IAM Decommissioning
IAM decommissioning is the controlled retirement of an identity platform or component once the usage it supported has genuinely moved elsewhere.
- Synonym
- platform retirementsunsetting
Definition
Decommissioning an IAM component means methodically checking several conditions: migrations are complete, applications are actually switched over rather than merely declared so, useful data is retained for the applicable periods, technical accounts, secrets and certificates are revoked or taken over, inbound and outbound flows are removed, hidden dependencies are identified, audit needs are covered, rollback procedures have reached their end date and access that is no longer needed is removed. Decommissioning is a project phase in its own right, with its own tests and exit criteria.
Why it matters
As long as the old system stays alive, the organisation carries two attack surfaces, two sets of rules and two cost lines.
The Ariovis perspective
A migration is not finished when the new platform goes live: it is finished when the old one is no longer needed. Keeping two systems alive indefinitely out of caution eventually increases risk — duplicated flows, diverging rules, cost, fragmented skills and ambiguous ownership.
Common pitfalls
- A common mistake is switching off an old platform without identifying the residual consumers that were still silently calling it.
Resources
Explore this category
These concepts matter most inside a real project.
The first conversation helps establish your context, the systems involved and the next useful decision.