02 — Capability · BC-760.20
Identity & Access Management
Know who and what is accessing enterprise systems, grant only the access each needs for as long as they need it, and make privileged access rare, recorded and reviewed.
- IAM
- Access Control
- Identity Governance
In scope
- Identity lifecycle from joiner to leaver
- Authentication and single sign-on
- Access requests with certification and revocation
- Privileged and machine identity control
Out of scope
- HR system of record for employees (see BC-360)
- Customer account registration flows (see BC-460)
Realized by · 10
- SAP S/4HANA · Governance, Risk and Compliancepartial via BC-760.20.30
- Microsoft 365 · Microsoft Entra IDstrong via BC-760.20.10
- Oracle Fusion Cloud Applications · Risk Management and Compliancepartial via BC-760.20.30
- Okta · Universal Directorycore via BC-760.20.10
- Okta · Single Sign-Oncore via BC-760.20.20
- Okta · Adaptive Multi-Factor Authenticationcore via BC-760.20.20
- Okta · Lifecycle Managementstrong via BC-760.20.10
- Okta · Identity Governancepartial via BC-760.20.30
- Okta · Privileged Accessemerging via BC-760.20.40
- Okta · Customer Identitystrong via BC-760.20.20
Used in · 2
Build it · 6
Decomposes into · 4
- BC-760.20.10Identity LifecycleCreate, change and remove identities as people and systems join, move and leave, driven from authoritative sources rather than tickets.
- BC-760.20.20AuthenticationVerify identities with strength proportional to the risk, through single sign-on and multi-factor methods users will actually tolerate.
- BC-760.20.30Access GovernanceGrant access by role, review it on a cycle with the people who own the data, and remove what is no longer justified.
- BC-760.20.40Privileged Access ManagementVault, broker and record administrative access so it is granted just in time, used under observation and withdrawn when done.