E-time | the software company
User onboarding and offboarding: how to automate Identity Lifecycle Management
INDEX
- User onboarding: what it is and why it is essential for productivity
- Identity Lifecycle Management: complete identity lifecycle management
- User offboarding: the most critical phase for cybersecurity
- How to automate user onboarding and offboarding
- Benefits of identity lifecycle automation
- IGA software: identity governance and advanced automation
- Yookey IAM and YooPoint IGA: an integrated identity management platform
User onboarding: what it is and why it is essential for productivity
User onboarding represents the initial phase of the digital identity lifecycle. During this process, the new employee’s identity is created and the necessary access is assigned to allow them to perform their operational activities from day one.
When onboarding is managed manually, organizations may face several challenges: delays in account activation, errors in permission configuration, repetitive tasks for the IT department, and a lack of standardization. These inefficiencies slow down the integration of new employees and reduce productivity, generating operational costs and internal disruptions.
Identity Lifecycle Management: complete identity lifecycle management
Identity Lifecycle Management (ILM) includes the set of processes that govern the creation, updating, and deactivation of digital identities within an organization.
Identity lifecycle management is not limited to initial account provisioning but covers the entire employee journey. It includes access assignment, privilege changes due to role or department changes, periodic compliance reviews, and finally revocation of permissions when employment ends.
A structured approach to Identity Lifecycle Management ensures alignment between business roles, permissions, and security policies throughout all phases of the professional relationship.
User offboarding: the most critical phase for cybersecurity
Offboarding represents the final stage of the identity lifecycle and is often considered one of the most sensitive processes in cybersecurity.
Ineffective account deactivation can leave active users, credentials, and unnecessary privileges in place. These unused accounts, often referred to as orphan accounts, can become an entry point for unauthorized access and data breaches.
Automating access revocation allows organizations to promptly remove privileges, group memberships, and software licenses, significantly reducing exposure risks and improving control over digital assets
How to automate user onboarding and offboarding
Identity lifecycle automation is based on the integration between HR systems, directory services, and identity management platforms.
When a new employee is registered in the HR system, automated workflows can instantly create the digital identity, assign the correct role, and activate the necessary application access. Similarly, when employment ends, the system can automatically revoke access rights, remove permissions, and reclaim assigned licenses.
This approach eliminates most manual tasks, accelerates processes, and ensures consistent enforcement of organizational policies.
Why manual identity lifecycle management is no longer sustainable
Many organizations still manage onboarding, access changes, and offboarding through manual activities, spreadsheets, or non-standardized procedures. This approach increases the risk of human errors and makes it difficult to maintain an up-to-date view of user permissions.
The rise of cloud applications and phenomena such as Shadow IT further complicate access monitoring. As a result, unused licenses, excessive permissions, and forgotten accounts tend to accumulate over time, creating operational inefficiencies, security risks, and compliance issues during audits.
Benefits of identity lifecycle automation
Automating identity management delivers tangible benefits in both operational efficiency and security.
Key benefits include:
- reduction of manual IT tasks
- faster onboarding and offboarding processes
- greater control over enterprise access
- consistent enforcement of the least privilege principle
- reduced risk of unauthorized access
- optimization of software licensing costs
- full audit trails for compliance and reporting
Automation also improves the end-user experience by ensuring timely access to the tools needed to work efficiently.
IGA software: identity governance and advanced automation
Identity Governance and Administration (IGA) platforms enable organizations to control and govern the entire digital identity ecosystem, ensuring that each user has only the access rights required for their role.
IGA software automates key processes such as access assignment, access review campaigns, periodic certifications, and compliance enforcement. With Role-Based Access Control (RBAC), permissions are consistently assigned based on business roles.
More advanced solutions also integrate artificial intelligence and behavioral analytics to detect anomalies, identify excessive privileges, and automatically suggest appropriate access rights.
