Leaving UZH (Life Cycle Management, LCM)
Table of contents
Introduction
Life Cycle Management (LCM) manages the entire lifecycle of user accounts in UZH’s Identity Manager – from creation to deletion. The system operates largely automatically and ensures that accounts are correctly deactivated and removed once a user leaves the university
How Does LCM Work During Employment?
For regular employment, an account in the Identity Manager is automatically created approximately 30 days before the first working day. This process includes:
- the creation of the user identity,
- the setup of the associated accounts (e.g. email, VPN, UZH services).
Manually created users (e.g. guests or temporary staff) have a default validity period of six months.
After this period, the IT administrator can extend the validity. If it is not extended, the affected person automatically receives a notification by email, and 30 days later the accounts are deleted.
Archived users remain stored in the system but are no longer visible to IT administrators.
What Happens When You Leave UZH?
As soon as a person no longer has an active employment or enrollment, the LCM offboarding process starts automatically:
- The person concerned receives an email notification about the upcoming departure.
- If no action is taken, all user accounts are deactivated after seven days.
- After a further 30 days, the accounts are permanently deleted.
Note:
Persons who continue to work at an institute or in a central service (e.g. as external staff or guest researchers) must be managed manually. This requires a request to the IT administrator of the respective institute.
Timeframes for leaving the University
| Event | Timing | Action |
|---|---|---|
| Students: Deregistration |
After 4 months | Email notification about deactivation |
| Stuff: End of employment |
On the last working day | Email notification about deactivation |
| Deactivation of all accounts | 7 days after notification | Access ends; forwarding/out-of-office messages no longer work |
| Deletion of all accounts & data | 30 days after deactivation | Permanent removal of data |
Reactivation by IT Administrators
Until final deletion, IT administrators can manually reactivate or extend accounts in the Identity Manager. After that, access to data or email accounts is no longer possible.
Contact
If you have any questions, please contact the IT Support team at the Central IT Department: