Term · 3. Account Management & Provisioning
Provisioning Prov
Definition
Process of creating, updating, and disabling accounts and access in target systems based on identity lifecycle events. Manual provisioning (admin tickets) vs automated provisioning (connector-driven, event-triggered). Goal: reduce lag between identity event (hire, role change, termination) and downstream system access reflecting that event.
- Application
- SailPoint: Provisioning Engine — automated CRUD operations on target Applications via connectors
- Standards & regulations
-
- NIST SP 1800-2B «Provisioning connects the administrative activities to the run-time activities by providing the run-time capabilities with the information needed from the administrative activity to make runtime decis»
- NIST SP 800-63B «When any new authenticator is bound to a subscriber account, the CSP SHALL ensure that the binding protocol and the protocol for provisioning and deprovisioning subscriber authenticators are protected»
- OASIS IDCloud-paas-v1.0 «Provisioning Services: are responsible to manage the lifecycle of Identity Objects such as Users, Roles, Groups, Attributes and other objects involved in defining an identity for an entity. The manage»
- Sources
-
- NIST SP 1800-2 (csrc.nist.gov) primary source
Related terms
-
Delegated Administration (DA)
Permission model where administrators delegate specific management functions to other users within scoped boundaries — t …
-
Deprovisioning (Deprov)
Removal of an identity's access from a target system — typically triggered by termination (Leaver), role change (Mover), …
-
Joiner-Mover-Leaver (JML)
Standard workforce identity lifecycle pattern: Joiner (new hire onboarding — create accounts, assign baseline access), M …
-
Password Synchronization (PS)
Pattern where users have the same password across multiple systems, synchronized when changed in any one. Reduces passwo …
-
Role Assignment (RA)
Specific instance of assigning a role to an identity — captures who, when, why, with what expiration. Direct (manually r …
-
Role Management
Operational discipline of maintaining the role catalog — creating new roles, modifying existing roles, retiring obsolete …