REGISTER REVISED SEPTEMBER 2026

What is identity lifecycle management?

ILM Reference editors · Last reviewed September 2026 · 7 minute read

SUMMARYREV. 2026-09

Identity lifecycle management is the process of creating, changing, reviewing and removing access for every identity, human or machine, from the day it is created to the day it is retired. In practice it has five stages: joiner, mover, leaver, periodic review, and orphan-account clean-up. Most programs automate these stages for connected applications and leave disconnected ones to manual work.

§ 01

What does identity lifecycle management cover?

An identity is a person, contractor, service account or AI agent that can use systems. Lifecycle management answers four questions about each one at any moment: which accounts does it have, in which applications, with what access, and should it still have them. The program is a set of processes and tools that keep those answers correct as people join, change roles and leave.

Regulators describe the same thing in their own words. Commission Delegated Regulation (EU) 2024/1774, the technical standard under DORA for ICT risk management, requires financial entities to operate a lifecycle management process for identities and accounts covering creation, change, review and update, temporary deactivation and termination of all accounts (Article 20). NIST SP 800-53 Rev. 5 control AC-2 (Account Management) asks organizations to create, enable, modify, disable and remove accounts in line with defined policy, and to review accounts for compliance on a defined frequency.

§ 02

What are the five stages?

04 · Review

Connected apps: SailPoint Identity Security Cloud, Saviynt, Okta Identity Governance, Microsoft Entra ID Governance, Veza, C1 (formerly ConductorOne), Lumos

Disconnected apps: Microsoft Entra ID Governance (CSV export, match to Entra users, then review), Veza (accounts outside identity platforms), Saviynt (disconnected apps in campaigns)

05 · Orphan

Connected apps: Veza, Lumos, C1 (formerly ConductorOne), Okta Identity Governance, Microsoft Entra ID Governance

Disconnected apps: Orchid Security (orphaned and local accounts found inside the app), Veza (local, machine and service accounts)

Identity lifecycle ring: which tools document coverage at each stageFive stages in a ring, joiner, mover, leaver, review and orphan, with the tools whose public pages describe coverage for connected and disconnected applications at each stage. A dashed return line runs from orphan back to review.Joiner01Mover02Leaver03Review04Orphan05found, then re-reviewedEvery applicationCONNECTED + DISCONNECTED

01 · Joiner

Connected apps: SailPoint Identity Security Cloud, Saviynt, Okta Identity Governance, Microsoft Entra ID Governance, Veza, C1 (formerly ConductorOne), Lumos

Disconnected apps: Saviynt (onboarding of disconnected apps), Microsoft Entra ID Governance (ServiceNow ticket for manual provisioning), Orchid Security (brings the app under IAM and IGA control; provisioning stays in your IGA)

02 · Mover

Connected apps: SailPoint Identity Security Cloud, Saviynt, Okta Identity Governance, Microsoft Entra ID Governance, Veza, C1 (formerly ConductorOne), Lumos

Disconnected apps: Saviynt (disconnected apps in the same IGA), Orchid Security (maps roles and access paths inside the app)

03 · Leaver

Connected apps: SailPoint Identity Security Cloud, Saviynt, Okta Identity Governance, Microsoft Entra ID Governance, Veza, C1 (formerly ConductorOne), Lumos

Disconnected apps: Veza (offboarding including local accounts), Lumos (revocation across local accounts, custom and on-prem apps), Microsoft Entra ID Governance (access review result plus manual removal)

Read the ring as a list
Figure 1. Coverage documented on each vendor's public pages, reviewed September 2026. A name appears only where the vendor's own page or documentation describes the capability. Absence means not documented, not proven absent.
The five stages of identity lifecycle management.
StageWhat happensTypical triggerTypical owner
JoinerAccounts and birthright access createdHR record createdIAM team, via IGA or IdP
MoverAccess added and removed for the new roleHR change in role, department or managerIAM team, managers
LeaverAll accounts disabled or removedHR termination dateIAM team, app owners for disconnected apps
ReviewAccess certified or revokedScheduled campaign (quarterly, annual)Managers, app owners, GRC
Orphan clean-upAccounts with no current owner found and resolvedReconciliation, audit findingIAM and GRC
§ 03

Where do the identity provider and IGA stop?

An identity provider (IdP) controls sign-on. An IGA platform controls provisioning, reviews and policy. Both act through connections: SSO federation, SCIM, APIs or connectors. Where an application has none of these, neither system can see its accounts or change them. Microsoft's documentation for Entra ID Governance covers this case with a manual procedure: export the application's users to a CSV file, match them to directory users, then review.

Those disconnected applications are usually legacy, on-premises or custom-built, and often hold the most sensitive data. They are also where local accounts, created inside the app and never passed through the IdP, accumulate.

§ 04

What does a complete program include?

  1. Application inventory, including applications nobody connected.
  2. Account inventory per application, reconciled to the HR system of record.
  3. Automated JML for connected apps; a timed, ticketed process for disconnected ones.
  4. Access reviews that include disconnected apps.
  5. Orphan-account detection on a schedule, not only at audit time.
  6. Evidence retained so each audit does not start from zero.
§ 05

Which tools help?

Governance platforms (SailPoint Identity Security Cloud, Saviynt, Microsoft Entra ID Governance, Okta Identity Governance, C1, Lumos) automate stages 1 to 4 for connected applications. Veza adds effective-permission visibility across its integrations. Orchid Security focuses on discovering unmanaged applications and the accounts inside them, then feeding them to those platforms. Scores and trade-offs: tool comparison.

FAQ

Is identity lifecycle management the same as IGA?

IGA (identity governance and administration) is the category of software that automates most of the lifecycle. Lifecycle management is the process; IGA is one of the tools for it.

Does lifecycle management include non-human identities?

Yes. Service accounts, API keys and AI agents have owners, access and an end of life too. Several vendors in this reference now include them.

Sources

Reviewed Sep 2026

Related

GUIDEREV. 2026-09
COMPARISONREV. 2026-09