User Provisioning
User Provisioning is the automated creation, management and deletion of user accounts in IT systems. New employees automatically receive access to relevant applications, while all permissions are reliably revoked during offboarding.
The starting point is usually a leading system – typically the HR software – whose changes are transferred to target systems such as directory services and SaaS applications via connectors or the open standard SCIM (System for Cross-domain Identity Management). The most critical sub-step is deprovisioning: orphaned accounts of departed employees are among the most common avoidable security gaps, because they keep valid access open unnoticed.
Automated user provisioning ensures consistency, traceability and lower error rates, especially in environments with many applications. As an operational sub-process of the identity lifecycle, it is a core element of Identity and Access Management and a prerequisite for reliable compliance evidence about granted permissions.