From manual onboarding to federation — an evolution with blind spots
Organizations have made significant investments in Identity and Access Management (IAM) over the past years. IAM platforms have been consolidated, streamlined, and modernized. Processes were centralized, internal identity sources were linked to HR systems, and even external personnel were integrated into structured procurement and HR workflows.
However, the landscape is shifting. While IAM has often focused on on-premise environments, the way companies collaborate is evolving. Cloud services have significantly simplified cross-organizational communication and collaboration. Microsoft 365, with Teams at its core, has become the de facto standard for many enterprises. The appeal is obvious: seamless integration, ease of use, and the ability to work from anywhere. However, these cross-organizational use cases are often not yet integrated into enterprise IAM frameworks, leading to blind spots.
Yet, a new challenge is emerging: External users. Traditionally, these identities were onboarded manually, assigned an internal identity, treated like an internal identity, and governed under established IAM processes. But organizations are now increasingly inviting external users directly into their cloud environments, bypassing established IAM workflows. This shift is driven by both necessity and cost: Why create and manage costly internal accounts for external contractors or partners when they can simply bring their own identity?
If organizations employ identity federation with partner organizations they need to rely on the identity information of the partner organization and utilize them in their processes. If the conditions of this data exchange are not defined, organizations face significant risks, as there is no guarantee of the quality of the identity information.
Federation — a technical advantage, but an organizational headache
Technically, federated identity solves several problems: External users authenticate via their home organization, reducing credential sprawl and shifting lifecycle management responsibility to the external entity. The inviting organization no longer manages passwords, authentication methods or identity information for these users.
Functionally, this approach is efficient. Externals can be onboarded quickly and with minimal overhead. However, this rapid adoption often occurs without a solid governance framework, which leads to unmanaged risks. Key questions remain unanswered:
- Who ensures that external identities meet internal security standards?
- How can organizations track access for federated identities and enforce lifecycle management?
- How can organizations be audit-compliant if identity processes exist outside their control?
- What happens in case of a security breach or immediate contract termination?
Without answers to these questions, federation introduces risks that organizations cannot afford to ignore.
Defining a trust framework — because not all identities are equal
To use federated identities responsibly, organizations must introduce clear governance structures. The first step: Classify your data. Not every external partner should automatically be able to access all data. Instead, the sensitivity of data and services accessed needs to be assessed and then decided who can access it.
This means:
- Classifying data and systems — Which resources require which level of assurance?
- Defining security standards — What security policies and frameworks does the organization follow?
- Defining external identity requirements — What minimum security standards must external identities meet?
- Assessing partners’ identity assurance level — How does the external organization manage their identities?
A structured questionnaire can help determine whether a partner’s IAM practices align with internal security requirements. This allows organizations to document the IAM standards at the partner organization and evaluate risks systematically.
Beyond policies: Contracts, audits, and integration
Once the identity assurance level and requirements for federated identities are defined, organizations must ensure enforceability. This requires:
- Contractual agreements: External organizations must commit to fulfilling identity-related obligations (e.g., lifecycle management, incident handling). These agreements should be formally established through contracts.
- Regular audits: Verification processes should be established. In addition, the audit requirements of external auditors (e.g., regulators) need to be considered.
- Integration with IAM workflows: Federation must not operate in isolation. External identities need to be embedded in existing processes, for example:
- Request and approval workflows
- Recertification cycles
- Incident response procedures
Regulatory impact: Compliance beyond internal policies
The increasing relevance of regulations such as NIS2 makes structured federation practices even more critical. NIS2 explicitly enforces supply-chain IT security, making it essential for organizations to ensure that external identities meet strict security and governance standards. Companies affected by these regulations must not only implement secure IAM processes internally but also extend these controls to federated identities, ensuring that third-party users and partner organizations comply with defined security requirements. Proper documentation and auditability of federated access will become key factors in regulatory compliance.
The bottom line: Federation, but with a backbone
Federated identities are a powerful tool, but without governance, they introduce significant risks. Organizations must ensure that federated access follows the same rigorous standards as internal IAM processes. That means defining identity assurance levels, establishing compliance mechanisms, and ensuring transparency in identity lifecycles. All involved parties must have clearly defined roles and responsibilities for process execution.
If the usual standards for IAM are followed and identity federation is introduced with a solid governance framework, organizations can use federation to reduce costs (e.g., licenses). In addition, they can benefit from shortened onboarding procedures as the existing identity is used.
Federation is not a shortcut to bypass IAM! It’s an evolution that requires a solid foundation. Organizations that set clear frameworks today will enable secure, scalable, and cost-efficient collaboration in the future without losing sight of security and compliance.