Depending on the service, these capabilities may include a hosted directory, authentication, multi-factor authentication, federation, single sign-on, provisioning, access policy, lifecycle workflows, reporting, and interfaces that connect applications and other identity sources.
IDaaS can reduce the infrastructure an organization operates directly and provide a consistent identity layer across software-as-a-service, cloud, and on-premises applications. It also creates a critical external dependency. Architecture and procurement should therefore address tenant isolation, administrative privilege, data use and location, key custody, integration security, audit access, portability, availability, incident response, and exit procedures.
Key points
Service boundaryDocument which identity functions the provider performs, which systems remain authoritative, and which decisions and enforcement points stay with the customer or application.
Integration modelEvaluate federation, provisioning, directories, APIs, agents, connectors, and recovery paths, including the privileges and failure modes of each component.
Assurance and resilienceMatch authentication and federation assurance to risk, protect provider administration, export useful logs, and plan for outages, compromise, and service termination.
Important limitationMoving identity functions to a service does not transfer accountability for access policy, lifecycle data, application authorization, configuration, or user recovery. Capabilities and security properties vary substantially between providers and service tiers.