Skip to content
Tech Interview Prep home
Technical interview guide

Identity Lifecycle & Provisioning

Automating account creation, access changes, and deprovisioning across a person's entire time at an organization.

Read
45 min
Practice MCQs
25
Interview QA
25
Edition
v5
Editorial status
Reviewed

Scope: SCIM RFC 7643/7644, NIST SP 800-53 Rev. 5 and SP 800-63C-4, current CISA, Microsoft Entra, Google Cloud, AWS IAM Identity Center, Okta, OWASP, and OpenID guidance reviewed 2026-09-04.

Overview

Curated: · Written: · Reviewed:

Turn authoritative lifecycle events into verified effective access

Identity lifecycle management translates a person's or workload's relationship with an organization into accounts, identifiers, groups, roles, attributes, sessions, and target-system access. The joiner–mover–leaver model is useful, but the real control is an end-to-end state machine: a trusted source establishes an event, policy computes desired access, provisioning changes each target, reconciliation verifies effective state, and failures reach an accountable owner. A successful workflow status is not proof that access changed at the target. The operator question is what the principal can still do, not which ticket closed.

Choose authoritative sources explicitly. HR may own worker status, manager, department, location, and dates; partner systems may own sponsor and contract end; a workload registry may own service identity and environment. Normalize events into stable internal identifiers and effective times. Email address, display name, and reused employee number are unsafe primary keys. Preserve immutable identity linkage across name changes while preventing a rehired person or replacement contractor from inheriting the previous principal's sessions, secrets, private data, or unexplained entitlements. A recycled email is a collision, not a join.

For joiners, apply birthright access from reviewed policy and delay sensitive grants until required evidence, training, device, manager, or start time exists. Pre-provisioning can improve day-one readiness, but activation must respect effective date and cancellation. Avoid copying a peer's complete access because peers often carry accumulated exceptions. Record why each entitlement exists and who owns it so later review and removal are possible. Cloning a neighbour is the fastest way to recreate last year's unreviewed exceptions on a new account.

Movers are not only add events. Recompute desired access from the new relationship, remove obsolete and toxic grants before or atomically with additions when risk demands it, update privilege-bearing attributes, and reconcile every downstream system. Temporary projects, acting assignments, leave, suspension, and dual roles need explicit start, end, conflict, and precedence rules. Treat attribute changes as authorization changes because ABAC systems may alter access without any group membership update.

Leavers require a coordinated kill chain: stop new authentication and token issuance, disable central and privileged identities, revoke sessions and application tokens, remove group and role membership, invalidate credentials and API keys, transfer owned resources and automation, and reconcile local or disconnected accounts. Schedule normal departures precisely and support immediate termination. Define maximum effective-access removal time by system risk. Deleting a directory row before targets acknowledge deactivation can destroy the correlation needed to find residual accounts. The SLO is minutes to denied action on privileged paths, not hours to a green connector dashboard.

SCIM standardizes provisioning resources and operations; it does not guarantee correct lifecycle policy. Define schema mapping, identifier ownership, case and canonicalization rules, mutability, required attributes, group semantics, and active/deactivation behavior. Authenticate and authorize provisioning clients, protect bearer tokens, validate input, rate-limit safely, and return correct errors. Make retries idempotent, use versioning or ETags where supported, handle PATCH semantics carefully, paginate and filter correctly, and prevent one tenant from addressing another tenant's resources.

Push events provide low latency; reconciliation provides completeness. Run periodic full or incremental comparisons of desired and actual state, including accounts created outside the identity provider, nested groups, local roles, disabled-but-still-tokened users, orphan service accounts, and failed deletions. Classify drift, remediate safely, preserve approved exceptions, and alert owners. A connector that repeatedly retries one poison record must not block every later leaver. Reconciliation that only counts matching usernames will miss a disabled account that still holds a group.

Provisioning and sign-in are different control planes. Disabling a user through SCIM may not terminate an IdP session, an RP session, an OAuth refresh token, an API key, or an already issued cloud session. Map each target's account, authentication, session, token, and local authorization behavior. Use federation logout or revocation where supported, shorten lifetimes where it is not, and measure from authoritative event to denied effective access—not merely to queue acceptance.

Design failure handling before scale. Use durable event IDs, ordering keys, version or effective timestamps, bounded retries, dead-letter isolation, operator replay, and idempotent target changes. Protect against out-of-order join and leave, duplicate webhooks, partial group updates, rate limits, schema drift, connector credential expiry, regional outage, and target restoration from backup. Re-evaluate stale events against current source truth before replaying them so an old join cannot resurrect a leaver. A connector that reports healthy while its oldest unprocessed leaver is fourteen hours old is not healthy.

Audit source event, normalized identity, policy decision, desired-state diff, connector request/result, target resource ID, version, retry, exception, actor, and reconciliation outcome without storing passwords or sensitive attributes unnecessarily. Measure join readiness, mover stale-access duration, leaver effective-revocation latency, orphan and duplicate accounts, out-of-band grants, reconciliation drift age, connector backlog, poison records, retries, failures by target, manual overrides, and review completion. A SCIM 204 that left a 14-day refresh token alive is not a completed leaver. The goal is timely, least-privilege, attributable effective access across every path.