My current customer has this workflow:
1. The person or someone else raises an request for an account(some users have up to 3 accounts for security reasons);
2. An certain amount of people approves it
3. The system adds the account to an group.
all the systems can look up the account and the groups he is a member of in the AD.
This also works for applications that don't authenticate themselfs over ldap, like SAML or OAuth, since the sso is configured to relay the groups.