Systems · Concept · 10 min read

Provisioning: Creating the Account Is the Easy Third

Provisioning is one moment in a resource that lives for years. The two jobs on either side of it, keeping it correct and taking it away, are the ones without a tool behind them.

Written by Marko Ristic, Editor Updated Sep 17, 2026
3Jobs in the life of a resource, and automation reliably covers one
404What a SCIM provider must return for a deleted user, even if it kept the record
2015When the IETF published SCIM, as RFC 7643 and RFC 7644
2Teams that own user provisioning, because the leaver signal lives in HR
Short answer

Provisioning is creating a resource and handing it over ready to use: a server, a user account with its access rights, a network port, a cloud resource, a seat in a SaaS application. It happens once.

What the usual definition leaves out is that the resource then has to stay correct for years, and one day the access has to be taken away, and those are two separate jobs with two separate sets of tools.

Onboarding is automated in most organizations; drift and offboarding usually are not, which is why a company with excellent provisioning still has machines that no longer match their own standard and accounts belonging to people who left months ago.

  • Provisioning creates the resource, once, and then finishes
  • Configuration management is what keeps it correct, and it never finishes
  • Deprovisioning is the third job, and it is usually a checklist
  • User provisioning between applications runs on SCIM, an IETF standard
  • The word means something different in telecom and in accounting
On this page

Three jobsCreate, keep correct, remove

Provisioning is a moment. Everything that follows it is not.

Ask what is provisioning and the usual answer is the process of setting up IT infrastructure, meaning servers, devices, software, data storage and network components, and giving users and systems access to it. That provisioning definition is accurate, and it describes one step. IT provisioning as a job is wider.

A new laptop is provisioned once: imaged, joined to the domain, enrolled, handed over with the access its user needs.

From that afternoon onward it is subject to a different discipline, because applications update themselves, users install things, policies change and somebody eventually disables a security setting to make a printer work. Keeping the machine matching its own standard is configuration management, and it runs continuously.

Then the employee resigns, and a third job starts. Deprovisioning removes the user access, reclaims the license, wipes or reissues the hardware and closes the accounts.

It is the only one of the three with a deadline set by somebody outside IT, it is the one with the clearest security consequence, and it is the one most likely to be a ticket that gets closed without being done.

JobWhen it runsWhat it ownsTypical tooling
ProvisioningOnce, at the startThat the resource exists and users can access itImaging, infrastructure as code, an identity platform
Configuration managementContinuously, foreverThat it still matches the standardGroup Policy, an endpoint manager, a configuration tool
DeprovisioningOnce, at the endThat access and cost actually stopUsually a checklist, which is the problem

Read the last column. Two of the three rows name a category of automation software and the third names a document. That asymmetry is the subject of this page.

The typesThe types of provisioning, and who owns each

The word takes a modifier and the modifier changes who does the work. This matters because the types of provisioning get discussed as if they were one process with one owner, and in practice they sit in different teams.

TypeWhat is createdWho usually owns it
ServerA physical or virtual machine, with an operating system and the applications for its roleInfrastructure or the platform team
UserA user account, its group memberships and its access rightsIT with human resources, from a hiring record
NetworkSwitch ports, addressing, firewall rules, network access to the segmentThe network team
CloudCloud compute, storage, networking and the applications built on themWhoever writes the infrastructure code
ServiceA seat in a SaaS product, with credentials and entitlementIT, and increasingly whoever owns the budget for it
DeviceA laptop, phone or tablet, enrolled, configured and assigned to a userThe endpoint or desktop team

Server provisioning is the one people picture, and it is the one where automation arrived first. User provisioning is the one that runs weekly in a normal business, which makes it the one where a missing process costs the most, in access nobody meant to grant as well as in time.

Service provisioning is the one that leaks money, because a seat nobody cancels bills every month whether or not anybody signs in.

Device provisioning is the type most users meet first. A new laptop ships from the reseller, enrolls itself in mobile device management at first boot, and pulls its software, policies and security settings based on who signs in. Windows Autopilot and Apple's Automated Device Enrollment are the two common implementations of that zero-touch model.

AutomationAutomated provisioning, and what it saves

Manual provisioning means a technician working through a runbook: build the server, create the user, assign the licenses, set the permissions. It works at small scale and it fails the same way every time. Steps get skipped, two servers built a month apart differ, and a new hire waits days for access.

