Identity Management is mainly used to manage user resources. If any organization having multiple resources (multiple directories like AD, LDAP, Exchange etc) it is very difficult to update all the resources manually so there comes Identity Management.
If any new user joined in Organization then he need to be created in all resources, then OIM can be used to create (provision) that user in all resources and when ever user role got changed it OIM automatically pulls it from trusted resource and updates remaining all resources. And same for user termination.
Identity Management completely manages user life cycle in any organization.