4.1 Configuring Lifecycle Manager
Key Takeaways
Lifecycle Manager is licensed separately and is configured on gear icon > Lifecycle Manager, which has the Configure, Business Processes, and Identity Provisioning Policies tabs.
The Configure tab controls request priorities, account group management, full text search, role and entitlement request options, identity creation, Manage Accounts actions, password options, and batch request approval.
Only applications listed under account-only requests or additional account requests allow those request types.
IdentityIQ System Administrators can make any request regardless of the LCM configuration.
Who can request for whom, and what they can request, is controlled by QuickLink populations, not by the Configure tab.
Configuring Lifecycle Manager
Objective 2.1 asks you to know how to configure Lifecycle Manager. Lifecycle Manager (LCM) is the IdentityIQ module for self-service access requests, account management, password management, identity creation and editing, and lifecycle events. It is sold as a separate license and must be purchased and activated before it appears.
What Users Can Do With LCM
LCM actions are offered as QuickLinks and cards on the Home page:
| Action | What it produces |
|---|---|
| Request Access | Role and entitlement requests. For a single user, a Current Access tab lets you request removals. |
| Manage Accounts | Requests for new accounts, deletion, disable/enable, and unlock |
| Create Identity / Edit Identity | Provisioning plans that create or update an IdentityIQ identity from a form |
| Manage Passwords | Password changes and resets on target applications |
| View Identity | Read-only; no provisioning |
In a typical configuration, managers request for their direct reports, Help Desk users request for themselves and others, and any user requests for themselves. Self-service ("request for me") does not include Create Identity. System Administrators can make any request regardless of LCM settings.
The Three Configuration Tabs
Open gear icon > Lifecycle Manager.
1. Configure Tab
General options
- Enable requesters to set request priorities. Without it, every request is Normal priority.
- Enable Account Group Management allows account groups to be provisioned through LCM requests.
- Enable Full Text Search speeds up request pages. The Full Text Index Refresh task must run before it works. You can also set the index directory and automatic index refresh.
- Allow Searching by Population / by Identity when requesting access. This powers "what do people like me have?" searches.
- Maximum number of results and maximum selectable users in Request Access.
- Applications that support additional account requests – only these applications let a requester create a second account or choose which existing account receives an entitlement.
Request Role Options and Request Entitlement Options
- Which role types can be requested. Types that are not selected cannot be requested by anyone.
- Minimum percentage of a population that must hold a role or entitlement before it appears in population-based searches.
- The maximum number of identities returned when searching entitlements by identity.
Create Identity Options
- Require password on all identity creation requests.
- Enable self-service registration, which adds a registration link to the login page. The LCM Registration process must have its approvers configured. The default approver is the Security Officer (
securityOfficerName), with the system administrator as fallback. - URL of the action button after successful registration.
- Prevent pruning of new identities for this many days. The default is 30.
Manage Account Options
- Which Manage Account actions are enabled: Delete, Disable, Enable, and Unlock.
- Applications that support account-only requests, meaning accounts not tied to a role or entitlement.
- Auto-refresh of account status, with a list of applications excluded from it.
Manage Password Options
- Enable password auto-generation when requesting for others.
- A Password Validation Rule for new passwords.
Other options
- Batch Request Approver – requires approval before batch requests run (section 5.3).
- AI-Driven Identity Security recommendations on approvals and access requests. These appear only when the AI integration is installed.
- Classifications and elevated access display on roles and entitlements in requests.
2. Business Processes Tab
This tab maps each LCM action to the workflow (business process) that runs it. The defaults are LCM Provisioning for access and account requests, LCM Create and Update for identity creation and editing, LCM Manage Passwords for passwords, and LCM Registration for self-registration. Section 4.3 explains how to change and customize them.
3. Identity Provisioning Policies Tab
This tab defines the forms for Create Identity, Update Identity, and Self-service Registration (section 4.2).
What the LCM Page Does Not Control
A common exam trap is looking for "who can request for whom" on the Lifecycle Manager page. That is set in Global Settings > QuickLink Populations (section 5.2):
- Membership – who belongs to the population
- Who can members request for? – Everyone, or specific users (sharing attributes, reporting to the requester, custom criteria, or an IdentityFilterGenerator rule)
- What can members request / remove? – rules that limit roles, applications, and entitlements
- Which QuickLinks the population sees, such as Request Access, Manage Accounts, or Create Identity
So a complete LCM design combines three places: the Configure tab (what request types exist at all), QuickLink populations (who may use them and for whom), and the Business Processes tab (how requests are approved and fulfilled).
Scenario: Turning on Self-Service for a Pilot Group
A customer wants pilot users to request entitlements for themselves, managers to request for direct reports, and nobody to delete accounts yet. One way to configure it:
- Configure tab: enable full text search (then run Full Text Index Refresh). Leave only the business and IT role types that should be requestable. Under Manage Account Actions, clear Delete and keep Disable, Enable, and Unlock.
- QuickLink populations: give the Self Service population the Request Access QuickLink for themselves only. Give the Manager population Request Access with Report to the requester set to direct reports.
- Business Processes tab: point Request Access at a copied provisioning workflow with manager approval (section 4.3).
- Test: use email redirection (section 3.4) and check the request under Track My Requests or the Access Requests search.
If a requirement does not work, check the right place: missing request types are on the Configure tab, who can do it is in QuickLink populations, and how it is approved is in the workflow.
Users can request new entitlements on the Finance application, but they cannot create a second Finance account for the same identity. Which Lifecycle Manager setting controls this?
The Configure tab's list of applications that support additional account requests
The Identity Provisioning Policies tab's Update Identity policy
The LCM Registration process variables
The Batch Request Approver option
A help desk team must be able to submit access requests for any identity, while ordinary users may request only for themselves. Where is this difference configured?
In QuickLink populations, using the "Who can members request for?" settings
On the Lifecycle Manager Configure tab under General Options
In the LCM Provisioning approvalScheme variable
On the Identity Mappings page
Requesters report that the Request Access page always submits their requests at Normal priority. Which option has not been enabled?
Enable Account Group Management
Enable requesters to set request priorities
Allow Searching by Population when requesting access
Enable automatic index refresh
Full text search was enabled on the Lifecycle Manager Configure tab, but request searches still do not use it. What else must happen?
Import init-lcm.xml a second time.
Grant every user the System Administrator capability.
Enable self-service registration.
Run the Full Text Index Refresh task to build the index.
Sections you finish are checked off in the contents.