We recently migrated from our on-premises Active Directory to Microsoft Entra ID, and the migration itself went really well. Now that everything is up and running, we're taking the opportunity to rethink how we handle application access requests and user lifecycle changes. Rather than simply continuing with our existing process, we're interested in learning how other organizations have approached this after making a similar move.
One area we're particularly looking to improve is reducing the amount of manual work involved for our IT team. It would be great if access requests could automatically reach the appropriate application owner or IT administrator for approval, and once approved, have that approval trigger the rest of the provisioning process. Ideally, application access, group memberships, role assignments, and lifecycle events like onboarding, department transfers, role changes, and offboarding would all happen automatically, while still maintaining a complete audit trail and keeping everything easy to manage.
I'm curious to know what has worked well for others. Are you using Microsoft Entra ID's native approval and lifecycle capabilities, or have you implemented an Identity Governance & Administration (IGA) solution? We'd love to hear what approach you've taken, what challenges you've encountered, and any lessons learned that you'd recommend to teams designing a similar process today.