Yookey IAM and YooPoint IGA: an integrated identity management platform
To achieve full control over the digital identity lifecycle, it is essential to integrate Identity Access Management (IAM) and Identity Governance and Administration (IGA). In this context, Yookey and YooPoint work in synergy: Yookey handles authentication, SSO, MFA, and application access, while YooPoint manages roles, approvals, authorization processes, and compliance.
The integration between the two platforms enables full identity lifecycle automation, from onboarding to offboarding, ensuring that access always aligns with business roles. This approach reduces the risk of unauthorized access, improves compliance, and simplifies identity management within a secure and scalable ecosystem.
Kubernetes: efficiency and scalability for organizations
Kubernetes: what It is and what it’s for
Kubernetes is an open-source platform designed to orchestrate containers and simplify the management of applications and services in an automated and scalable way.
Applications are divided into one or more containers, which Kubernetes groups into pods, the fundamental execution units of the system. Each pod can contain multiple containers that share resources and common settings.
Pods run on nodes, which are physical or virtual machines forming the cluster infrastructure.
Kubernetes automates complex operations and manual processes required for deployment, monitoring, and error management, ensuring that applications remain stable, operational and high-performing at all times.
How a Kubernetes Cluster works
A Kubernetes cluster represents an active instance of the orchestration platform. It is composed of two fundamental elements: the control plane and a set of worker nodes.
The control plane is responsible for managing and maintaining the cluster’s desired state, ensuring that the defined configuration is enforced. The nodes, on the other hand, are the operational units that run the applications and associated workloads.
Administrators define the desired state by specifying which applications should be deployed, which container images to use, the resources to allocate, and the configurations required for the system to function correctly.
Benefits of adopting Kubernetes
Adopting Kubernetes provides significant advantages in managing complex, dynamic and highly scalable IT environments. The main benefits include:
- Efficient management of complex environments:
Kubernetes is particularly suited for scenarios where it is necessary to deploy and manage multiple containers across several hosts, providing centralized and automated control. - Automatic scalability:
The platform dynamically adjusts resource allocation based on workload, ensuring optimal performance and more efficient use of costs. - Separation between development and operations:
It promotes process automation, simplifies collaboration between Dev and Ops teams, and accelerates the application release cycle while maintaining stability in production. - High portability:
Kubernetes can run on various types of infrastructure , from on-premises environments to public and private clouds , ensuring consistency in commands and uniformity in operational processes. This feature allows deployment in any cloud environment, using the same tools and methodologies regardless of the underlying platform.
Yookey: Keycloak managed in SaaS
Yookey is an Identity and Access Management (IAM) solution based on Keycloak, offered as a Software as a Service (SaaS) and fully managed.
The platform provides a secure, constantly updated, customizable, and GDPR-compliant environment, simplifying the management of digital identities.
The service independently manages the entire Keycloak lifecycle combining Keycloak’s native functionalities with the convenience of a ready-to-use solution.
In this way, Yookey eliminates operational complexity for the end user, allowing organizations to focus on their applications without worrying about the underlying infrastructure.
Public Administration and IAM Systems: Security and Access Control
Digital Security in Public Administration: IAM systems for effective access control
Identity and Access Management (IAM) represents a fundamental element of cybersecurity for public administration, where the protection of sensitive data and effective access management play a crucial role.
In this context, within public administration, IAM enables:
- Managing the digital identities of employees and citizens, ensuring that only authorized users can access certain resources.
- Ensuring compliance with data protection regulations, such as the NIS2 Directive or GDPR, through strict access controls.
- Improving operational efficiency by optimizing user provisioning and deprovisioning processes.
Thanks to the automation of identity management, IAM solutions can enhance regulatory compliance, reduce the risks of unauthorized access, and optimize operational processes.
Which sectors can benefit the most from IAM systems
The adoption of Identity and Access Management (IAM) systems can potentially offer significant benefits across various sectors, particularly those that manage critical data and infrastructures.
