Understand account management responsibilities
DigiCert® Trust Lifecycle Manager depends on DigiCert® Account Manager for identity. This split determines where you perform each administrative task.
Task | Performed in |
|---|---|
Creating, disabling, and deleting human users | Account Manager |
Assigning and removing user roles | Account Manager |
Configuring authentication methods, SSO/federation, and MFA | Account Manager |
Password and session policy | Account Manager |
Account and organization records | Account Manager |
Licensing and feature entitlement | Account Manager |
Business units and seat allocation | Trust Lifecycle Manager |
Certificate profiles, connectors, automation, and certificate operations | Trust Lifecycle Manager |
How Trust Lifecycle Manager consumes identity
Every authenticated request carries a signed token issued by Account Manager. Trust Lifecycle Manager retrieves Account Manager's verification key and validates the token signature before processing the request.
Trust Lifecycle Manager reads user, account, organization, and licensing information from Account Manager. It doesn’t hold its own user or role store.
Trust Lifecycle Manager cannot create, modify, or delete human users or roles.
Trust Lifecycle Manager can create and disable service users and their authentication certificates, used only by Trust Lifecycle Manager agents and sensors. Treat these as machine identities and review them alongside human accounts.
Important
Because role assignment happens in Account Manager, your Trust Lifecycle Manager access review is incomplete unless it also covers Account Manager. Apply the FedRAMP account management and access review controls in both products.