FI Finnish
SE Swedish
FR French
PL Polish
DE German
US English (US)

Contact Us

If you still have questions or prefer to get help directly from an agent, please submit a request.
We’ll get back to you as soon as possible.

Please fill out the contact form below and we will reply as soon as possible.

English (US)
FI Finnish
SE Swedish
FR French
PL Polish
DE German
US English (US)
  • Log in
  • Home
  • Identity Governance and Administration (IGA)
  • IGA solution library
  • Processes and use cases
  • Use case library
  • Access right management

Automation: De-Provisioning

Contact Us

If you still have questions or prefer to get help directly from an agent, please submit a request.
We’ll get back to you as soon as possible.

Please fill out the contact form below and we will reply as soon as possible.

  • Service Management
    Matrix42 Professional Solution Matrix42 Core Solution Enterprise Service Management Matrix42 Intelligence
  • Identity Governance and Administration (IGA)
    IGA overview IGA solution library
  • Platform
    ESM ESS2 ESS Efecte Chat for Service Management Integrations Add-ons
  • Release Notes for M42 Professional, IGA, Conversational AI
    2026.1 2025.3 2025.2 2025.1 2024.2 2024.1 2023.4 2023.3 2023.2 2023.1 2022.4 2022.3 Release Information and Policies
  • Other Material
    Terms & Documentation Guidelines Accessibility Statements
  • Services
+ More
    • Service Management

    • Identity Governance and Administration (IGA)

    • Platform

    • Release Notes for M42 Professional, IGA, Conversational AI

    • Other Material

    • Services

Automation: De-Provisioning

This has been combined with provisioning use case. 



De-Provisioning


In this article is described use case for de-provisioning, which is part of several other IGA use cases. 

De-provisioning can happen when 

1. End-user is requesting access right removal from the  Self-Service Portal

2.  End-user is updating user information from the Self-Service Portal

3. User and employment data is received from the source system and there are automated rule for granting access rights

4. Organizational data is received from the source system and there are IGA Automated Rules related to the information. If there are new, updates or removals regarding organizational information also access rights granted based on the information are de-provisioned from the user. 

De-provisioning is ongoing process in the background and it will start based on scheduled time in provisioning task (scheduled-based provisioning task) or based on information received from the source system. 



Use Case Description

Panel content


 

Description

Overview

This use case describes use cases, where de-provisioning is used and how IGA admins can report and audit information received from the directories or source systems.

Operators

IGA solution
IGA Admin
Directory
Source system

Prerequisites

Scheduled-based provisioning task needs to be configured and/or integration to the source system needs to be implemented.

Result

De-provisioning is completed successfully or an IGA Admin Task is created to IGA Admin for manual handling. 

Operating chain

  1. Remove access rights

    • If user or manager requests access right removal from the Self-Service Portal, de-provisioning process is started and group memberships are removed


  2. Update user information

    • If users information is updated, either via Self-Service Portal or via source system and IGA Automated rules applies to the changes, users group memberships are provisioned or de-provisioned 


  3. Update to organizational data

    • Manage Organizational Data & Manage Automated Rules use cases needs to be implemented

    • If there is removal of organizational unit, Cost Center or title from the source system, and there are active IGA Automated Rules using that information for access rights, IGA Admin request is created to IGA Admins for manual review


  4. Other views and reports for managing data read from the Customers directory

    • Orphan user accounts (IGA Account without Identity Storage relation)

    • User accounts which last login was made x time ago

    • User accounts with x entitlement and last login was made x time ago

    • User accounts without group memberships

    • User account attributes with different values (for example different first name than spoken name)

    • New entitlements (new group is created into the Customers directory and read to the IGA solution)

    • Open re-certification requests for de-provisioning
Auditing Details IGA Access Right Records are saves according to each relating use case

Related datacards

IGA Identity Storage
IGA Automated Rules
IGA Account
IGA Entitlement

IGA Admin Task

Delete

Configuration changes


In this use case Customer can make following changes, without them having affects to the project schedule or work estimations: 

1. Customer can add applications, which access rights are managed manually (manual provisioning) to be part of de-provisioning 

Delete

Expansion possibilities


1. Add more directories to de-provisioning

Depending which IGA package Customer has chosen, certain number of directories are included, but there can be additional directories, but this will need separate evaluation for estimating needed work days, schedule and contract changes.  

Delete

Relations & configuration instructions


Relations to other use cases, 


Relations to other data cards, 

IGA Identity Storage
IGA Automated Rules
IGA Account
IGA Entitlement

IGA Admin Task

Configuration instructions,

With IGA baseline there is no need to edit workflows or EPEtasks to achieve this use case. Event-based tasks are executing deprovisionings and those are configured in other use cases.

Delete



de-provisioning automation

Was this article helpful?

Yes
No
Give feedback about this article

Related Articles

  • Provisioning & de-provisioning
  • Manage organizational data
  • User Lifecycle Management
  • HR connector

Copyright 2026 – Matrix42 Professional.

Matrix42 homepage


Knowledge Base Software powered by Helpjuice

0
0
Expand