Cloud-based IAM/IAG initially succeeded through Cloud Single Sign-On (SSO), enabling users to reach cloud services, on-premises web applications, and even partner applications via a portal. Authentication commonly relies on SAML or OAuth, often paired with OpenID Connect, as core identity federation standards. However, SSO alone is necessary but no longer sufficient. Pressure for higher efficiency and lower costs is pushing cloud identity services to expand beyond login to full Identity and Access Management (IAM) and Identity and Access Governance (IAG) capabilities.
Two forward paths emerge. One is cloud-based IAM/IAG delivered as a service that adds Identity Provisioning and Access Governance, functioning either as a strong integration layer with traditional on-premises IAM/IAG or eventually as its replacement. The other is a broader Identity-as-a-Service (IDaaS) model that combines identity federation, self-service registration, directory services, and access management, and is positioned as especially effective for managing non-employee populations (“externals”) such as partners, vendors, contractors, and clients.
In practice, cloud IAM/IAG must become an integral part of the organization’s access management and governance portfolio, supporting both cloud and on-premises apps with full functionality. A common deployment model has employees and contractors accessing datacenter applications directly or via portals while also reaching cloud services, with partners and other externals coming into datacenter apps through the cloud-based system, which can also connect them to additional cloud services.
Because convergence between these approaches may come later, the recommended strategy is to choose one direction now based on current needs. Delaying action risks years of costly catch-up and potential future organizational damage.
See All Locations
See All Locations