Skip to content
English
  • There are no suggestions because the search field is empty.

User Management Procedure

This document outlines the standard procedure for creating, modifying, disabling, and deleting user accounts. Following this process helps ensure secure access management, compliance with company policies, and accurate user permissions.


Roles and Responsibilities
 Requester: Submits the request for user account creation, modification, or removal.
 Manager: Approves the request and validates the required level of access.
 IT Service Desk: Processes the request and performs the necessary account
administration.
 System/Application Owner: Approves application-specific access where required.


User Management Process
1. New User Creation
1. Receive a user creation request through the approved ticketing system.
2. Verify manager approval.
3. Confirm the user's required access and permissions.
4. Create the user account in the relevant systems.
5. Assign security groups and application access based on the approved request.
6. Configure email, MFA, and any required licences.
7. Notify the requester once the account is ready.


2. User Access Modification
1. Receive a request detailing the required access changes.
2. Verify manager or application owner approval.
3. Review the user's current permissions.
4. Add, modify, or remove access as approved.
5. Validate that access changes have been successfully applied.
6. Update the service ticket with the completed work.


3. User Deactivation
1. Receive notification from HR or the user's manager.
2. Disable the user account immediately on the employee's last working day or as
instructed.
3. Revoke access to all systems, applications, VPN, and email.
4. Remove the user from security groups.
5. Document the actions taken in the service ticket.


4. User Deletion
1. Confirm that the account retention period has expired.
2. Verify that all required data has been retained or transferred.
3. Permanently delete the user account according to organisational policy.
4. Update the service ticket and close the request.


Access Approval Requirements
 Manager approval is required for all new accounts and access changes.
 Application owner approval is required for privileged or restricted systems.
 Administrative access requires additional authorisation in accordance with security
policies.


Security Guidelines
 Enforce Multi-Factor Authentication (MFA) where applicable.
 Apply the Principle of Least Privilege.
 Review user access periodically.
 Disable inactive accounts in accordance with company policy.
 Never share user credentials or passwords.


Validation Checklist
 User identity verified.
 Required approvals obtained.
 Correct permissions assigned.
 MFA configured (if applicable).
 Request documented and closed.


Related Documents
 Access Control Policy
 Password Policy
 Information Security Policy
 Joiner, Mover, Leaver (JML) Process
 Identity and Access Management (IAM) Standard