LOGBOOK

HELP

Quiz Entry - updated: 2026.09.17

How does the Heidelberg University of Education example illustrate a provisioning architecture?

Several data sources are consolidated in one identity-management (IDM) system, which then provisions the resulting identities to the various identity providers and directory systems.

Four administrative sources consolidated by an IDM system that provisions an LDAP directory, Active Directory and an SSO identity provider serving the applications

* Sources are consolidated in one IDM system, which provisions the directories and the identity provider that serve the applications. *

The pattern has three tiers:

  1. Sources: the administrative systems that know about people (student administration, HR, library, ...), each authoritative for its own population and attributes.
  2. Consolidation: the IDM system merges the records, matches the same person across sources, resolves conflicts and applies rules (which attributes win, which roles follow from which affiliation).
  3. Targets: identity providers and directory services (for instance an LDAP directory and an SSO IdP) receive the consolidated identities and serve the applications.

The reason to consolidate first instead of connecting every source to every target is the same as for hub-and-spoke federation: it turns an n-times-m mesh of connectors into n plus m, and it creates a single place where the rules for a person's identity are decided.

From Quiz: IAM / IAM Models: Topologies, Federation and Provisioning | Updated: Sep 17, 2026