A home services insurance company replaced a separate HR-to-AD sync tool with BalkanID, and moved its quarterly access reviews off the identity provider.
Systems
UKG Pro (HR), on-prem Active Directory (via BalkanID AD agent), Entra ID, Oracle EBS, Salesforce, Freshservice
Drivers
CISO mandate to close the gap between HR terminations and application access; quarterly review evidence
Challenges before BalkanID
- HR attributes (department, title, manager, office) reached AD through a separate sync product that had to be licensed and maintained on its own.
- Disabling a user in the directory did not remove access in downstream applications. In the CISO's words, "that opens up a security risk."
- Onboarding a new hire took days.
- Access reviews ran inside the identity provider, with limited reviewer routing and no coverage for contractors or service accounts.
What they implemented
- AD sync from UKG through the BalkanID AD agent, running every few hours. The previous sync product was switched off.
- Leaver playbook: a termination date in UKG triggers an access removal request with approval.
- Continuous finding for terminated users who still hold group access, with daily alerts.
- Quarterly access reviews with reviewer precedence (manager, then app owner, then risk manager), automatic reassignment, branded emails, and self-review by service account owners.
- A dedicated campaign for contractors with privileged access to cloud apps.
Outcomes
- One platform replaced a standalone AD sync tool, with the cost and maintenance that came with it.
- Terminated employees with lingering cloud group access identified from HR data, and now monitored daily.
- Legacy records cleaned up during onboarding to BalkanID.
- Contractors, service and privileged accounts brought into quarterly reviews for the first time.