Here’s a detailed breakdown of ITIL’s core principles as they relate to Identity and Access Management (IAM) — including both the foundational ITIL guidance and the typical process flow/steps IT departments use to manage identity and access securely and efficiently.
ITIL Core Principles (Applied to IAM)
ITIL v4 promotes 7 guiding principles that can be applied to any IT service management process — including IAM.
ITIL Principle Application to Identity & Access Management
IAM Process Objectives
The purpose of Identity and Access Management within ITIL is to:
Ensure authorized users have appropriate access to systems and information.
Prevent unauthorized access or misuse of credentials.
Maintain traceability for compliance and audits.
Support business continuity by managing identity lifecycles efficiently.
IAM Process Steps (ITIL-Aligned)
1. Identity Creation (Provisioning)
Goal: Establish user identity within the organization.
Key Activities:
HR or manager triggers onboarding via Service Desk or HRIS.
Create identity in directory (Active Directory, Azure AD, Okta, etc.).
Assign baseline access per role (RBAC).
Outputs:
New user credentials, assigned system access.
2. Access Request Management
Goal: Grant additional or temporary access securely.
Key Activities:
User submits access request via ITSM tool (ServiceNow, Summit, Jira, etc.).
Approval workflow follows least privilege and SoD (Segregation of Duties).
System automatically applies access rights via provisioning tools.
Outputs:
Audit-tracked approval and access assignment.
3. Authentication & Authorization
Goal: Ensure users are who they claim to be and can access what they’re entitled to.
Key Activities:
Enforce MFA/SSO (Okta, Azure AD, Google Workspace, etc.).
Apply conditional access policies (device type, IP, time of day).
Use role-based or attribute-based access control models (RBAC/ABAC).
Outputs:
Secure login sessions and verified user actions.
4. Access Review & Recertification
Goal: Periodically confirm access is still valid and appropriate.
Key Activities:
Managers and system owners review access lists quarterly or semi-annually.
Identify dormant or unnecessary accounts.
Revoke or adjust access as needed.
Outputs:
Updated access records, compliance reports.
5. Identity Termination (Deprovisioning)
Goal: Immediately revoke access upon role change, transfer, or separation.
Key Activities:
Triggered automatically from HR or Service Desk.
Disable or delete accounts across all integrated systems.
Archive or transfer data per retention policy.
Outputs:
Confirmed account disablement and audit log entries.
6. Monitoring and Auditing
Goal: Detect anomalies, policy violations, or unauthorized access.
Key Activities:
Collect logs from IAM, SSO, and privileged access systems.
Review access events via SIEM or analytics tools (Splunk, Sentinel, etc.).
Report to Security and Compliance teams for follow-up.
Outputs:
Audit trail, incident response documentation.
Common ITIL Roles Involved
Supporting ITIL Practices
Summary