What teams run on Identity Mesh

Nine situations we see in most estates, what the platform does about each one, and the features doing the work. Every one runs on the same install, the same connectors, and the same audit chain.

01HR and IT operations

Joiner, mover, leaver from the HR system of record

The situation

New hires wait days for an account. Transfers keep old group memberships. Leavers keep working credentials because the HR change never reached the directory.

With Identity Mesh

Import from Workday, a SQL HR database, or a file feed, then flow employees into Active Directory and Entra ID with transform rules for usernames, OUs, and group assignment. Delta sync picks up only what changed. A leaver's precondition failing disables or deletes the target account on the next run.

02Application owners

Keep line-of-business databases in step with the directory

The situation

A dozen applications hold their own user tables. Each one drifts from Active Directory, and nobody is sure which copy of a phone number or manager is right.

With Identity Mesh

Bidirectional SQL and Active Directory connectors with confidence-based attribute resolution decide which source wins per attribute. Watermark-based delta import on both sides keeps sync cycles short, and export preview shows what the engine would write before it writes it.

03Identity teams in hybrid tenants

Govern groups across Active Directory and Entra ID

The situation

Groups exist twice, once on-premises and once in the cloud. Owners are tracked in a spreadsheet. Nobody can say who approved a membership or when a group should have been retired.

With Identity Mesh

Build groups from criteria with MeshComposer or let owners run them through self-service. Either way the mesh holds membership and ownership, and the Entra connector creates the cloud group and flows its owners and members through Microsoft Graph. Expiry empties the directory group on schedule.

04Service desk and group owners

Take group requests off the service desk queue

The situation

Every access request becomes a ticket. The service desk adds people to groups it does not understand, and high-impact groups get the same treatment as a mailing list.

With Identity Mesh

Users browse joinable groups and request membership in the portal. Open groups add them at once. Owner-approval groups notify the owners. High-impact groups require a second decision from an administrator, and the requester can never approve their own request.

05Security and infrastructure

Vault privileged accounts without a second PAM product

The situation

Service accounts and break-glass admins share passwords that were set years ago. The PAM renewal quote asks for a vault appliance, a rotation module, and a dedicated administrator.

With Identity Mesh

Nominate an account into Identity Mesh Vault with its current credential, or blind-rotate it so nobody knows the old one. Checkouts are approved, revealed strictly once, and rotated on check-in, on expiry, on demand, or on a policy schedule. Access is granted by mesh group membership, and every event joins the tamper-evident audit chain.

06MIM and FIM customers

Retire Microsoft Identity Manager one agent at a time

The situation

MIM runs the estate, the people who built it have moved on, and the only way to know what is in 28 management agents is to open 29 XML files.

With Identity Mesh

Run the analyzer on the Sync Engine export. It gives a verdict with reasons, proposes connectors and flows with evidence, and saves the plan as a migration project in the Admin Portal. Bring connectors up in staging mode and decommission MIM agents one at a time.

07Architects during mergers and acquisitions

Consolidate identities across forests and tenants

The situation

Two companies, three forests, duplicate people, and a deadline to present one directory to the business.

With Identity Mesh

One Active Directory connector spans every partition of a forest, so cross-domain group members resolve inside it. Anchor-based join rules match the same person across sources, uniqueness re-resolution and orphan cleanup deal with the duplicates, and projection templates apply the same export rules to each new source.

08Compliance, risk, and audit

Produce evidence auditors can verify

The situation

The auditor asks who changed a manager attribute in March, who approved a group join, and whether the log could have been edited afterwards.

With Identity Mesh

Every identity, admin, group, and vault event is written to append-only, hash-chained audit tables with before and after values, verified from the UI. Events stream to your SIEM over syslog, CEF, LEEF, webhook, or Sentinel. Data-subject requests are handled with erasure that preserves the chain.

09Developers

Connect the system nobody else has a connector for

The situation

The badge system, the lab LDAP, the mainframe extract. Every estate has a source that matters and that no vendor ships a connector for.

With Identity Mesh

Build it on the Connector SDK. The SDK packages the connector contract, retry and change-ordering helpers, composite keys, watermarks, and export routing, with a Visual Studio sample solution to start from. Custom connectors load beside the bundled ones and get the same test-connection, discovery, and relay support.

Have a situation that is not on this list?

Tell us what you are connecting and what has to be true afterwards. We will say plainly whether Identity Mesh does it today.