← SC-300: identity, access, and operations
06 / 11 · 35 MIN

Privileges, packages, and lifecycle

Connect temporary need with approval, expiry, and execution.

Concept and mechanism

Identity governance tracks who should receive access, why, for how long, and how it is removed. PIM controls eligible-privilege activation and configures conditions such as duration and approval. Settings are associated with the role; changing duration is not necessarily an exception only for the next request. Assess affected assignments. The mechanism also needs a workable operational design. If all necessary administrators are eligible, none active, and approval depends on an unavailable active approver, circular dependency can arise. Current documentation identifies this risk. Protected and validated emergency access belongs in the recovery design with monitored use.

Guided application

In a fictional migration project, a supplier needs several resources for six weeks. Entitlement management groups access in an access package and defines request, approval, and lifecycle policies. Confirm included resources, owners, conditions, and expiry effects. Lifecycle workflows handles joining, moving, and leaving through tasks and conditions. Automation based on an HR date depends on that attribute’s presence and quality and on the scope selecting people. Test missing-data cases, role changes, and failed tasks. Project objectives should include execution evidence, support capability, and exception handling. A diagram naming features does not demonstrate that a worker received, retained, or lost correct access on the required date.

IN PRACTICE

A joiner task cannot correctly select a missing date; start by validating data and condition.

Common pitfalls

Role settings as individual exception; circular approver dependency; package as link list; workflow as execution proof.

Related topics: Tenant, scope, and objects · Hybrid identity and partners · Methods and emergency access

Take this idea with you

Design granting and removal with data, authority, and execution capability.

Create account

Reference: Entitlement management · SC-300 objectives effective 2026-04-27; product documentation reviewed 2026-10-01; 2026-10-28 English update compared separately