Identity enrollment (registration)

The step after identity proofing in which a proofed applicant is given an account and has authenticators bound to it, so that later logins can be tied to that identity.

Identity enrolment, also called registration, is the step that turns a proofed applicant into a subscriber. NIST SP 800-63A-4 (which uses the US spelling “enrollment”) describes it as the credential service provider giving a successfully proofed applicant a subscriber account and binding authenticators to it, so that the person has persistent access. The ISC2 outline groups this work under “Registration, proofing, and establishment of identity”.

Enrolment depends on the step before it. Identity proofing collects and checks evidence that the applicant is who they claim to be; enrolment then records that result and links it to something the person holds or knows. Later authentication proves control of an authenticator bound here, so a weak binding step (for example, sending a first credential to an address nobody verified) undermines the rest. Enrolment is also distinct from provisioning, which grants the account access to particular systems once the identity exists.

Exam relevance: a scenario is likely to describe the order of events at onboarding. Candidates are expected to place proofing first, enrolment and authenticator binding second, and access provisioning after that, and to see a careless binding step as a weakness no strength of later login repairs.