squirrelworks

Systems Architecture > Identity & Access Management

Automating Enterprise IAM Lifecycles & Dynamic RBAC via PowerShell Engine

Manual account provisioning creates security risks, stale permissions, and offboarding delays. Here is how we engineered an autonomous, database-driven Joiner/Mover/Leaver (JML) synchronization engine using PowerShell, SQLite, and Active Directory on server APP1 to enforce role-based access control and export execution audit logs.

JML Automation Dynamic RBAC SQLite Audit Engine
Task Scheduler executing HR_Identity_Sync on APP1

1. JML Identity Lifecycle Automation Mechanics

The synchronization script Invoke-HRIdentitySync.ps1 runs on host APP1, querying an authoritative HR database (hr_system.db) to evaluate employee record states against Active Directory (DC1).

Lifecycle Trigger HR Database State Automated Active Directory Action
JOINER status = 'Active' (New record) Provisions AD object in OU=Employees,OU=SW, sets UPN/Title/Dept, and assigns default VPN/Dept groups.
MOVER status = 'Transferred' Updates Title and Department attributes via Set-ADUser, revokes stale department groups, and assigns target role groups.
LEAVER status = 'Terminated' Strips non-primary security groups, disables account, and relocates object to OU=Disabled_Users,OU=SW.
Active Directory Container Topology
Active Directory Users and Computers showing SW OUs

OU structure on DC1 isolating active accounts in OU=Employees and offboarded accounts in OU=Disabled_Users.

Live Attribute Mapping Verification
Elena Rostova Properties window in ADUC showing updated Organization tab

Updated Organization tab for Elena Rostova (erostova) confirming automated Title and Department property synchronization.

2. Dynamic Role-Based Access Control (RBAC)

Instead of managing individual user access manually, group memberships are calculated dynamically during every execution loop using hashtable mapping structures.

Department Hash Mapping

Maps HR database department strings directly to Active Directory global security groups:

"Information Technology" => "SG_IT_Dept"
"Cybersecurity" => "SG_Cybersecurity_Dept"

Role-Based Step-Up Entitlements

Evaluates wildcard job title matches to grant specialized operational roles:

If job_title -like "*SOC Analyst*", user is added to SG_SOC_Analysts.

3. PowerShell Automation Engine Code Structure

Below is the core execution logic used within Invoke-HRIdentitySync.ps1 to query SQLite, drive AD object state transitions, strip memberships upon termination, and log events.

# Hash Table for Department Mapping
$deptGroupMap = @{ "Information Technology" = "SG_IT_Dept"; "Cybersecurity" = "SG_Cybersecurity_Dept" }

# Query HR Database Employees
$employees = Invoke-SqliteQuery -Database $dbPath -Query "SELECT * FROM employees"

foreach ($emp in $employees) {
    $upn = $emp.user_principal_name
    $samName = $upn.Split('@')[0]
    $adUser = Get-ADUser -Filter "UserPrincipalName -eq '$upn'" -ErrorAction SilentlyContinue

    # LEAVER STATE: Strip access, disable, move to disabled OU
    if ($emp.status -eq 'Terminated' -and $adUser) {
        $userGroups = Get-ADPrincipalGroupMembership -Identity $adUser -Server DC1 | Where-Object { $_.Name -ne 'Domain Users' }
        if ($userGroups) { Remove-ADPrincipalGroupMembership -Identity $adUser -MemberOf $userGroups -Confirm:$false -Server DC1 }
        Disable-ADAccount -Identity $adUser -Server DC1
        Move-ADObject -Identity $adUser.DistinguishedName -TargetPath $disabledOU -Server DC1
    }
}
PowerShell Execution Console & Dynamic Group Membership Output
PowerShell execution console output showing active users and assigned RBAC groups

Live console verification showing dynamic role grants: mvance granted SG_IT_Dept, SG_VPN_Users; erostova granted SG_Cybersecurity_Dept, SG_SOC_Analysts.

