The directory is often treated as a mere identity repository, but that view ignores its potential to integrate diverse identity information and thereby increase the value of one of the enterprise’s most critical assets: identity data spread across many systems. Historically, enterprises used an “enterprise directory” provisioned from HR or contractor systems to control application access. Microsoft Active Directory (AD) later became the default authentication source for network and on-premises Windows services, but attempts to use AD as the enterprise directory commonly fell short because an authentication directory prioritizes stability and restricts changes (such as schema updates), while an enterprise directory must remain business-flexible to support reorganizations, compliance, cloud moves, and mergers.
Cloud adoption, mobility, and hybrid environments have multiplied identity sources and consumers. Proliferating cloud identity stores increases corporate risk, while enterprises also seek unified visibility across employees and customers even though relevant data for a single individual is created and maintained in multiple systems not designed to feed an enterprise identity repository. As identity volume, attribute variety, and the number of systems grow, identity information quality becomes a security, compliance, and operational issue—often forcing slow, manual, or custom-scripted synchronization.
The text argues the directory should sit at the center of IAM as a unified source of truth that models changing relationships (people, roles, groups, devices), supports many protocols, correlates identities without shared identifiers, transforms attribute formats/semantics, and automatically synchronizes systems at scale.
Radiant Logic’s RadiantOne suite targets these needs with FID (core), ICS (correlation/synchronization/provisioning), and CFS (cloud federation). FID now includes HDAP, a Hadoop-based “Big Data Directory” that instantiates unified identity profiles from multiple sources, computes synthetic attributes, and scales to tens of millions of identities with high availability and strong encryption controls. ICS provisions “mirror identities” to target systems and identifies orphaned accounts; CFS issues federation tokens and can add two-factor authentication without application changes. Strengths include scalability, correlation/transformation, GUI tooling, provisioning/synchronization, and standards support; challenges include limited ecosystem reach, dependence on partners for core IAM components, and Windows-only deployment for CFS.
See All Locations
See All Locations