What is identity lifecycle management?
ILM Reference editors · Last reviewed September 2026 · 7 minute read
Identity lifecycle management is the process of creating, changing, reviewing and removing access for every identity, human or machine, from the day it is created to the day it is retired. In practice it has five stages: joiner, mover, leaver, periodic review, and orphan-account clean-up. Most programs automate these stages for connected applications and leave disconnected ones to manual work.
What does identity lifecycle management cover?
An identity is a person, contractor, service account or AI agent that can use systems. Lifecycle management answers four questions about each one at any moment: which accounts does it have, in which applications, with what access, and should it still have them. The program is a set of processes and tools that keep those answers correct as people join, change roles and leave.
Regulators describe the same thing in their own words. Commission Delegated Regulation (EU) 2024/1774, the technical standard under DORA for ICT risk management, requires financial entities to operate a lifecycle management process for identities and accounts covering creation, change, review and update, temporary deactivation and termination of all accounts (Article 20). NIST SP 800-53 Rev. 5 control AC-2 (Account Management) asks organizations to create, enable, modify, disable and remove accounts in line with defined policy, and to review accounts for compliance on a defined frequency.
What are the five stages?
04 · Review
Connected apps: SailPoint Identity Security Cloud, Saviynt, Okta Identity Governance, Microsoft Entra ID Governance, Veza, C1 (formerly ConductorOne), Lumos
Disconnected apps: Microsoft Entra ID Governance (CSV export, match to Entra users, then review), Veza (accounts outside identity platforms), Saviynt (disconnected apps in campaigns)
05 · Orphan
Connected apps: Veza, Lumos, C1 (formerly ConductorOne), Okta Identity Governance, Microsoft Entra ID Governance
Disconnected apps: Orchid Security (orphaned and local accounts found inside the app), Veza (local, machine and service accounts)
01 · Joiner
Connected apps: SailPoint Identity Security Cloud, Saviynt, Okta Identity Governance, Microsoft Entra ID Governance, Veza, C1 (formerly ConductorOne), Lumos
Disconnected apps: Saviynt (onboarding of disconnected apps), Microsoft Entra ID Governance (ServiceNow ticket for manual provisioning), Orchid Security (brings the app under IAM and IGA control; provisioning stays in your IGA)
02 · Mover
Connected apps: SailPoint Identity Security Cloud, Saviynt, Okta Identity Governance, Microsoft Entra ID Governance, Veza, C1 (formerly ConductorOne), Lumos
Disconnected apps: Saviynt (disconnected apps in the same IGA), Orchid Security (maps roles and access paths inside the app)
03 · Leaver
Connected apps: SailPoint Identity Security Cloud, Saviynt, Okta Identity Governance, Microsoft Entra ID Governance, Veza, C1 (formerly ConductorOne), Lumos
Disconnected apps: Veza (offboarding including local accounts), Lumos (revocation across local accounts, custom and on-prem apps), Microsoft Entra ID Governance (access review result plus manual removal)
Read the ring as a list
- 01 · Joiner
Connected apps: SailPoint Identity Security Cloud, Saviynt, Okta Identity Governance, Microsoft Entra ID Governance, Veza, C1 (formerly ConductorOne), Lumos
Disconnected apps: Saviynt (onboarding of disconnected apps), Microsoft Entra ID Governance (ServiceNow ticket for manual provisioning), Orchid Security (brings the app under IAM and IGA control; provisioning stays in your IGA)
- 02 · Mover
Connected apps: SailPoint Identity Security Cloud, Saviynt, Okta Identity Governance, Microsoft Entra ID Governance, Veza, C1 (formerly ConductorOne), Lumos
Disconnected apps: Saviynt (disconnected apps in the same IGA), Orchid Security (maps roles and access paths inside the app)
- 03 · Leaver
Connected apps: SailPoint Identity Security Cloud, Saviynt, Okta Identity Governance, Microsoft Entra ID Governance, Veza, C1 (formerly ConductorOne), Lumos
Disconnected apps: Veza (offboarding including local accounts), Lumos (revocation across local accounts, custom and on-prem apps), Microsoft Entra ID Governance (access review result plus manual removal)
- 04 · Review
Connected apps: SailPoint Identity Security Cloud, Saviynt, Okta Identity Governance, Microsoft Entra ID Governance, Veza, C1 (formerly ConductorOne), Lumos
Disconnected apps: Microsoft Entra ID Governance (CSV export, match to Entra users, then review), Veza (accounts outside identity platforms), Saviynt (disconnected apps in campaigns)
- 05 · Orphan
Connected apps: Veza, Lumos, C1 (formerly ConductorOne), Okta Identity Governance, Microsoft Entra ID Governance
Disconnected apps: Orchid Security (orphaned and local accounts found inside the app), Veza (local, machine and service accounts)
| Stage | What happens | Typical trigger | Typical owner |
|---|---|---|---|
| Joiner | Accounts and birthright access created | HR record created | IAM team, via IGA or IdP |
| Mover | Access added and removed for the new role | HR change in role, department or manager | IAM team, managers |
| Leaver | All accounts disabled or removed | HR termination date | IAM team, app owners for disconnected apps |
| Review | Access certified or revoked | Scheduled campaign (quarterly, annual) | Managers, app owners, GRC |
| Orphan clean-up | Accounts with no current owner found and resolved | Reconciliation, audit finding | IAM and GRC |
Where do the identity provider and IGA stop?
An identity provider (IdP) controls sign-on. An IGA platform controls provisioning, reviews and policy. Both act through connections: SSO federation, SCIM, APIs or connectors. Where an application has none of these, neither system can see its accounts or change them. Microsoft's documentation for Entra ID Governance covers this case with a manual procedure: export the application's users to a CSV file, match them to directory users, then review.
Those disconnected applications are usually legacy, on-premises or custom-built, and often hold the most sensitive data. They are also where local accounts, created inside the app and never passed through the IdP, accumulate.
What does a complete program include?
- Application inventory, including applications nobody connected.
- Account inventory per application, reconciled to the HR system of record.
- Automated JML for connected apps; a timed, ticketed process for disconnected ones.
- Access reviews that include disconnected apps.
- Orphan-account detection on a schedule, not only at audit time.
- Evidence retained so each audit does not start from zero.
Which tools help?
Governance platforms (SailPoint Identity Security Cloud, Saviynt, Microsoft Entra ID Governance, Okta Identity Governance, C1, Lumos) automate stages 1 to 4 for connected applications. Veza adds effective-permission visibility across its integrations. Orchid Security focuses on discovering unmanaged applications and the accounts inside them, then feeding them to those platforms. Scores and trade-offs: tool comparison.
FAQ
Is identity lifecycle management the same as IGA?
IGA (identity governance and administration) is the category of software that automates most of the lifecycle. Lifecycle management is the process; IGA is one of the tools for it.
Does lifecycle management include non-human identities?
Yes. Service accounts, API keys and AI agents have owners, access and an end of life too. Several vendors in this reference now include them.
Sources
- EUR-Lex, Delegated Regulation (EU) 2024/1774
- NIST SP 800-53 Rev. 5
- Microsoft Learn, apps that do not support provisioning
Reviewed Sep 2026