# What is Identity as a Service (IDaaS)?

> Identity as a service (IDaaS) is a cloud service model in which a provider delivers identity, credential, and access-management capabilities for customer organizations.

- Canonical URL: https://yellowcube.eu/glossary/identity-as-a-service/
- Publisher: Yellow Cube
- Language: en
- Contact: hello@yellowcube.eu

## Content

Depending on the service, these capabilities may include a hosted directory, authentication, multi-factor authentication, federation, single sign-on, provisioning, access policy, lifecycle workflows, reporting, and interfaces that connect applications and other identity sources.

IDaaS can reduce the infrastructure an organization operates directly and provide a consistent identity layer across software-as-a-service, cloud, and on-premises applications. It also creates a critical external dependency. Architecture and procurement should therefore address tenant isolation, administrative privilege, data use and location, key custody, integration security, audit access, portability, availability, incident response, and exit procedures.

### Key points

- **Service boundary:** Document which identity functions the provider performs, which systems remain authoritative, and which decisions and enforcement points stay with the customer or application.
- **Integration model:** Evaluate federation, provisioning, directories, APIs, agents, connectors, and recovery paths, including the privileges and failure modes of each component.
- **Assurance and resilience:** Match authentication and federation assurance to risk, protect provider administration, export useful logs, and plan for outages, compromise, and service termination.
- **Important limitation:** Moving identity functions to a service does not transfer accountability for access policy, lifecycle data, application authorization, configuration, or user recovery. Capabilities and security properties vary substantially between providers and service tiers.

### Related terms

[Identity and access management (IAM)](<https://yellowcube.eu/glossary/identity-and-access-management/>) · [Federated identity](<https://yellowcube.eu/glossary/federated-identity/>) · [Single sign-on (SSO)](<https://yellowcube.eu/glossary/single-sign-on/>) · [Multi-factor authentication (MFA)](<https://yellowcube.eu/glossary/multi-factor-authentication/>) · [Conditional access](<https://yellowcube.eu/glossary/conditional-access/>)

### Sources

[NIST IR 8335 initial public draft (June 2021; comment period closed): Identity as a Service for Public Safety Organizations](https://csrc.nist.gov/pubs/ir/8335/ipd) · [NIST SP 800-63-4: Digital Identity Guidelines](https://csrc.nist.gov/pubs/sp/800/63/4/final)

## Attribution and scope

This Markdown representation is generated from the same approved content records as the canonical HTML page. Cite the canonical URL above when referencing this material. Product and service descriptions are informational; confirm project-specific requirements with Yellow Cube.

