Identity & Access Management (IAM) sits at the center of enterprise IT because it governs digital identities—employees, partners, customers, and increasingly devices/things—and protects corporate digital assets. As security perimeters erode through mobility, partner integration, and cloud adoption, organizations face higher exposure while the value of digital assets and intellectual property rises, including in traditional industries moving toward connected things and smart manufacturing. In this context, IAM reduces attack surface by enforcing well-managed identities, credentials, and entitlements, supporting the least-privilege principle, automating provisioning and deprovisioning, and enabling regular entitlement reviews to detect excessive access.
IAM also enables business by streamlining onboarding and access workflows for diverse user populations and by supporting access needs for new digital services, including IoT and device identities. The market has been shifting from on-premises IAM to Identity as a Service (IDaaS), driven by faster time-to-value and cloud-ready integrations that extend IAM controls across expanding SaaS portfolios. However, “IDaaS” covers varied offerings, from Single Sign-On to full provisioning and access governance, with differing support for user types, mobility, and hybrid integration.
The report evaluates One Identity Manager On Demand, the IDaaS version of One Identity Manager. Rather than a simple lift-and-shift or a wholly new product, it builds on years of modernization and modularization in the on-premises platform, achieving near feature parity; the main functional gap is the absence of the Data Governance Edition as SaaS. One Identity addresses IDaaS requirements through an API-first approach, isolation of customizations, continuous provider-managed updates, and scalable deployments (not necessarily multi-tenant). The Angular-based UI consumes backend APIs via an API Server, separating front-end and backend to keep customer extensions resilient through updates. Tenants typically receive both pre-production and production instances, with continuous updates delivered via Microsoft Azure and Kubernetes. Strengths include broad connectors, SAP-certified integration, and strong APIs; challenges include lack of published pay-per-use pricing, Azure-only availability, and Starling Connect as a separate component.
See All Locations
See All Locations