Skip to main content

← Back to glossary

Term · 3. Account Management & Provisioning

Provisioning Prov

IDM/IGA Domain

Definition

Process of creating, updating, and disabling accounts and access in target systems based on identity lifecycle events. Manual provisioning (admin tickets) vs automated provisioning (connector-driven, event-triggered). Goal: reduce lag between identity event (hire, role change, termination) and downstream system access reflecting that event.

Application
SailPoint: Provisioning Engine — automated CRUD operations on target Applications via connectors
Standards & regulations
  • NIST SP 1800-2B «Provisioning connects the administrative activities to the run-time activities by providing the run-time capabilities with the information needed from the administrative activity to make runtime decis»
  • NIST SP 800-63B «When any new authenticator is bound to a subscriber account, the CSP SHALL ensure that the binding protocol and the protocol for provisioning and deprovisioning subscriber authenticators are protected»
  • OASIS IDCloud-paas-v1.0 «Provisioning Services: are responsible to manage the lifecycle of Identity Objects such as Users, Roles, Groups, Attributes and other objects involved in defining an identity for an entity. The manage»
Sources