REGISTER REVISED SEPTEMBER 2026

Identity lifecycle management FAQ

ILM Reference editors · Published 2026-09-01

SUMMARYREV. 2026-09

Short answers to the questions we are asked most, grouped by theme. Each answer links to the page that goes deeper. Scores and ranks in the answers are computed from the same data file as the comparison page.

Identity lifecycle basics

What is identity lifecycle management?

The processes that create, change, review and remove access for every identity, human or machine, from the day it is created to the day it is retired. It covers joiners, movers and leavers, periodic access reviews and the clean-up of accounts nobody owns. See what is identity lifecycle management.

What is the joiner-mover-leaver process?

Joiner, mover and leaver (JML) are the three HR events that should drive access. A joiner receives accounts and birthright access, a mover gains the access for the new role and loses the old, and a leaver loses every account. Most programs automate JML for connected applications and handle the rest by ticket; see the JML process guide.

What is an orphan account?

An active account with no current valid owner, usually left behind when someone leaves or changes role, or created locally inside an application. NIST SP 800-53 control enhancement AC-2(3) asks organizations to disable accounts that are no longer associated with a user or individual. See the orphan accounts guide.

What is a disconnected application?

An application your identity provider or IGA platform cannot read from or write to, because it has no connector, no SCIM endpoint and no SSO integration. Its accounts are handled by exports, tickets or not at all. See disconnected applications.

What is the difference between an identity provider and an IGA platform?

An identity provider controls sign-on to connected applications. An IGA platform controls provisioning, access reviews and access policy. Neither can act on an application it has no connection to, which is where local accounts and orphan accounts collect.

How often should access be reviewed?

Your policy sets the frequency; quarterly for high-risk and financially significant systems is common. DORA's technical standard sets a floor of at least once a year for staff with access to ICT assets supporting critical or important functions. See the DORA lesson.

Buying and pricing

Which identity lifecycle management tools publish prices?

Microsoft Entra ID Governance publishes $7.00 per user per month, paid yearly, with Entra ID P1 or P2 required. Okta publishes Workforce Identity suite prices, but Identity Governance sits in the Professional and Enterprise suites, priced on inquiry. C1 publishes its pricing structure without prices, and the other tools are by quote. The calculator shows cost where a price is published.

Do I need a separate tool for disconnected applications?

Not always. With a few disconnected applications, a documented manual process can work; Microsoft documents one for Entra ID Governance. With many, or an unknown number, a tool that discovers applications and the accounts inside them, or an IGA that onboards disconnected applications, reduces the manual work. The coverage ledger records what each vendor describes.

Should I replace my IGA platform to cover disconnected applications?

Usually not as a first step. All the governance platforms on this site describe coverage for connected applications; they differ mainly on disconnected ones. Adding discovery beside the existing IGA is a smaller change than a migration. Replacing the IGA makes more sense when it also falls short on JML automation or certifications.

How should I run a proof of concept for a lifecycle tool?

Test it on your own applications, including at least one disconnected, one legacy and one custom-built application, and measure what it finds against an account list you extracted yourself. Our proof of concept note lists the steps.

How can I compare the tools on my own priorities?

Use the calculator to change the weight of each criterion and re-rank all 8 tools, or the side-by-side compare to put two to five tools in one table.

The tools we score

What is Orchid Security best for?

Discovering unmanaged applications and the local and orphaned accounts inside them, and feeding that context to the IGA, IAM and PAM tools already in place. Orchid Security scores 71/100 (rank 1 of 8); it trails on JML automation, certification depth and pricing transparency because it does not provision users or run campaigns itself.

What is Saviynt best for?

Organizations that want one IGA platform covering connected, disconnected and custom-built applications, with JML, certifications and audit evidence. Saviynt scores 70/100 (rank 2 of 8) and publishes no prices.

What is Veza best for?

Effective-permission visibility across cloud, data and SaaS systems, with dormant, local and service accounts revealed and lifecycle actions on the same Access Graph. Veza scores 69/100 (rank 3 of 8); coverage follows its 325+ integrations and custom connectors.

What is SailPoint Identity Security Cloud best for?

JML automation and certification campaigns at enterprise scale. SailPoint Identity Security Cloud scores 68/100 (rank 4 of 8); discovery of unregistered applications depends on add-ons or partners.

What is Microsoft Entra ID Governance best for?

Microsoft-centric organizations that want lifecycle workflows and access reviews at a published price of $7.00 per user per month, paid yearly, on top of Entra ID P1 or P2. Microsoft Entra ID Governance scores 64/100 (rank 5 of 8); disconnected applications use a documented manual CSV process.

What is Okta Identity Governance best for?

Organizations already on Okta Workforce Identity that want access requests, certifications and entitlements in the same console, with most applications connected through SCIM. Okta Identity Governance scores 59/100 (rank 8 of 8).

What is C1 (formerly ConductorOne) best for?

Teams that want HR-triggered JML and access reviews with an open connector model: Baton open-source connectors and C1 Bridge for on-prem systems. C1 scores 63/100 (rank 6 of 8); prices are by quote.

What is Lumos best for?

SaaS-heavy companies that want HRIS-driven JML, license reclamation at offboarding and help preparing access reviews. Lumos scores 62/100 (rank 7 of 8) and publishes no prices.

How this site scores

How are the scores calculated?

Each tool gets a 0 to 100 score on seven weighted criteria from its public pages, documentation and pricing. The total is the sum of score times weight, divided by 100, computed in code. The editorial method lists the weights and every reason.

Were the tools tested?

No. The scores are an editorial assessment of public vendor material, reviewed in September 2026. We did not test the products, run them against our own applications or interview vendors or customers.

How often is the reference updated?

Prices and headline capabilities are re-checked each quarter, and the review date on each page changes when that happens. New articles carry their own publication date.

How do I report an error?

Email editor@identitylifecyclemanagement.com with the page, the claim and a public source. We check corrections against public sources before changing anything.

Related

COMPARISONREV. 2026-09
METHODREV. 2026-09