Identity and access management services in India are usually bought as a single sign-on project and then quietly abandoned once the login page works. The login page was never the hard part. The hard part is knowing who can reach what, why they still can, and what happens to that access the day they leave.
Every organisation accumulates the same debt: accounts belonging to people who left, service accounts nobody will admit to owning, administrators who were granted rights for one project in 2022, and a set of standing privileges that would each be refused if requested today. That accumulation is what turns a single compromised workstation into a domain-wide incident.
We work the whole discipline (governance and lifecycle, privileged access, and customer identity) with a bias toward removing standing access rather than monitoring it. Where the estate is Active Directory, the attack paths are demonstrable; see VAPT. Where it is cloud, permissions compose in ways nobody reads; see cloud security testing.