An organization is designing an automated identity lifecycle architecture to synchronize user identity state between its cloud-based HR system and its central Identity Provider (IdP). Which of the following requirements must be implemented within this architecture to support secure automated user provisioning and real-time deprovisioning? (Select TWO).
- Implementation of standardized System for Cross-domain Identity Management (SCIM) service endpoints to automate identity schema operations between systems.Cevap
- Deployment of centralized session revocation mechanisms to invalidate active tokens and application access upon user status change signals.Cevap
- CReliance on internal perimeter firewall rules to filter resource requests from terminated employees while keeping active identity tokens intact.
- DPrompting users to re-enter primary authentication credentials for each granular API call to evaluate resource entitlement boundaries.
Cevap
Standardized System for Cross-domain Identity Management (SCIM) endpoints must be implemented for automated identity schema operations, along with centralized session revocation mechanisms to invalidate active application tokens upon deprovisioning.
Automating identity provisioning between HR platforms and centralized Identity Providers requires SCIM service endpoints to standardize user schema updates and deprovisioning calls across multi-tenant applications. Furthermore, to prevent unauthorized access via active sessions after account suspension, the architecture must incorporate centralized token and session revocation capabilities across all downstream relying parties.
Adım Adım Çözüm
Anahtar Kavram
Automated Identity Lifecycle & Provisioning Architecture
Tahmini Süre:1m 30s