LOGBOOK

HELP

Quiz Entry - updated: 2026.09.17

What are the two categories of provisioning systems?

Central systems, where provisioning requests and changes are executed in directly connected systems, typically (meta-)directory services such as LDAP or Active Directory; and distributed systems, where there is no central identity authority, identity information is distributed according to trust relationships, and each connected system keeps its own user management. Most real deployments combine both.

Central provisioning with a metadirectory driving three systems, and distributed provisioning with four systems synchronising along trust relationships

* Central versus distributed provisioning systems. *

Central provisioning system Distributed provisioning system
Identity authority One central place None
How changes propagate Executed directly in the connected systems Distributed along trust relationships between systems
User management in target systems Consumes the central directory Each system keeps its own
Typical technology (Meta-)directory services: LDAP, Active Directory Point-to-point connectors, peer synchronisation

The central variant is easier to govern (one source of truth, one audit point) but requires that every target can be driven from the centre. The distributed variant tolerates autonomy of the connected systems but makes it harder to answer "who has access to what" at any given moment. Since large organisations always contain both kinds of systems, they end up with a combination.

Go deeper:

From Quiz: IAM / IAM Models: Topologies, Federation and Provisioning | Updated: Sep 17, 2026