Provisioning and Deprovisioning
Provisioning is the process of creating user identities and granting them access to the applications and systems they need, while deprovisioning is the reverse process of removing that access and disabling or deleting accounts when they are no longer required. Together they manage a user's access from onboarding through departure. These processes are typically part of broader identity lifecycle management within an organization.
Provisioning refers to the creation and configuration of an identity in one or more target systems, including the assignment of access rights, privileges, and entitlements, generally based on defined conditions or policies. Deprovisioning is the corresponding removal, disabling, or deletion of that identity and its associated access across the relevant applications and systems. In practice these operations span the full lifecycle of identities, privileges, and entitlements, and may be applied across multiple applications and directory services; specific mechanisms, triggers, and automation depend on the organization's tooling and policy design.
Why it matters
Provisioning and deprovisioning sit at the core of access control, and errors in either direction create risk. Under-provisioning frustrates productivity, but over-provisioning—granting more access than a role requires, or leaving access in place after it is no longer needed—expands the attack surface and undermines the principle of least privilege. Deprovisioning failures are a particular concern: accounts that remain active after an employee departs or changes roles (often called orphaned or dormant accounts) can be exploited by external attackers or misused by former insiders, and they complicate any subsequent investigation.
Because these processes govern who can reach which systems and data, they are frequently examined in security assessments and audits. Access control is a recurring focus of widely used security frameworks such as ISO/IEC 27001 and SOC 2, and of data protection regimes such as the GDPR, which generally expects organizations to implement appropriate technical and organizational measures to protect personal data. It is important to recognize the distinction: frameworks like ISO/IEC 27001 and SOC 2 are voluntary or contractual unless incorporated by law or agreement, whereas the GDPR carries legal force within its jurisdictional scope. Provisioning and deprovisioning practices are one means by which an organization may support such obligations, but they do not by themselves constitute compliance or certification.
The specific mechanisms, triggers, and degree of automation depend heavily on an organization's tooling and policy design, so what is adequate varies by risk level, data category, and organizational context. This entry describes provisioning and deprovisioning as identity lifecycle concepts; it does not prescribe particular controls for any given regulatory requirement, and application to specific circumstances requires professional judgment. Readers should verify obligations against the current authoritative text of any applicable regulation, framework, or certification scheme.
Who it's relevant to
Inside Provisioning and Deprovisioning
Common questions
Answers to the questions practitioners most commonly ask about Provisioning and Deprovisioning.