The fractured state of enterprise identity
Identity continues to be the biggest vulnerability in enterprise security. The majority of breaches still involve compromised credentials, yet most organizations wrestle with fragmented and inconsistent identity systems. Enterprises depend on multiple Software as a Service (SaaS) applications, each with its own approach to Single Sign-On (SSO), provisioning, and session management. Developers often face a patchwork of protocols, optional features, and provider-specific requirements that make integration error-prone and governance difficult. This complexity fuels identity sprawl, increases operational overhead, and leaves dangerous gaps in access control.
Why standardization is needed now
The absence of a common framework for identity security has long been a weakness. Protocols such as Security Assertion Markup Language (SAML), OpenID Connect (OIDC), and System for Cross-domain Identity Management (SCIM) provide the building blocks, but their flexibility is a double-edged sword. Too much optionality means implementations diverge, creating interoperability issues and security blind spots. Enterprises struggle to achieve consistent outcomes such as secure provisioning, predictable session lifecycles, and reliable signal sharing. Developers face repeated work to adapt to each integration, while security teams face uncertainty about whether controls are being enforced in practice.
Against this backdrop, an OpenID Foundation working group aims to provide a unifying standard. Backed by Okta, Microsoft, Ping Identity, Beyond Identity, SGNL, Capital One, Cisco’s Duo Security division and others, the initiative promises to simplify and harden enterprise identity security.
What IPSIE is and why it matters
The OIDF Interoperability Profiling for Secure Identity in the Enterprise (IPSIE) working group develops profiles of existing standards to reduce complexity and guarantee interoperability. Rather than inventing new protocols, IPSIE delivers opinionated specifications that strip away optionality and enforce secure defaults. Its goal is to make identity standards easier to implement, test, and certify.
Key areas of focus include:
- SSO: Centralizing login and ensuring secure session handling
- Account Lifecycle (AL): Automating user provisioning and deprovisioning to prevent orphaned accounts
- Entitlements: Enforcing least privilege and supporting role synchronization across systems
- Risk Signal Sharing: Exchanging alerts about threats or device posture to improve response
- Session Termination and Token Revocation: Ensuring compromised sessions are cut off immediately
IPSIE introduces maturity levels to define what secure implementations look like in practice. For example, Session Lifecycle Level 1 (SL1) requires compliance with US National Institute of Standards and Technology (NIST) Special Publication 800-63-4 at Federation Assurance Level 2 (FAL2), enforcing Multifactor Authentication (MFA) and requiring applications (relying parties) to set their session duration based on the validity period defined in the federation assertion. Higher levels add capabilities such as session state communication between apps and identity providers. Similarly, AL levels progress from basic user provisioning (AL1) to full synchronization of application roles and entitlements (AL3).
The first draft profile is already in circulation, with OIDC SL1 serving as an early demonstration of how IPSIE maps existing protocols to concrete operational behaviors.
This structured approach brings clarity where today there is ambiguity. Instead of vague requirements like “support SSO,” IPSIE provides measurable, testable criteria. With conformance testing and certification, enterprises will be able to trust that applications meet consistent security expectations.
The promise and the limits of IPSIE
IPSIE addresses real and persistent challenges. By narrowing choices and enforcing secure defaults, it reduces the likelihood of weak or inconsistent implementations. Enterprises benefit from better visibility and stronger controls. SaaS providers benefit from a common standard that makes integration predictable and reduces costly one-off engineering.
But IPSIE’s scope is clearly human-centric. Its focus is SaaS identity flows tied to workforce users, including authentication, lifecycle, entitlements, and logout. Missing from the IPSIE charter are non-human identities: service accounts, CI/CD tokens, API keys, IoT device credentials, and machine-to-machine workloads. These identities are proliferating rapidly, often unmanaged, and present one of the largest attack surfaces today. If IPSIE does not extend its model to include them, the NHI problem will remain largely unresolved.
Some observers have also cautioned that IPSIE risks being too broad, trying to cover everything from login to entitlements to logout in one sweep. Others compare it to the early days of the FIDO Alliance, where progress came by focusing on a narrow, well-defined problem before expanding. IPSIE’s long-term success will depend on whether it can balance ambition with pragmatism and secure adoption across vendors.
A step toward solving the NHI challenge
IPSIE is not the complete answer to non-human identity governance, but it is an important step. Standardized, interoperable, secure-by-default profiles for SaaS identity will reduce identity sprawl and strengthen enterprise controls. Yet without extending its scope to machine identities, IPSIE risks addressing only part of the problem. For a full solution, enterprises will still need lifecycle governance, automated secrets rotation, least-privilege enforcement, and continuous discovery across all identities, human and non-human.
How KuppingerCole can help
KuppingerCole Analysts can help organizations make sense of this evolving space. Our research on identity fabrics, Zero Trust strategies, and machine identity management provides a framework for addressing both human and non-human identity challenges. We have published Advisory Notes on non-human identity governance and Leadership Compass reports on Privileged Access Management that highlight the importance of consistent lifecycle controls for machine identities.
IPSIE represents progress. By bringing clarity and interoperability to enterprise SaaS identity, it addresses a pressing security gap. But the wider challenge of non-human identity still looms large. Organizations should welcome IPSIE as part of the solution, while recognizing that much work remains to be done.