Deprovisioning

Disabling or removing an account and revoking the access that went with it, including sessions, tokens and shared credentials, when a person leaves, moves role or no longer needs it.

Deprovisioning is the closing stage of the identity lifecycle and the counterpart of provisioning. When access is no longer needed, the account is disabled or removed and its access revoked. That reaches beyond the directory entry to open sessions, issued tokens and any shared or group credential the person knew; NIST SP 800-53 Rev. 5 control AC-2 calls for changing shared or group authenticators when a member leaves the group, and for aligning account management with personnel termination and transfer processes.

A transfer is both at once: the new role’s access is added, and whatever the old role had that the new one does not need is removed. Skipping the removal is how privilege creep builds up, and an account that outlives its owner becomes an orphaned account. In a federation, disabling the user at the identity provider stops new sign-ins, but sessions already open and accounts already created at each application end only when those are ended too, the gap SCIM is used to close.

Exam relevance: a scenario is likely to describe a leaver who still has access weeks later, or a mover who kept both roles. Candidates are expected to find the failed step and to prefer a process triggered by HR events, with access review as the check that catches what it missed.