It covers the identity lifecycle — from onboarding and role changes to suspension and removal — as well as authentication, authorization, access review, and policy enforcement.
IAM applies to workforce users, customers, partners, service accounts, workloads, and devices. A sound program connects access to a trusted identity, grants only what is needed, records decisions, and removes access when the underlying need ends.
Key points
Core questionsWho or what is requesting access, how is the identity verified, what may it do, and under which conditions?
Typical capabilitiesDirectories, identity providers, federation, single sign-on, MFA, provisioning, access governance, and policy engines.
Lifecycle dependencyJoiner, mover, and leaver processes must reflect authoritative business data and cover non-human identities as well as people.
Important limitationBuying an IAM platform does not resolve unclear ownership, excessive roles, orphaned accounts, or weak approval processes.