THE SAFEHOUSE / JOURNAL
Identity Management · Part 6 of 7

Identity Lifecycle Management: Automating Access from Hire to Exit

11 May 2025· 3 min read

Welcome back to the sixth post of the Identity Management series, tackling the most essential — yet often neglected — piece of Identity Management: Identity Lifecycle Management (ILM).

Whether you're managing Windows Servers, Azure AD environments, or mixed infrastructures, understanding ILM will help you eliminate manual mistakes, automate compliance and streamline operations.

What is Identity Lifecycle Management?

Identity Lifecycle Management (ILM) refers to the end-to-end process of creating, managing and deleting user identities as they progress through their lifecycle:

  1. Onboarding (Joiners)
  2. Movement (Movers)
  3. Offboarding (Leavers)

Done right, ILM ensures users have the right access at the right time, no orphaned accounts after someone leaves, and reduced security risks and audit gaps.

1. ILM in Windows Server (Active Directory)

Onboarding (Joiners): use PowerShell scripts or HR system triggers to create users automatically, and assign them to the right Organizational Units (OUs) and security groups.

New-ADUser -Name "New Hire" -GivenName "New" -Surname "Hire" -SamAccountName "new.hire" `
  -UserPrincipalName "new.hire@yourdomain.com" -Path "OU=Dev,DC=yourdomain,DC=com" `
  -AccountPassword (ConvertTo-SecureString "Temp@1234" -AsPlainText -Force) -Enabled $true

Movers: automate role-based group changes using group membership automation or scripts, and move users between OUs using policies for access control and GPO enforcement.

Move-ADObject -Identity "CN=User Name,OU=Dev,DC=yourdomain,DC=com" -TargetPath "OU=Managers,DC=yourdomain,DC=com"

Offboarding: disable account immediately and move to a "Disabled Users" OU, schedule account deletion and home folder cleanup, and log actions for audits.

2. ILM in Azure Active Directory

Azure AD offers cloud-native, policy-driven automation.

Onboarding: Dynamic Groups assign licenses, apps and roles based on user attributes (e.g., department = 'Engineering'). Provisioning from HR systems (e.g., Workday) using SCIM (System for Cross-domain Identity Management).

Movers: changes in department, title, or location auto-update a user's group membership and access; Conditional Access adapts based on updated user risk or device compliance.

Offboarding: immediate account block via Azure AD portal or Graph API, use Access Reviews to clean up group memberships, and trigger Just-In-Time (JIT) access removal workflows with Microsoft Entra ID Governance.

# Disable a user in Azure AD
Set-AzureADUser -ObjectId "user@domain.com" -AccountEnabled $false

3. ILM in Linux Server (OpenLDAP or Integrated with AD)

Linux ILM typically ties into AD or OpenLDAP.

Onboarding: if integrated with AD, accounts are auto-available via SSSD/realmd. For OpenLDAP, use ldapadd scripts or tools like FusionDirectory to create users.

sudo ldapadd -x -D "cn=admin,dc=example,dc=com" -W -f new_user.ldif

Movers: update user attributes via ldapmodify, and map LDAP groups to sudoers or access policies.

Offboarding: use ldapdelete or AD user disablement to revoke access, and monitor Linux auth logs for last login — useful for determining inactive users.

Best Practices for ILM

Wrapping Up

Identity Lifecycle Management is more than user creation — it's a strategic capability that ensures security, compliance and efficiency across your IT environment, whether in the cloud or on-prem. Start small: automate onboarding, then build toward full lifecycle automation.

Related reading