Just-in-time (JIT) provisioning

Creating a user's account at a relying party automatically the first time a federated identity arrives there, using attributes from the assertion, instead of creating it in advance.

Just-in-time (JIT) provisioning creates an account at an application the first time a user arrives through federation. NIST SP 800-63C-4 (section 4.6.3) describes it as the relying party creating a subscriber account when it first receives an assertion carrying a federated identifier it does not know, and optionally storing identity attributes learned from the assertion. The same section notes that it is the most common form of provisioning in federation systems because it needs the least coordination between the identity provider and the relying party. Another model it describes, pre-provisioning, creates accounts in bulk ahead of time through a provisioning interface, commonly SCIM.

JIT provisioning is a different idea from just-in-time access, which grants a privilege for a limited task and time and then removes it. JIT provisioning also leaves a gap at the other end of the lifecycle: it creates accounts and has no step of its own for removing them, so a user disabled at the identity provider can leave accounts behind at each application unless deprovisioning is handled separately, and those can become orphaned accounts.

Exam relevance: a scenario is likely to describe an account appearing at a cloud application on a user’s first federated login. Candidates are expected to name JIT provisioning, keep it apart from JIT access, and see the deprovisioning gap it leaves.