Account Provisioning Manager Placeholder Onboarding

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The current onboarding processes for new users in organizations are cumbersome and time-consuming, often requiring manual and programmatic steps, leading to new users attempting to access resources before they are fully available, which can result in security breaches and inappropriate access.

Innovation Solution

The implementation of an account provisioning manager that uses placeholder accounts with primary and enhanced work set attributes, where primary attributes enable quick onboarding and enhanced attributes are populated via data propagation, including a just-in-time trigger mechanism to ensure secure and complete provisioned employment status.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional onboarding processes are used, then security and complete provisioning are ensured, but onboarding time increases to days

Engineering Contradiction:
ImprovesecurityVSAvoidonboarding time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system creates placeholder accounts in advance with pre-configured security settings and attributes before users actually need access. This preliminary provisioning allows accounts to be ready immediately when users join, eliminating the time delay while maintaining security through pre-established configurations

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The provisioning process is segmented into essential attributes (created immediately in placeholder accounts) and non-essential attributes (populated later via data propagation). This segmentation allows critical security settings to be in place instantly while non-critical details are filled in asynchronously, resolving the time-security tradeoff

Inventive Principle:
Principle #1Segmentation

2Reliability

If manual onboarding steps are performed, then complete account provisioning is achieved, but process complexity increases

Engineering Contradiction:
Improvecomplete provisioningVSAvoidprocess complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system enables self-service onboarding where placeholder accounts automatically receive essential attributes and security configurations without manual intervention. The account provisioning manager autonomously manages the provisioning process, reducing complexity while ensuring complete provisioning through automated workflows

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

Multiple manual provisioning steps are merged into a single automated process managed by the account provisioning manager. The system combines attribute creation, security configuration, and data propagation into one unified workflow, reducing process complexity while maintaining complete provisioning

Inventive Principle:
Principle #5Merging (Combining)

3Productivity

If users are given early access before full provisioning, then productivity increases, but security risks increase

Engineering Contradiction:
Improveearly accessVSAvoidsecurity breaches
Core Design Contradiction:
ProductivityVSObject-affected harmful factors

Solution Approach 1:

Security settings and essential attributes are preliminarily configured in placeholder accounts before users need access. This ensures that even when users receive early access for productivity, the security framework is already in place to prevent breaches and inappropriate access

Inventive Principle:
Principle #10Preliminary action

4Reliability

If multiple disconnected tasks are required for onboarding, then complete provisioning is ensured, but ease of operation decreases

Engineering Contradiction:
Improvecomplete provisioningVSAvoidonboarding ease
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The account provisioning manager merges multiple disconnected onboarding tasks into a single unified process. Users interact with one system that automatically handles attribute creation, security configuration, and data propagation, ensuring complete provisioning while dramatically improving ease of operation

Inventive Principle:
Principle #5Merging (Combining)

Data Source

PatentUS12074878B2Account provisioning manager
Publication Date: 2024.08.27 MICROSOFT TECHNOLOGY LICENSING LLC
  • US12074878B2 patent drawing
  • US12074878B2 patent drawing
  • US12074878B2 patent drawing

AI summary

An account provisioning manager is disclosed. A placeholder account is generated with a primary work set attribute and a plurality of enhanced work set attributes. Initially, the primary work set attribute is populated with data to convert the placeholder account into an onboarded operating account. Subsequently, the plurality of enhanced work set attributes are populated via data propagation into the onboarded operating account, wherein an enhanced work set attribute of the plurality of enhanced work set attributes is selectively populated in response to a trigger for the onboarded operating account.