The IDaaS market has expanded in size and vendor diversity, but the umbrella term covers substantially different service types. Offerings span from Single Sign-On (SSO) to full Identity Provisioning and Access Governance for both on-premises and cloud environments, with varying support for employees, partners, customers, mobile users, and integrations back to on-premises applications. Three market segments are distinguished: IDaaS SSO (cloud access and downstream SSO), IDaaS B2E (cloud-delivered employee IAM with provisioning and governance for on-premises plus federation and baseline cloud SSO), and IDaaS Digital (newer services aimed at digital transformation requirements for customers and partners with more complex functionality).
Organizations commonly combine on-premises IAM, IDaaS, and CIAM, while weakly protected digital identity remains a major pathway to fraud and data breaches. In response, some IDaaS Digital vendors provide API-delivered services such as identity vetting, authoritative attribute retrieval, device/location context analysis, identity analytics, threat and compromised-credential intelligence ingestion, risk analysis, dynamic policy evaluation, and risk-score outputs to adaptive authentication engines. These capabilities can reduce fraud and may be required by regulation; PSD2 is highlighted as driving transaction risk analysis for most transactions above €30 in Europe.
ThreatMetrix (acquired by LexisNexis Risk Solutions/RELX) exemplifies IDaaS Digital through a cloud-based identity intelligence platform. It assigns a globally unique ThreatMetrix ID, links multiple external user identifiers for unified cross-domain views, and produces confidence, trust, and risk scores using extensive network-scale data and contextual signals. The platform emphasizes privacy-by-design with encryption, hashing of identifying fields, tenant-specific keys, and GDPR-aligned deletion requests. It does not manage end-user accounts, so it does not support LDAP/SCIM provisioning, instead relying on identifier association and just-in-time SAML provisioning. Strengths include scale, intelligence quality, end-user transparency, and integration; challenges include administrator authentication limited to username/password or SAML, feature-packaging clarity, and a need for broader standards support such as OIDC.
See All Locations
See All Locations