
dokumentiert
2Freigabe (4-Augen)
1 / 2
3Ausführung
15.11. · 08:00
4Abschluss & Nachweis
1 Aufgabe offen
Indirekt: G_Vertrieb_Alle → 1 Share, 1 Postfach
Owner FS · Marketingfreigegeben
Begründung: Abteilungswechsel, HR vom 02.11.
IT-Betrieb (zweite Freigabe)ausstehend
Technische Schritte 5 / 5 · Übergaben 1 / 1
Manuell: CRM-Rolle durch App-Owneroffen
Vorgang gilt erst nach der letzten Aufgabe als abgeschlossen — Protokoll bleibt
Max AI in identity management

Support based on your actual environment

Max AI helps you understand your existing environment, prepare role models, and plan the introduction of your identity and access management. In day-to-day operations, Max AI supports tasks and decisions. Technical review and approval remain with the responsible parties. You determine the approved AI provider and the usable models; changes remain bound to the designated permissions and approvals.

Understanding the starting situation

Explain recorded identities, access, and relationships. Identify anomalies and data gaps and point out the next review steps.

max-ai-identity-ausgangslage

Preparing role models

Explain results from analysis and role mining and support the technical evaluation of potential role profiles.

max-ai-identity-rollenmodelle

Planning the introduction

Organize goals, dependencies, and integration steps. Prepare a suitable initial process scope and make open decisions visible.

max-ai-identity-einfuehrung

Supporting day-to-day operations

Explain tasks and error messages in an understandable way, improve justifications, and provide support for the next steps.

max-ai-identity-alltag
Integration and introduction

Connecting to existing systems and processes

Start with transparency and organized structures. Then standardize the most important processes and expand them to suit your environment.

  • Vorhandene Grundlagen nutzen

    Connect Microsoft systems and analyze existing accounts and permissions. HR data imports, interfaces, and existing scripts can be integrated as needed.

  • SaaS-Anwendungen in den Prozess einbinden

    For SaaS applications, the responsible application owners receive specific assignments and confirm their implementation. Open and overdue tasks are tracked. This way, access outside the directly connected systems also remains part of your identity and access management.

  • Einführung mit klarer Reihenfolge

    Offboarding stabilisieren · Benutzeranlage standardisieren · Rollenwechsel auf geprüfter Grundlage automatisieren.

Anbindung & Einführung5 Quellen · Sync 5 Min.
Angebundene Systeme
Active Directory12.480 Konten
Entra ID / Microsoft 365Gruppen, Lizenzen
Fileserver3 Server
HR-Import (CSV)täglich 06:00
Skript set-mailbox.ps1eingebunden
Aufträge an Applikations-Owner (SaaS)
CRM · Zugang sperrenoverdue
DATEV · Rolle anpassenbestätigt
Einführungsplan · Phase 1 von 3
1Offboarding stabilisierenabgeschlossen
2Benutzeranlage standardisierenin Vorbereitung
3Rollenwechsel automatisierengeplant
2 offene Entscheidungen: HR-Import, Übergangszeit
Bestehende Konten, Skripte und Prozesse werden eingebunden, nicht ersetzt
Ongoing governance

Checking whether permissions still fit

Identity management remains an ongoing task. Regular reviews, documented changes, and comparable metrics help maintain the order achieved.

  • Abweichungen erkennen

    Regularly check accounts and their assignment against defined requirements and make the need for action visible.

  • Verantwortung nachhalten

    Integrate ownership and recertification into operations. Also take guests and transferred responsibilities into account.

  • Fortschritt belegen

    Track the development of account hygiene, risks and ownership coverage based on key metrics and change history.

Governance-Cockpit12 Monate

0%

Kontenhygiene · +8

0

Risiko-Score · −11

0%

Ownership · +22

Abweichungen · Prüfung wöchentlich
3 Konten ohne Personaneu
1 Gastkonto ohne Ownerneu
2 Gruppen außerhalb der Rollenprofileoffen
Berechtigungen am System vorbei0
Ownership & Rezertifizierung je Quelle
Active Directory0 %
Fileserver0 %
SharePoint0 %
Gastkonten0 %
Nächste Rezertifizierung: SharePoint · Vertrieb in 9 Tagen — Änderungshistorie lückenlos

Frequently asked questions
on identity and access management

Quick answers on roles, processes and approvals. Anything still open is clarified directly by ourteam– without detours.

Get in touch