Some of the sectors that most benefit from these solutions include:
- Public Health
- Protection of healthcare data (electronic medical records, electronic health records).
- Access control for doctors, nurses, and patients in hospital and telemedicine systems.
- Finance and the Revenue Agency
- Managing access to citizens’ and businesses’ tax data.
- Protection of electronic payment systems and government transactions.
- Secure authentication for financial operators and taxpayers via SPID, CIE, and CNS
- Justice and Law Enforcement
- Strict control of access to database.
- Protection of confidential information in courts and law enforcement agencies.
- Secure authentication for all users.
Not only these, but many other sectors also benefit from IAM services, which leverage advanced and more secure methods of authentication and user identification.
Public Administration and NIS2: How IAM Ensures Security and Compliance
One of the main challenges of IAM systems is ensuring services fully comply with evolving regulations in the field of cybersecurity. In this context, IAM systems play a crucial role in enabling public entities to fully adhere to regulations such as the NIS2 Directive.
This support for regulatory compliance is realized through a series of initiatives aimed at ensuring full compliance, including:
- Strong Authentication and Zero Trust Security:
NIS2 requires the adoption of robust authentication measures, such as multi-factor authentication (MFA). In response to this need, IAM systems promote the implementation of the Zero Trust model, which involves continuous verification before every access, ensuring perimeter security and accurate identity management. - Continuous Monitoring and Auditing:
NIS2 compliance requires the management of detailed access logs and the ability to monitor suspicious activities. IAM systems address this need by adopting advanced tools for activity logging and tracking, ensuring continuous surveillance and proactive security management. - Centralized Identity and Access Management:
IAM systems enable centralized control of users, reducing the risk of unauthorized access, and ensuring that public entities comply with NIS requirements, which impose strict access management measures.
Secure Access in Public Administration: Yookey with SPID and CIE Authentication
The NIS2 Directive (Network and Information Security Directive 2) imposes stricter cybersecurity requirements for critical infrastructures and essential services, including the management of digital identities and authentication systems.
Authentication via SPID (Public Digital Identity System) and CIE (Electronic Identity Card) is part of the strategies to meet these requirements, as it ensures strong authentication, thereby reducing the risk of unauthorized access.
Yookey ID, the Keycloak service in SaaS mode, is already configured for authentication through SPID and the Electronic Identity Card, making it easy to implement SPID and CIE authentication on any web service, thus ensuring a quick and secure process.
Explore our solutions
for Identity and Access Management
for Identity and Access Management
Passkey is added to the MFA methods supported by Yookey
Passkey is the alternative to passwords and marks a definitive transition to a new chapter in cybersecurity, this time, Passwordless.
Despite authentication systems having relied on passwords until now, it has become clear over time that while they serve as a security key, they also represent the weak link in account security due to their susceptibility to Phishing attacks.
Passkey is a secure authentication method based on a recognition system (fingerprint, face, PIN, sequence), generated and stored locally on users’ devices.
During the registration process, two keys are created: a public key and a private key, which is encrypted and securely stored on the user’s device. Both keys are required for accessing the account. This mechanism is known as Asymmetric or Public Key Authentication.
Passkey adopts the WebAuthn Standard, or rather, adheres to and implements the technical specifications provided by FIDO2, which include WebAuthn and CTAP (Client to Authenticator Protocol).
WebAuthn Standard
WebAuthn or Web Authentication is the open standard (FIDO2 framework) established by the FIDO Alliance and the World Wide Web Consortium (W3C) with participation from Google, Mozilla, Microsoft, and other major players, upon which Passkey is based.
The WebAuthn API allows servers to register and authenticate users using public key cryptography instead of a password, ensuring that authentication works regardless of the device’s operating system, whether it be Android, iOS, Mac, or Windows.
In most cases, the WebAuthn client that implements the authentication API is a compatible browser (currently supported by all major browsers and Android and Apple devices).
