Skip to main content
Promotional banner ad for the Penetration Testing Report Kit
Category: Identity & Access

Provisioning and Deprovisioning

Also known as: User Provisioning and Deprovisioning, Account Provisioning and Deprovisioning, Identity Provisioning
Simply put

Provisioning is the process of creating user identities and granting them access to the applications and systems they need, while deprovisioning is the reverse process of removing that access and disabling or deleting accounts when they are no longer required. Together they manage a user's access from onboarding through departure. These processes are typically part of broader identity lifecycle management within an organization.

Formal definition

Provisioning refers to the creation and configuration of an identity in one or more target systems, including the assignment of access rights, privileges, and entitlements, generally based on defined conditions or policies. Deprovisioning is the corresponding removal, disabling, or deletion of that identity and its associated access across the relevant applications and systems. In practice these operations span the full lifecycle of identities, privileges, and entitlements, and may be applied across multiple applications and directory services; specific mechanisms, triggers, and automation depend on the organization's tooling and policy design.

Why it matters

Provisioning and deprovisioning sit at the core of access control, and errors in either direction create risk. Under-provisioning frustrates productivity, but over-provisioning—granting more access than a role requires, or leaving access in place after it is no longer needed—expands the attack surface and undermines the principle of least privilege. Deprovisioning failures are a particular concern: accounts that remain active after an employee departs or changes roles (often called orphaned or dormant accounts) can be exploited by external attackers or misused by former insiders, and they complicate any subsequent investigation.

Because these processes govern who can reach which systems and data, they are frequently examined in security assessments and audits. Access control is a recurring focus of widely used security frameworks such as ISO/IEC 27001 and SOC 2, and of data protection regimes such as the GDPR, which generally expects organizations to implement appropriate technical and organizational measures to protect personal data. It is important to recognize the distinction: frameworks like ISO/IEC 27001 and SOC 2 are voluntary or contractual unless incorporated by law or agreement, whereas the GDPR carries legal force within its jurisdictional scope. Provisioning and deprovisioning practices are one means by which an organization may support such obligations, but they do not by themselves constitute compliance or certification.

The specific mechanisms, triggers, and degree of automation depend heavily on an organization's tooling and policy design, so what is adequate varies by risk level, data category, and organizational context. This entry describes provisioning and deprovisioning as identity lifecycle concepts; it does not prescribe particular controls for any given regulatory requirement, and application to specific circumstances requires professional judgment. Readers should verify obligations against the current authoritative text of any applicable regulation, framework, or certification scheme.

Who it's relevant to

Information security professionals
Those responsible for access control rely on provisioning and deprovisioning to enforce least privilege and to ensure access reflects current need. They are particularly concerned with timely deprovisioning to reduce the risk posed by orphaned or dormant accounts, and with ensuring that changes propagate consistently across the multiple applications and directory services an identity may touch.
Identity and access management (IAM) teams
IAM practitioners design and operate the policies, triggers, and tooling that drive identity lifecycle management. Their work spans the creation, updating, and removal of accounts across systems, and they must translate organizational conditions—roles, departments, approvals—into the entitlements assigned at provisioning and revoked at deprovisioning.
Auditors and assessors
Access control is a common focus of security assessments and audits, including those aligned with frameworks such as ISO/IEC 27001 or SOC 2. Auditors typically examine whether provisioning follows defined policy and whether deprovisioning occurs reliably when access is no longer required. Note that an assessment or audit evaluates practices against criteria; it is distinct from certification, and passing one does not by itself establish compliance with any legal obligation.
Data protection and privacy specialists
Where provisioning governs access to personal data, these processes may support obligations to implement appropriate technical and organizational measures under regimes such as the GDPR. Specialists should consider provisioning and deprovisioning as one contributing measure rather than a complete answer, and should verify specific requirements against the applicable regulation, as obligations differ across the EU, the United States, the United Kingdom, and other jurisdictions.
IT operations and system administrators
Administrators often carry out provisioning and deprovisioning day to day—creating accounts, granting resource access at onboarding, and disabling or deleting accounts at departure. In directory environments such as Active Directory, they manage these actions directly, and their timeliness and accuracy materially affect both operational access and security posture.

Inside Provisioning and Deprovisioning

Provisioning
The process of creating, configuring, and granting a user, service, or device the access rights, accounts, and resources needed to perform an authorized function. Provisioning typically maps identities to entitlements based on role, attributes, or explicit approval, and should be tied to a documented authorization event such as onboarding or a role change.
Deprovisioning
The process of removing or disabling access rights, accounts, and associated resources when they are no longer required, such as at offboarding, role change, or contract termination. Deprovisioning aims to eliminate residual access that could otherwise be exploited, and generally covers not only primary accounts but also linked entitlements, tokens, and shared credentials.
Joiner-Mover-Leaver (JML) lifecycle
A common conceptual model describing the identity lifecycle events that trigger provisioning and deprovisioning: joining (initial access grant), moving (adjustment of access on role or department change), and leaving (removal of access). Provisioning and deprovisioning are the operational actions applied across these stages.
Access request and approval workflow
The controls governing who may request access, who authorizes it, and on what basis. Provisioning should generally follow a defined approval path so that entitlements are granted according to least privilege and are traceable to an accountable approver.
Automated vs. manual provisioning
Provisioning may be performed manually by administrators or automated through identity governance and administration (IGA) or identity provider tooling. Automation can reduce delay and error, particularly in deprovisioning, but the appropriate approach depends on organizational scale, system integration, and risk.
Audit trail and evidence
Records that document when access was granted, modified, or revoked, by whom, and under what authorization. Such records support internal review and may serve as evidence when demonstrating access controls under frameworks such as ISO/IEC 27001 or SOC 2, or where required by applicable regulation.
Access review and reconciliation
Periodic verification that provisioned access still matches current authorization, intended to detect entitlements that should have been removed. Reviews complement deprovisioning by catching access that persisted after a JML event was missed or incompletely processed.

