deprovisioning

term

securitygovernance & risk

Removing an identity's access when a person leaves or a role changes - the half of the lifecycle nobody is waiting on.

Provisioning has an impatient audience and deprovisioning has none, which is why access accumulates and departures leave accounts behind. The dangerous residue is rarely the main directory account, which someone does disable, but everything federated, local or machine-to-machine that was granted separately: a key in a repository, an account on a supplier's portal, a token in a scheduled job. The measurable question is how long after a departure the last credential dies.

Also known as: offboarding

All glossary entries