Skip to content
Tech Interview Prep home
Technical interview guide

Identity Lifecycle & Provisioning

Automating account creation, access changes, and deprovisioning across a person's entire time at an organization.

Read
45 min
Practice MCQs
25
Interview QA
25
Edition
v5
Editorial status
Reviewed

Scope: SCIM RFC 7643/7644, NIST SP 800-53 Rev. 5 and SP 800-63C-4, current CISA, Microsoft Entra, Google Cloud, AWS IAM Identity Center, Okta, OWASP, and OpenID guidance reviewed 2026-09-04.

Interview QA

Treat each question like a live interview question: answer out loud first (structure, assumptions, tradeoffs), then open the model answer to spot gaps and rehearse a tighter follow-up.

Curated: · Written: · Reviewed:

QA-1

Design identity correlation across authoritative and target systems.

QA-2

Design a secure joiner workflow.

QA-3

Implement pre-hire and delayed activation safely.

QA-4

Design a mover workflow that prevents access accumulation.

QA-5

Implement time-bound lifecycle grants.

QA-6

Design normal and immediate leaver workflows.

QA-7

Choose disable, archive, and delete semantics.

QA-8

Implement idempotent SCIM provisioning.

QA-9

Map SCIM identifiers and usernames correctly.

QA-10

Implement and test SCIM PATCH.

QA-11

Secure a SCIM endpoint and its client credentials.

QA-12

Design lifecycle reconciliation.

QA-13

Handle retries, dead letters, and poison lifecycle records.

QA-14

Design event ordering for lifecycle automation.

QA-15

Handle rehire without account takeover or stale privilege.

QA-16

Resolve multi-source identity data conflicts.

QA-17

Coordinate deprovisioning with session and token revocation.

QA-18

Provision groups without hidden privilege expansion.

QA-19

Handle resource ownership and automation during offboarding.

QA-20

Design controlled manual provisioning and exception handling.

QA-21

Protect lifecycle state during disaster recovery.

QA-22

Design lifecycle audit and evidence.

QA-23

Define identity lifecycle quality and risk metrics.

QA-24

Operate and monitor provisioning connectors.

QA-25

How do you automate access recertification campaigns and reconcile revoked entitlements across downstream target systems?