Manage the identity lifecycle
Create, update, review, and remove access as people and systems change.
- Describe joiner, mover, and leaver processes and access reviews.
IAM follows identities and permissions through their lifecycle. When someone or a service joins, grant approved access for its responsibilities. When roles change, update access so obsolete permissions do not accumulate. When an identity leaves or is retired, disable credentials and revoke sessions, keys, tokens, and grants. Periodic access reviews help find permissions that are no longer needed.
A small example
events = ["join: provision approved role", "move: review and update", "leave: disable and revoke"]
for event in events:
print(event)join: provision approved role move: review and update leave: disable and revoke
Automating lifecycle steps can reduce delays and orphaned access, but automation needs authoritative identity data, approvals, and error handling. Include non-human identities such as service accounts and API credentials in inventory and review processes. Keep evidence of approvals and changes for audit needs.
Key takeaways
Describe joiner, mover, and leaver processes and access reviews.
Treat access as a lifecycle: grant deliberately, review regularly, and revoke promptly.
Lesson quiz
5 questions · pass with 4 correct · up to 50 XP
Passing this quiz completes the lesson and keeps your streak going. Questions you miss come back in review sessions later.
Questions about this lesson
Stuck? Ask. Figured something out? Share it. Explaining is one of the best ways to learn.
Loading posts…