
01 / THE CONSTRAINT
What had to be true before changing anything.
A 20+ year old identity estate — Active Directory plus a parallel IBM i user profile store — had never been audited end to end. Accounts accumulate for decades of manufacturing operations, M&A, and staff turnover with no attrition process: nobody was disabling what nobody was using. The actual scale of the problem was unknown because nobody had measured it. Guesses about 'stale accounts' or 'who has admin rights' were opinions, not numbers.
02 / THE WORK
What was changed and why.
Built a read-only identity posture audit against the live directory using a dedicated, least-privilege service account and paged LDAP queries (a naive single-page query silently truncates around 1,000 entries and under-reports a directory this size — worth knowing before trusting any AD report tool). The audit measures privileged group membership, password policy weaknesses, account staleness by last logon, and computer object sprawl versus actually-live hosts, cross-checked against network scan data so 'enabled' and 'real' are two different questions with two different answers.
The same discipline was applied to the IBM i side, auditing user profiles for dormant accounts, excess authority, and default-password exposure directly against QSYS2 system views rather than relying on decades-old assumptions about who has access.
Remediation is intentionally staged and human-gated: findings are surfaced with severity and evidence, then acted on in phases, site-by-site, starting with a pilot, disabling rather than deleting, and keeping a full restore path for every account touched. Nothing is auto-remediated — the tooling's job is to make the decision visible, not to make the decision.
03 / OPERATING RESULT
What became clearer, safer, or easier to run.
• Directory-wide measurement replaced guesswork: privileged group membership, password policy gaps, and stale account counts are now known numbers, not impressions
• Computer object sprawl found running roughly 3-4x the actual live host count — a real attack surface that had no owner and no cleanup cadence
• A large share of enabled service and privileged accounts identified as unnecessary domain-level privilege — remediated via delegation instead of blanket admin rights
• Staged, disable-not-delete remediation process shipped with a pilot phase and full reversibility, so cleanup doesn't become its own outage risk
• Same audit-before-you-touch-it approach extended to the IBM i user profile store, closing the gap between two identity systems that had never been reconciled against each other
Project notes
This case study covers an identity governance initiative across both a Windows/Active Directory environment and a parallel IBM i identity store at a multi-site manufacturing company with domestic and international operations. Specific enterprise identifiers, hostnames, and account names are withheld; the methodology, findings categories, and approximate scale described are accurate and reflect an active, in-progress program rather than a completed one-time audit.