What are the two categories of provisioning systems?
Central systems, where provisioning requests and changes are executed in directly connected systems, typically (meta-)directory services such as LDAP or Active Directory; and distributed systems, where there is no central identity authority, identity information is distributed according to trust relationships, and each connected system keeps its own user management. Most real deployments combine both.
* Central versus distributed provisioning systems. *
| Central provisioning system | Distributed provisioning system | |
|---|---|---|
| Identity authority | One central place | None |
| How changes propagate | Executed directly in the connected systems | Distributed along trust relationships between systems |
| User management in target systems | Consumes the central directory | Each system keeps its own |
| Typical technology | (Meta-)directory services: LDAP, Active Directory | Point-to-point connectors, peer synchronisation |
The central variant is easier to govern (one source of truth, one audit point) but requires that every target can be driven from the centre. The distributed variant tolerates autonomy of the connected systems but makes it harder to answer "who has access to what" at any given moment. Since large organisations always contain both kinds of systems, they end up with a combination.
Go deeper:
LDAP (Wikipedia) — the directory protocol behind central provisioning targets.
Active Directory (Wikipedia) — the enterprise directory that is usually the central identity authority.
Metadirectory (Wikipedia) — synchronising identity data between several directories and databases.