Automated provisioning replaces the runbook with software. Templates and infrastructure as code define what a server or a cloud environment should look like, and an automation tool builds it on request. For users, an identity system creates accounts and assigns access based on role, department and location, a model called role-based access control.

The benefits the vendors list are real and worth stating plainly.

  • Time. A server that took days of tickets is ready in minutes, and a new user has working access on the first morning.
  • Fewer errors. The same template produces the same system every time, which removes the typing mistakes and forgotten steps of manual setup.
  • Security and compliance. Users get the access their role defines and no more, and every change leaves a record an auditor can read.
  • Scaling. Cloud systems can add and remove servers automatically as demand changes, which is only possible when provisioning needs no human.
  • Cost. Self-service requests replace tickets, and resources created from a template are easier to track and shut down.

Automation does not change the argument of this page. It makes the first job fast and leaves the other two where they were, so the usual result is automated provisioning beside a manual leaver checklist.

DriftWhy the machine stops matching its own standard

This is where provisioning gets confused with configuration management, and the confusion has a cost.

A provisioning tool answers the question does this resource exist. A configuration tool answers the question is it still right. Buy only the first and the answer to the second is whatever it happens to be, which is the definition of configuration drift: the accumulated difference between the infrastructure that was built and the infrastructure running now.

Drift is not dramatic. It is one machine where the update service was disabled to finish a deployment, one firewall rule opening network access at three in the morning, one server never rebooted after a change so it is running a configuration that exists nowhere on disk.

None of these is visible from the provisioning side, because automated provisioning finished successfully months ago and reported so.

The practical test is whether anything in the environment can currently answer this question: which resources no longer match the standard they were built to.

If the honest answer is that somebody would have to go and look, then configuration management is not in place, no matter how automated the provisioning is. This is the same shape of problem as patch management, where a deployment report is a claim and a scan is evidence.

DeprovisioningDeprovisioning, and the account that outlives the employee

Every source will tell you deprovisioning is the reverse of provisioning. That is the wrong way to think about it, because reversing a process implies the process was recorded, and usually it was not.

A user account accumulates access. It gets a group on the first day, another when it covers for somebody, a shared mailbox during a project, access to a SaaS application used twice.

Provisioning created the first of those and nothing owns the rest, so deprovisioning cannot be an inverse of anything. It has to be an audit of what the account can currently reach.

What is left behind when it goes wrong is an orphaned account: a valid credential belonging to nobody, still a member of its groups, still licensed, and still able to authenticate against your systems.

It is a good credential to attack precisely because nobody is watching it, which makes it a standing security exposure rather than untidiness. Nobody will report the login as suspicious, because there is nobody left to notice.

Two things reduce it, and neither is a tool purchase. The first is that the leaver signal comes from the human resources system rather than from a manager remembering, which is why user provisioning is a joint process rather than an IT one.

The second is a periodic reconciliation between the people who work here and the user accounts that exist, which finds the access the leaver process missed.

SCIMHow user accounts actually move between systems

The mechanism deserves naming, because it is a published standard rather than a vendor feature, and knowing it changes what you can ask a supplier for.

SCIM is the System for Cross-domain Identity Management, published by the IETF in September 2015 as two standards track documents: RFC 7643 defines the schema and RFC 7644 defines the protocol.

It is HTTP based, and it exists so that an identity provider can create and remove users in a cloud application without either side writing a custom integration. It is what automated user provisioning usually runs on, and SCIM provisioning is the label identity vendors give the feature.

EndpointOperationsWhat it does
/UsersGET, POST, PUT, PATCH, DELETERetrieve, add and modify user accounts
/GroupsGET, POST, PUT, PATCH, DELETERetrieve, add and modify group membership

One detail in RFC 7644 is worth knowing before you assume a deprovisioning job is finished. On a DELETE, the specification says a service provider may choose not to permanently delete the resource, but must return 404 for every operation associated with it and must omit it from future query results.

So the standard itself allows a deprovisioned user to keep existing inside the application. What is guaranteed is that the resource stops being found, not that it stops being stored.

PitfallsWhere people go wrong

Buying a provisioning tool to solve a drift problem. Automated provisioning will build correct resources quickly and will not tell you anything about the ones built last year. Those are different products because they answer different questions.

Treating deprovisioning as the reverse of onboarding. User access accumulates from sources the onboarding process never touched. Running it backward removes only the access it granted.

