Domain 4 of 4 · Chapter 1 of 4

Architect the identity lifecycle

Unlock the complete study guide + 1,500 practice questions across 12 full exams.

Bundled into the existing Information Systems Security Architecture Professional premium course — no separate purchase.

14-day money-back guarantee — no questions asked.

Included in this chapter:

  • Four families behind a trustworthy account
  • Resolution, validation, and verification
  • Selecting the identity assurance level from impact
  • What changes from IAL1 to IAL3
  • Proofing types: where it happens, who attends
  • Defending remote capture against injected media
  • Enrollment and authenticator binding
  • When proofing fails a legitimate applicant
  • Choosing the durable identity join key
  • Identifier scope and unwanted correlation
  • Identifiers for services, processes, and devices
  • Joiner, mover, and leaver events
  • De-provisioning order at the termination boundary
  • Reconciling desired state against target state
  • What the directory tier is authoritative for
  • External identities and lifecycle accountability
  • Workload identity on a machine timescale
  • Reading the stem: which lifecycle decision is under test

How the four identity lifecycle families are decided, delivered, and evidenced

Question to answerEstablishing and verifying identityAssigning identifiersProvisioning and de-provisioningIdentity management technologies
What the architect decidesThe assurance level and the accepted proofing paths that meet itThe durable key, its collision domain, and its reassignment ruleWhich authoritative events trigger which access changes, and in what orderWhich system originates each attribute, and how state is exchanged and compared
What drives the requirementThe harm caused by enrolling the wrong personThe systems that must correlate authorization, provisioning, and audit recordsThe real-world employment, contract, or sponsorship status of the subjectThe number of authoritative sources and target systems that must stay consistent
Primary failure modeA fraudulent or unverified enrollment that every later control then protectsA key that changes, collides, or is reassigned, breaking references and attributionPrivilege accumulation on movers and residual access after leaversDrift between intended and actual entitlement state that nobody detects
What proves it worksRecorded evidence, validation and verification results, and exception rationaleStable references across systems and unambiguous audit attributionAccess changes that track status changes within the defined risk windowReconciliation results comparing authoritative desired state with target state
Where it commonly goes wrongAccepting a valid document as proof of the presenter, or treating in-person as automatically sufficientUsing an email address as the permanent key, or recycling dormant usernamesCloning a peer's entitlements, or deleting the identity before revoking downstream credentialsReading a successful provisioning message as end-to-end consistency

Decision tree

Harm if the wrong person enrolls? Low Moderate High IAL1 one validated piece of evidence, any proofing type IAL3 on-site attended only, biometric collected and kept Must it run with no agent attending? Yes No Evidence captured through a camera? IAL2, attended remote video session with an agent, or on-site with an agent Yes No IAL2, remote unattended add genuine-sensor confidence, protected channel, forgery analysis IAL2, on-site unattended CSP-controlled kiosk or managed workstation Every path, whatever the level notify proofing to a validated address, protect authenticator binding, document exception and redress routes

Cheat sheet

  • Identity proofing resolves, validates, and verifies a claimed identity
  • Select identity proofing rigor from the impact of an enrollment error
  • Identity proofing and authentication establish different assurances
  • Equivalent proofing paths should preserve assurance while improving access
  • Successful proofing must end in a protected subscriber-account binding
  • Remote proofing must detect injected and forged media
  • Identity assurance levels increase evidence and process rigor
  • Proofing exceptions require governed evidence and redress
  • Use an immutable internal identifier as the durable identity join key
  • Retired identifiers should not be reassigned where history must remain attributable
  • Identifier uniqueness is required within every relying collision domain
  • Services, processes, devices, and components need attributable identities
  • Use pairwise pseudonymous identifiers when cross-service correlation is unnecessary
  • Authoritative business events should drive identity-state changes
  • Birthright access should be limited to an approved role baseline
  • Mover workflows must remove obsolete access as well as add new access
  • Leaver access must be disabled at the risk-defined termination boundary
  • Provisioning requires reconciliation, not only event delivery
  • Each identity attribute needs a designated authoritative source
  • A directory supplies identity data but need not decide access policy
  • External identities require sponsorship and lifecycle accountability
  • Workload identities need machine-oriented lifecycle controls
  • Lifecycle state changes should preserve attribution history

Unlock with Premium — includes all practice exams and the complete study guide.

Also tested in

References

  1. ISSAP Certification Exam Outline
  2. NIST SP 800-63-4, Digital Identity Guidelines Whitepaper
  3. NIST SP 800-63A-4, Digital Identity Guidelines: Identity Proofing and Enrollment Whitepaper
  4. NIST SP 800-63-3, Digital Identity Guidelines (Revision 3) Whitepaper
  5. NIST SP 800-53 Rev. 5, Security and Privacy Controls for Information Systems and Organizations Whitepaper
  6. NIST SP 800-63C-4, Digital Identity Guidelines: Federation and Assertions Whitepaper
  7. Develop a SCIM endpoint for user provisioning to apps from Microsoft Entra ID
  8. What is automated app user provisioning in Microsoft Entra ID
  9. NIST CSRC Glossary: authoritative source
  10. Active Directory Domain Services overview