4. Operational Auditing & Automated HTML Reporting

Every execution step writes a structured audit record into the SQLite database table jml_sync_log. At the end of each run, the engine automatically compiles recent events into a clean HTML dashboard for operational monitoring.

Generated Operational Audit Report — Latest_Sync_Report.html
Browser view of Latest_Sync_Report.html execution log table
Tech Fact Icon
Compliance & Auditability Takeaway

Maintaining decoupled audit tables (jml_sync_log) ensures complete traceability across all identity modifications, giving SOC analysts and auditors immediate visibility into automated privileged access changes.



Accessibility
 --overview

API
 --REST best practices
 --REST demo
 --REST vs RPC
 --Wikipedia API

Blockchain
 --overview

Blog
 --The 'Brute Force' Mistake
 --The Bezosian Protocol: Eliminating Learned Helplessness
 --The Humility Protocol: Reality Over Reputation
 --The Jobsian Protocol: Systems Analysis as a War on Entropy
 --The Jordan Framework: Engineering a Competitive Edge
 --Time Management as an Operational System: The Tracy Framework
 --Tracy on Goals: Vector Alignment & Execution

Cloud
 --AWS overview

CSS/HTML
 --Admissions Portal Simulation Lab
 --Bootstrap carousel
 --Grid demo
 --markdown demo

DevOps
 --Agile Principles
 --DevOps overview
 --Drupal, containerized
 --Prometheus & Grafana
 --RKE2: Deploying the Rancher Kubernetes Engine

Encoding
 --Overview

Ergonomics
 --Desk configuration
 --Device fleet
 --Input device array
 --keystroke mechanics
 --Phones & RSI

ERP
 --Anthology overview
 --Ellucian Banner
 --Higher Ed ERP Simulation Lab
 --PeopleSoft Campus Solutions
 --PESC standards
 --Slate data model

Git
 --Authoring & Deploying the Post-Receive Hook
 --Pipeline Optimization, Web-Root Migration, & Dependency Remediation
 --syntax overview
 --troubleshooting libcrypto

Hardware
 --Device fleet
 --Electricity fundamentals
 --Homelab diagram

Identity & Access
 --Automating Enterprise IAM Lifecycles
 --Deploying Entra Connect
 --Foundations
 --OIDC Integration
 --Provisioning Okta Dev Tenant

Java
 --Fundamentals

Javascript
 --Advanced Interaction: jQuery & UI Frameworks
 --input prompt demo
 --misc demo
 --Time and Date functions
 --Vue demo

Linux
 --Auditing the live interface state using ethtool
 --grep demo
 --HCI and Proxmox
 --Persistent Infrastructure Telemetry: TMUX
 --Proxmox install
 --xammp ftp server

Mail flow
 --DKIM, SPF, DMARC
 --MAPI

Microsoft
 --AZ-800: Administering Windows Server Hybrid Core Infrastructure
 --BAT scripting
 --Group Policy
 --IIS
 --robocopy
 --Server 2022 setup - Virtualbox

Misc
 --Applications
 --Computer Science Foundations
 --Field Notes: RainPoint Bluetooth Hose Timer
 --Protocols, TLS & Distributed Scale
 --regex
 --Resources
 --Runtimes, ASTs & Data Structures
 --Sustainable Computing
 --Terminology
 --Tribute to Computer Scientists

Networks
 --BGP Peering & Security Hardening Lab
 --CCNA Lammle Study Guide
 --Cisco 1921/K9 router
 --NGFW vs. Legacy
 --routing protocols
 --throughput calculations

PHP/SQL
 --Cookies
 --database interaction
 --demo, OSI Layers quiz
 --Foreign key constraint demo
 --fundamentals
 --MySQL and PHPmyAdmin setup
 --pagination
 --security
 --session variables
 --SQL fundamentals
 --structures
 --Tables display

Python
 --fundamentals

Security
 --Kerberos: Protocol Architecture
 --NTP Overview
 --Overview- GRC (Governance, Risk, and Compliance)
 --Security Blog
 --SSH fundamentals

Serialization
 --JSON demo
 --YAML demo