Common questions

Answers to the questions practitioners most commonly ask about Provisioning and Deprovisioning.

Is provisioning and deprovisioning a legal requirement under a specific regulation?
Provisioning and deprovisioning are access management practices, not obligations tied to any single named regulation. They are commonly treated as controls within voluntary standards and frameworks (for example, access control expectations found in ISO/IEC 27001 or SOC 2 criteria) and may support compliance with data protection or security regulations that require appropriate access safeguards. However, no universal statute mandates these processes by name. Whether and how they are required depends on the applicable regulatory regime, sector, contractual commitments, and risk profile. Readers should verify specific obligations against the relevant authoritative source for their jurisdiction and industry.
Are provisioning and deprovisioning just two names for the same access process?
No. They are distinct and complementary lifecycle activities that should not be conflated. Provisioning generally refers to granting and configuring a user's access rights and resources, typically at onboarding or when a role changes. Deprovisioning generally refers to revoking or removing that access, typically at offboarding, role change, or contract termination. Treating them as a single step is a common source of risk, because organizations may focus on granting access while neglecting timely removal, leaving dormant or orphaned accounts. Effective access management addresses both directions of the lifecycle as separate, auditable events.
When should deprovisioning occur relative to an employee's departure?
As a general practice, deprovisioning is intended to remove access promptly once it is no longer needed, and many organizations aim to align deprovisioning with the effective end of a role or employment. The appropriate timing is fact-specific and may depend on risk level, the sensitivity of the data or systems involved, and internal policy or contractual terms. Some scenarios call for immediate revocation, while others may involve staged removal. Organizations typically define timing expectations in their own access management policies rather than relying on a single external standard.
How can provisioning and deprovisioning support an audit or assessment?
Provisioning and deprovisioning activities generally produce records that can be reviewed during an audit or assessment of access controls. Maintaining logs of who was granted access, when, by whom, and under what authorization, along with corresponding records of removal, can help demonstrate that access is managed consistently. Note that an audit and an assessment are distinct exercises: an audit typically evaluates conformity against defined criteria, while an assessment may be a broader or advisory review. The value of these records depends on their completeness and reliability, which readers should confirm against the criteria applicable to their engagement.
What role does the principle of least privilege play in provisioning?
Least privilege is a design principle often applied during provisioning, under which a user is generally granted only the access needed to perform their function and no more. Applying it during provisioning can reduce the scope of access that later needs to be reviewed or removed. It is a practice that supports, but is separate from, deprovisioning; granting narrowly does not eliminate the need to revoke access when it is no longer required. How strictly least privilege is applied often depends on risk, role complexity, and organizational policy.
How can organizations reduce the risk of orphaned or dormant accounts?
Common approaches include tying provisioning and deprovisioning to authoritative sources of identity and role information, performing periodic access reviews to identify accounts that no longer correspond to active roles, and defining clear triggers for revocation such as offboarding or role change. Automation may help reduce delays and human error, though the appropriate level of automation is fact-specific and depends on the environment. These are general practices; their suitability and implementation details should be evaluated in light of an organization's own risk profile, systems, and applicable requirements.

Common misconceptions

Deprovisioning is complete once the primary user account is disabled.
Disabling a single account often leaves residual access intact, including entitlements in downstream systems, active session tokens or API keys, shared or service credentials, and access granted outside the central directory. Effective deprovisioning generally requires addressing all associated entitlements, not just the primary account.
Provisioning and deprovisioning are purely operational IT tasks with no compliance relevance.
Access lifecycle controls are commonly assessed under voluntary standards such as ISO/IEC 27001 and SOC 2, and may be relevant to demonstrating appropriate security and access measures where a regulation imposes such obligations. Whether specific requirements apply is fact-specific and depends on the applicable framework, contract, or law.
Automating provisioning guarantees least-privilege access.
Automation enforces whatever rules and role definitions it is configured with. If underlying roles are over-broad or approval logic is flawed, automation can propagate excessive access consistently. Automation reduces certain errors but does not, on its own, ensure that granted entitlements are appropriate.

Best practices

Tie every provisioning action to a documented authorization event and an accountable approver, and record the same for modifications and revocations to maintain a traceable audit trail.
Prioritize timely deprovisioning on leaver and mover events, and confirm that removal extends beyond the primary account to linked entitlements, tokens, keys, and shared or service credentials.
Apply least privilege by mapping access to defined roles or attributes, and review role definitions periodically so that automated provisioning does not propagate over-broad entitlements.
Conduct periodic access reviews and reconciliation to detect entitlements that should have been removed, treating these as a safeguard against missed or incomplete JML processing.
Where automation is used, validate the configured approval logic and role mappings rather than assuming automation alone ensures appropriate access.
Verify specific control requirements against the current authoritative text of any applicable standard, certification scheme, or regulation, since versions and obligations change and application to particular circumstances requires professional judgment.
Promotional banner for the Penetration Report Template Kit