Why is Passkey an effective measure against Phishing?
Passkey is effective against phishing attacks because the unique password is stored locally on the user’s device and is never transmitted over the network.
This means that even if a user is tricked into providing their passkey to a phishing site, cybercriminals will not be able to use it to access their accounts, as the passkey is not valid on other devices. This makes it much more difficult for hackers to compromise user access, thus protecting their personal and financial information.
Passkey and FIDO
The birth of Passkey is closely tied to FIDO (Fast Identity Online), an organization that promotes open standards for strong authentication. The FIDO Alliance comprises key players in the web industry such as Google, Microsoft, and Apple.
FIDO’s main objective is to enhance online security by using more advanced authentication methods, such as biometrics and asymmetric cryptography, aiming to reduce reliance on traditional (static) passwords, which are too vulnerable to theft regardless of their complexity.
The other MFA methods supported by Yookey | Keycloak SaaS
In addition to Passkey, the other MFA methods supported by our Yookey- Keycloak as A Service are:
- Sms and email
- Virtual Authenticator (Microsoft and Google authenticator)
- Physical tokens.
Would you like to know more?
Keycloak: Identity and Access Management solution
Keycloak, an open source solution for IAM Management
Keycloak is an open source software platform for unified identity and access management. It enables companies and organizations to centrally and securely manage the authentication and authorization of their users.
Keycloak is designed to work with modern applications and services. It provides a variety of authentication mechanisms by supporting several protocols, including social login, OAuth 2.0, SAML, and OpenID Connect.
A modern interface and high level of scalability make it the ideal product for those who want to opt for a secure yet highly customizable solution. Now let’s look at its features in more detail.
[INDEX]
Single Sign On (SSO) & Multi-Factor Authentication (MFA)
Keycloak supports Single Sign-On (SSO) allowing users to log in to multiple applications and services using a single set of credentials. This greatly simplifies the login process for users and results in increased security from reducing the number of passwords that must be remembered and managed.
The platform also supports multi-factor authentication (MFA) thus providing an additional layer of security by asking users to provide additional authentication information, (e.g. code sent to their phone) before accessing resources.
Function and installation
It functions as a central authentication server that delegates authentication to external sources and provides access tokens for requesting applications. Regarding the users, the platform provides a division into 3 macro categories that can be managed through a customizable admin dashboard:
- Users: those who can access resources.
- Roles: used to define the access levels of individual users.
- Groups: allow for quick management of the different roles present, creating aggregations between roles and users.
Keycloak supports multiple user stores including LDAP and Active Directory. In this way existing directories can be used for user authentication. Deployment can be on-premise, in the cloud or as a hybrid solution and it provides a flexible architecture with a high degree of scalability.
Features and Benefits
- Single Sign-On (SSO): allows users to access multiple applications and services using a single set of credentials.
- Identity brokering: identity validation using OpenID Connect or SAML 2.0 IdPs.
- Centralized management: customizable interface for managing users, roles and permissions.
- Multi-factor authentication: requires users to provide additional authentication information before accessing resources.
- Directory integration: Integration with LDAP and Active directory for authentication through existing directories.
- Scalability: Easily extendable according to different needs.
Keycloak: integrations
Keycloak has a number of APIs that allow the platform to be integrated with third-party services and systems thus making it an extremely versatile solution created to be integrated into the IT infrastructure of companies of any size.
Keycloak in SaaS
It is possible to have Keycloak as a SaaS solution, with a fully managed service.
Yookey is our product/service that allows you to take full advantage of Keycloak without worrying about the burden of installation and updates, and with the added benefit of a customizable Support.
Yookey ensures maximum security for access and authentication processes with Single Sign-On, and once integrated into your IT environment, no additional effort is required for software operation and maintenance.
For more information about Yookey, visit our dedicated website at this link: Yookey – Keycloak SaaS.







