Skip to main content

Understand account management responsibilities

DigiCert​​®​​ Trust Lifecycle Manager depends on DigiCert® Account Manager for identity. This split determines where you perform each administrative task.

Task

Performed in

Creating, disabling, and deleting human users

Account Manager

Assigning and removing user roles

Account Manager

Configuring authentication methods, SSO/federation, and MFA

Account Manager

Password and session policy

Account Manager

Account and organization records

Account Manager

Licensing and feature entitlement

Account Manager

Business units and seat allocation

Trust Lifecycle Manager

Certificate profiles, connectors, automation, and certificate operations

Trust Lifecycle Manager

How Trust Lifecycle Manager consumes identity

  • Every authenticated request carries a signed token issued by Account Manager. Trust Lifecycle Manager retrieves Account Manager's verification key and validates the token signature before processing the request.

  • Trust Lifecycle Manager reads user, account, organization, and licensing information from Account Manager. It doesn’t hold its own user or role store.

  • Trust Lifecycle Manager cannot create, modify, or delete human users or roles.

  • Trust Lifecycle Manager can create and disable service users and their authentication certificates, used only by Trust Lifecycle Manager agents and sensors. Treat these as machine identities and review them alongside human accounts.

Important

Because role assignment happens in Account Manager, your Trust Lifecycle Manager access review is incomplete unless it also covers Account Manager. Apply the FedRAMP account management and access review controls in both products.