Identity as a Service (IDaaS)

Identity and access management delivered as a cloud service by a third party, commonly covering directory, single sign-on, MFA, federation and account provisioning.

Identity as a Service (IDaaS) is identity and access management run by a third-party provider and consumed over the internet. Instead of operating its own identity infrastructure, an organisation subscribes to a service that commonly offers a cloud directory, single sign-on to many applications, multi-factor authentication, federation through protocols such as SAML and OpenID Connect, and automated account provisioning, often through SCIM. In many deployments the IDaaS platform acts as the organisation’s identity provider.

The model moves operational work to the provider but not accountability. The organisation still owns its access policy, its joiner, mover and leaver process and its access reviews, and it takes on third-party risk: the provider’s security, availability and contract terms now sit in front of the applications that rely on it. Because one service gates access to many systems, an outage or a compromised administrator account at the provider can have a wide effect. Many organisations run a hybrid arrangement, keeping an on-premises directory synchronised with the cloud service.

Exam relevance: the ISC2 outline’s objective on federated identity with a third-party service lists on-premise, cloud and hybrid. A scenario is likely to turn on the trade-off: less infrastructure to run, in exchange for dependence on a provider whose controls the organisation should assess.