Share via


2.7.2 Identity Lifecycle Management

The use cases in this category represent the management of accounts in the Active Directory system. These accounts are used to gain access to the Active Directory system. An account's lifecycle begins with its creation. After it is created, an account can be used to access the system and perform other operations based on the account's access-control rights. Accounts can be modified to change the state or attributes of the account. When accounts are no longer needed, they can be deleted. An account is a directory object, for example, a user object, so these use cases represent a specialization of the use cases in the Object Management category (section 2.7.1).

Note These use cases are applicable only to AD DS; they are not applicable to AD LDS.

The following use case diagram shows the use cases of identity lifecycle management.

Use cases for identity lifecycle management

Figure 13: Use cases for identity lifecycle management