What is provisioning and deprovisioning in IAM?

D1 ยท General  ยท  CompTIA Security+ SY0-701
Provisioning is the process of creating user accounts and granting appropriate access rights, permissions, and resources when someone joins an organization or changes roles.

Deprovisioning is the process of revoking and removing access rights, disabling accounts, and reclaiming resources when someone leaves or changes roles.

Proper deprovisioning must happen immediately upon termination โ€” active accounts of former employees are a major security risk.

User lifecycle management: joiner โ†’ mover โ†’ leaver.
Failure to deprovision is a major access control gap. Orphaned accounts (active accounts of former employees) are regularly exploited. Automated provisioning/deprovisioning (SCIM protocol, identity governance tools) reduces manual errors. Access reviews (recertification campaigns) periodically verify all access is still needed.
โ† Back to Glossary Practice Questions โ†’