People who left, still with access
Your source of truth marks them terminated or suspended, but an application or group still grants access. Reported as critical.
Access reconciliation · Sutura Suite
Sutura Drift compares who should have access, from Sutura, your IGA or HR, with what Microsoft Entra ID and your applications actually grant. Every night. It reports what never landed, what was granted outside the process, and who left but still has access.
Self-hosted · Read-only connections · Your data stays with you
Reads from the systems you already run
A request is approved but the group change fails. An admin adds a colleague by hand "just for today". Someone leaves, and one application keeps their account. Each gap is invisible until an auditor or an attacker finds it. Drift finds it first, every night, and shows the gap closing when it is fixed.
What it finds
Your source of truth marks them terminated or suspended, but an application or group still grants access. Reported as critical.
Accounts and group memberships nobody approved. Risk rises with the entitlement: an orphan administrator ranks above an orphan viewer.
Access your access system approved that never reached the application, including groups that are still empty. People are blocked, and the record says otherwise.
How it works
Read-only connectors pull expected access (Sutura, an IGA, HR) and actual access (Entra ID, SCIM applications, any JSON API). Credentials are encrypted.
A scheduled scan matches people, applications and entitlements, using each application's risk settings. A broken pull is held for review, never scanned.
Findings become remediation tasks with owners, due dates and email reminders, or ServiceNow tickets. Drift never changes access itself.
The next scan marks fixed findings resolved. Every step is in a tamper-evident audit trail, ready for the auditor.
With Sutura, or on its own
Sutura decides who should have access. Drift checks that it really happened, reading the applications directly, not through Sutura. If you use another access system, Drift checks that one instead.
Live demo
The live demo compares the Sutura demo with a real Microsoft Entra ID tenant every night, so the findings it shows are real. Ask us for a demo account to sign in.
FAQ
No. Drift can take expected access from Sutura, from an IGA export (SailPoint, Saviynt), from HR, or from a CSV file. With Sutura, the two connect with a read-only token.
Read-only ones: for Microsoft Entra ID, reading users, group members and application assignments. Drift cannot change access anywhere.
Containers with PostgreSQL on one server (optional automatic HTTPS), Kubernetes with the Helm chart, or AWS ECS. Migrations run automatically on upgrade.
Get in touch and we'll walk you through options, on its own or with Sutura.
See Drift with your own directory in a 30-day pilot.