Once an organization has procured a quality Identity & Access Management solution, it must clearly understand the Identity & Access Management lifecycle and how it will be applied to its environment. Employees come and go through all businesses, and over time, job roles and requirements change. Digital identities must be regularly monitored and configured to reflect the end user’s current job status. If identity and access management are neglected, issues will quickly arise. Privilege creep results in users obtaining more privileges than they require, effectively derailing the need-to-know and principle of least privilege strategies. Help Desk tickets will likely increase as users become frustrated by their inability to access the proper resources to do their jobs.

Following the Identity & Access Management Lifecycle keeps maintenance and growth of identities and access rights on track. The lifecycle is broken down into the following basic steps:

  1. Create: When new users or services are introduced into the digital environment, accounts are provisioned based upon a granular description of the necessary attributes and rights for the account user. Organizations need to have a thorough overview of their digital platforms and the privileges and permissions available. This clear understanding allows attributes and access rights to be assigned to accounts in a way that reflects the user’s job description.
  2. Enable: Once digital identities are created, they can be assigned to end users and enabled for use in the organization’s environment. Enabling accounts requires collaboration between the end user and the IAM platform for tasks such as password creation and authenticator enrollment. All digital identities need to prove proper security measures before they can be let loose into company resources.
  3. Manage: A critical aspect of identity security that is often overlooked is regular auditing and maintenance of account attributes and rights. Work environments and job descriptions change, and these new developments need to be reflected in digital identities. At a minimum, organizations should perform annual audits on digital identities and review their levels of access to determine if they still reflect the necessities of the end user’s job. If access rights are no longer accurate or need to be changed to reflect environmental developments, the proper IT staff can then modify accounts to bring them up to date. Nowadays, account activity is equivalent to network traffic in terms of how much information is provided on the organization’s security posture. All organizations should look into implementing 24/7 session monitoring capabilities to monitor all account activities. The resulting logs can be ingested into Security Information & Event Management (SIEM) appliances for thorough analysis. Modern digital environments can have automated incident response capabilities created to take immediate action on user accounts when suspicious or forbidden activity is detected.
  4. Exit: Every digital identity will someday become irrelevant and need to be removed from the organization. Retirements, firings, dismissals, and even promotions often require user accounts to be deleted from the organization’s IAM platform. Deprovisioning user accounts needs to happen quickly and smoothly upon authorization by the proper organizational authority. There are often many different protocols for account de-provisioning, depending on the nature of the event. For example, a promotion may require the account to be locked while the new access rights are assigned to the account, and the old ones are removed. A firing or dismissal may require immediate locking and password reset on the account while valuable company data is retrieved. The de-provisioning process is a delicate dance that needs to be planned and tested ahead of time to avoid security incidents.

This very basic Identity & Access Management Lifecycle provides a stable framework for organizations to follow when integrating a centralized IAM platform. The specific actions to be taken in each step need to be thoroughly discussed and reviewed by both senior management and IT authorities. The procedures that are decided upon need to be documented and regularly tested by the appropriate staff to ensure proper functionality of account management. In the modern digital landscape, many organizations are turning to automation to streamline many of these tasks. For example, provisioning and de-provisioning tasks can be automated by interconnecting the organization’s HR system with the IAM platform. When a decision is made regarding an employee and is input into the HR system, an API can pass this logic to the IAM platform, which can then immediately take action on the employee’s digital identity. 24/7 session monitoring can also interconnect with SIEM & SOAR platforms for near real-time information regarding the organization’s identity threat landscape. Actions can then be taken directly on the digital accounts themselves, including account locks, forced password resets, and unenrollment from critical resources.