Letting the leaver signal come from a manager. Managers are busy and departures are awkward. The signal that scales is the one that already exists in the human resources record, which is also the one that has a date attached.

Assuming a deprovisioned SaaS user stops costing money. Removing access and releasing a license are two actions, and only one of them appears on the invoice.

Confusing the word across industries. In telecom, provisioning means turning on service for a subscriber, such as assigning a phone number. In accounting, a provision is a liability of uncertain timing or amount, which is a different subject entirely and shares only the word.

Never reconciling accounts against people. Without that comparison, the offboarding process reports on itself, and a process that reports on itself is the one that quietly stops working.

THE LIFE OF ONE USER ACCOUNTThree jobs, three spans of time, and only one of them is reliably automated.Provisioningautomated in most organizationsConfigurationmanagementruns continuously, and often is not automatedDeprovisioningusually a checklist, not a systemday onethey leaveorphanedaccount,still worksThe exposure is not at the start. Creating the account is the part with a tool behind it.It is the credential that still authenticates after nobody is using it.
The three jobs do not cover equal spans, and the one at the end is the one without a tool behind it.

ComparisonProvisioning, configuration management and deployment, side by side

CriterionProvisioningConfiguration managementDeployment
WhenOnce, at creationContinuouslyEvery release
Question it answersDoes this resource existIs it still correctIs the new version live
Failure looks likeA request that never completedDrift nobody can seeA broken release
Owns costYes, it starts the billingNoNo
Has an end stateYesNo, by designYes, per release
Usually automatedYes, for servers and cloud infrastructureSometimesYes

The row that decides the tooling argument is the fifth. Configuration management has no end state on purpose, so a tool built to finish and report success is the wrong shape for it.

FAQFrequently asked questions

What is provisioning?

Creating a resource and making it available to use: a server, a user account, a network port, a cloud resource or a seat in a SaaS application. It is the setup step, and it happens once per resource.

What does provisioning mean in IT?

Setting up the infrastructure and the access that somebody needs in order to work. It covers the machine, the user account, the permissions and the applications, depending on which type of provisioning is meant.

What is the difference between provisioning and configuration?

Provisioning creates the resource. Configuration management keeps it matching the standard afterward. Provisioning happens once and finishes. Configuration management runs continuously and never does.

What is user provisioning?

Creating a user account with the group memberships and access rights the role needs, usually driven by a hiring record rather than by a request. Revoking that access is deprovisioning.

What is deprovisioning?

Removing the access, licenses and user accounts a person or system had. It is the third job after creating and maintaining, and it is the one most often left to a checklist, which is why it is also a security problem.

What is an orphaned account?

A valid account belonging to nobody, left behind when deprovisioning was incomplete. It can still authenticate, still holds its group memberships and is usually still licensed.

What is server provisioning?

Setting up a physical or virtual machine and bringing it to a working state: the operating system, the applications for its role, and its connections to network and storage resources.

What is cloud provisioning?

Creating the compute, storage and networking resources in a cloud environment and then the services and applications that run on that infrastructure, usually through code rather than a console.

What is SCIM provisioning?

User provisioning that runs over SCIM, the System for Cross-domain Identity Management, defined by the IETF in RFC 7643 and RFC 7644. It lets an identity provider create and remove accounts in a cloud application over HTTP.

Does deprovisioning delete the account?

Not necessarily. RFC 7644 allows a service provider to keep a deleted resource as long as it returns 404 for it and leaves it out of query results. Access ends; storage may not.

Is provisioning the same as deployment?

No. Provisioning creates the resource. Deployment puts a version of software onto it, and it happens again with every release.

Who is responsible for user provisioning?

IT and human resources together in practice, because the trigger for both joining and leaving lives in the human resources record rather than in a ticket.

What does provisioning mean in telecom?

Turning on service for a subscriber, such as assigning a phone number or activating a line. Same word, different industry, and it is one reason a search for the bare term returns a mixture.

What is a provision in accounting?

A liability of uncertain timing or amount. It is an unrelated meaning that shares the root word, and it explains part of the search volume for the term.

Read next · Directory and identity Active Directory Explained Where the user account being provisioned actually lives on a Windows network, and what its group memberships mean. Open this next15 min
Also worth reading
One packet a weekA short, illustrated explainer every Tuesday. No vendor pitches, unsubscribe in one click.