Ensure digital operational capability with Nubus for Business Continuity – sovereign IAM in standby mode.

Learn more
The right access. From the first day to the last.

User Lifecycle Management

  • Onboarding, role changes, offboarding – automated.
  • Centralized across all systems.
  • Less manual effort, more security.
User-Lifecycle-Management mit Nubus
The Challenges

When the Lifecycle Is Not Managed, Risk Arises.

Without end-to-end User Lifecycle Management, security, compliance, and operational risks arise across the entire IT landscape. Identities remain active even though they are no longer needed, permissions accumulate over time, and changes have to be reproduced manually in multiple systems.

01

Security Risks Through Ghost Accounts

Accounts remain in place even though people have long since left the organization. As a result, former employees or teachers can continue to access applications and data, whether intentionally or unintentionally.
02

Compliance Risks Through a Lack of Data Control

User accounts that are not deactivated or deleted contradict the principle of data minimization. Requirements such as GDPR and the right to be forgotten are therefore difficult to implement reliably.
03

Operational Effort and Sources of Error in Everyday Work

The manual management of user accounts leads to lost time and errors. Even small oversights, for example during role changes or departures, cause permissions to remain in place.
The Solution

Nubus Manages the Entire User Lifecycle Centrally

Nubus extends classic Identity & Access Management solutions with complete control over the user lifecycle. From automated creation through all role and access changes to the removal of identities across all connected systems, the entire process remains centrally managed and traceable.

  • End-to-End Synchronization Across All Systems

    Changes to identities and roles are automatically applied to all connected applications - consistently, without manual follow-up maintenance or system breaks.

  • Consistent Offboarding Without Ghost Accounts

    When an identity is removed, all associated access rights are deactivated simultaneously across all systems.

  • Flexibly Integrable Into Existing IT Landscapes

    Nubus can be operated as a Kubernetes solution or as a virtual machine in classic UCS environments, adapting to different operating models and migration strategies.

User Lifecycle Managemenr grafik EN
Nubus vs. Keycloak

Why Authentication Alone Is Not Complete User Lifecycle Management

Keycloak reliably manages authentication, but in User Lifecycle Management, this responsibility ends at the system boundary. This is exactly where Nubus comes in, extending pure authentication with end-to-end control of the entire user lifecycle across all connected systems.

The Limits of Keycloak

  • Focus on authentication and login processes
  • No end-to-end control of permissions in target systems
  • Deleted accounts do not automatically take effect in connected applications
  • Risk of remaining access rights (“orphaned permissions”)

The Extension Through Nubus

  • Complete lifecycle control across all connected systems
  • Automatic offboarding in applications such as Nextcloud, Open-Xchange, or M365
  • Consistent implementation of role and permission changes across systems
  • Reduction of manual rework and integration effort

The Three Phases

Every Digital Identity Has a Clear Lifecycle

Nubus ensures that every identity is managed consistently – from the first access to deactivation. What matters is that these steps are controlled end to end and implemented across systems.

The First Day Counts

New employees or teachers need to be able to work from day one. This includes not only user accounts, but also roles, groups, and access to applications.

  • Create digital identities automatically
  • Provide access to mail, calendar, and applications immediately
  • Assign roles and groups consistently
  • Reduced manual effort for IT teams

Permissions Change Over Time

Tasks, departments, and responsibilities change regularly. These changes must also be reflected in the permissions.

  • Central adjustment of roles and permissions
  • Changes take effect in all connected systems
  • Prevention of permission accumulation
  • Traceable and consistent management

The Last Click

When people leave the organization, all access must be removed reliably.

  • Central deactivation of all access
  • No remaining accounts in individual systems
  • Reduction of security and data protection risks
  • Unified process across all applications
FAQ

Frequently Asked Questions About User Lifecycle Management With Nubus

Answers to the most important questions about managing digital identities from onboarding and offboarding to role changes to automation, compliance, and integration.

User Lifecycle Management describes the management of digital identities across their entire lifecycle from the creation of a user account through role and permission changes to deactivation or deletion when leaving the organization.

Nubus creates digital identities automatically and assigns roles, groups, and access to applications centrally. This makes the required systems and services available from day one.

Yes. Roles, groups, and access rights can be managed centrally and assigned automatically. This reduces recurring administrative tasks and avoids errors.

Through the central management of roles and permissions, access remains traceable and consistent. Outdated permissions can be removed automatically, so that no unnecessary rights accumulate.

Ghost accounts are user accounts of former employees or teachers that are still active. They represent a security and compliance risk, as they can still be used to access systems and data.

Nubus can centrally manage identities and permissions for numerous applications – for example, for collaboration platforms, email systems, cloud services, or specialized applications.

Personal data and access rights must not remain in place indefinitely. A well-defined offboarding process reduces risks and supports the implementation of requirements such as data minimization and the right to be forgotten.

Yes. Existing LDAP directories, Microsoft Active Directory, and other identity sources can be connected via connectors and standards.