Here we go, perfect. Kevin Switala is my name. I'm working with one of our larger clients here at Okta, and if you don't know Okta yet, our mission is building a world where anyone can safely use any technology powered by their identity. And instead of us telling 20 minutes what we do at Okta, what great things we do with our two platforms, we thought about it might be useful getting proper insights by one of our larger clients, Siemens. So with that, I would like to introduce on stage André de Sousa from Siemens. Good morning, everyone. So I'll start with a small note.
If you guys looked at the agenda before, you were probably expecting a tall German person to be here, which is my manager, the Global Director for Identities, Thomas Miller Lynch, but he had a personal emergency, so you'll have to settle for the short Portuguese guy for the whole presentation. Sorry for that. As you see, as Kevin presented, what we'll talk a little bit about is how Siemens is currently bridging the gap between the business needs and specifically the authentication space for us, the identity space for us. Let me just start. I guess that's the easy thing.
Let's start with a short introduction. For those of you that don't know, we don't do appliances anymore. We are effectively in multiple business areas, of course, more in the industrial space, but across all, not all, that might be too strong of a word, across many areas of the industrial space, namely energy, mobility, security, sensors, that's what we are really focused on. Effectively still being an industrial company, but with a strong push on the digital side and trying to bridge the gap between what is physical and what is digital.
As you might expect, being such a large company and in so many areas, it's very common to have each one pulling in its own direction, and that's always a problem. It has always been a problem for us, especially in the authentication space, and we've been trying to really bring everyone together.
This, of course, happens at the base level, but we are now moving in a more global front or top-down take into this space. You might have seen this slogan being thrown out right now. We are trying to be a one-tech company. What this really means is we're trying to get everyone to move in the same direction, even when we know they have different end goals. We see people building trains, we see people building HVAC systems, but then at the end of the day, IT-wise, customer-wise, the goal is the same. We need to provide the same type of services and a strong customer focus.
We want to make sure that the customer is key to all of this, and even though we have so many distinct offerings, the experience has to be the same, the security has to be to the best that we can provide, and also the same. How is this really, this one-tech thing, how does this really tie in in this EIC context? Single identity.
That's, at the end of the day, what it means. Normally, we would go step by step to the things that we have been building to. I decided to take this way around. This is a clear look at our last ten years, 11 years, if you want to think about it.
Initially, we started with extremely disjointed identity systems. Every single one team, or every single one product line was doing their own thing, and we, at the time, wanted to go with, we adopted our Siemens Cloud first identity strategy, and we started working slowly towards what we have today. You will see it in a second. It was a long process. I guess that is one of the key messages that we would like to share with you is that there is no way to bridge the gap between business and IT and identity and security without really considering that it's going to take time.
It's not something that you do in a couple of months. On the bottom, you will see the purple ones. Those have been the main milestones for us. There are some additional things there. I'm personally responsible for the customer IDP at Siemens. We started a POC with that. That's the Siemens ID release. That was the first real step into this new model that we've adopted.
That was an attempt, really a pure POC, initially with our Auth0 vendor, now Okta, to try to build a small-scale, customer-first IDP that multiple of our business units, with completely different target spaces, could join in and see if it would work. Try to really push into that direction. We started with just 30 customers in that system in 2018. You'll see it in a later slide, but we are about at 5.5 million right now, just to give you a context in the last six years, how that evolved.
We kept going, and centrally, this is the other side of how to bridge business with IT, that 2020 year is very important for us. It's when we kick-started the Zero Trust program, and whatever came out of that allowed us to be where we are today. That Zero Trust program, of course, we call it program here. Most of you that work with Zero Trust know that this is not something that you just do once. It's something that you start, and you just keep rolling with it. It's a philosophy, if you want to call it, to how you try to manage your security, your identities, your company, even.
But we started as a small, contained program where... Well, small might not be the right word for it. The intention was to start analyzing, bringing people from different skill sets, different units, all together to focus on what we were going to do next, and how we could achieve that vision. A couple of things came out of that. We'll see it in a second. But the main piece for the authentication space that came out of it was our authentication consolidation strategy. That basically meant that we wanted to bring all of the distinct IDPs that we had at the company into single places.
It also effectively translated into a dual IDP strategy. We'll see it in a second. That meant one for workforce, one for customer. That was our take.
Of course, as you might expect, we had a lot of official and non-official IDPs spread through the company, so it has been a challenge to bring everything together. Starting with Zero Trust. We have some core principles on it. Most of the teams that were involved were, as I said before, multidisciplinary and across multiple business units. I specifically was working on that box regarding identity, and what came out of that for us as IAM, as identity and authentication experts, was that small thing there on the right side.
We decided that we would simply have those two IDPs for the whole company, and for ID for workforce, what we call Zeeman's ID, the Okta solution, for customer, and we basically pushed this top down to everyone, and got everyone on board with it. So we brought all of the business contacts into our conversation, and we basically tried to make sure that we were aligning all of the requirements that we had from the business with our intention to have central governance over everything.
I can tell you that it was not easy, as you would expect, but it was very fruitful because we managed to, one, improve overall security posture, to simplify many, many things inside of the company, but more importantly, bring a very clear increase in user experience for our customers, and in a very secure way. The key piece for this was to figure out the boundaries. What do we need to really manage centrally? What can the business manage, and how do we move forward with it?
On the workforce side, we had, if we go, let me just go back a little bit, when we look at this timeline here, in 2019, we moved our internal authentication system into a ping-based solution. Then in 2023, roughly, we moved away from that solution into the Entra ID solution, because we wanted to condense everything into that single place. From 2020 to 2023, we were working on that Zero Trust project, and making sure that Entra and Siemens ID were the main IDPs, and at the end of the day, we've managed to do, or we are currently supporting all of this in a single workforce system.
We have roughly 250,000 employees across the world. Those 470k accounts for guests are effectively people that connect to our systems to support Siemens internal needs. Those applications are a line of business applications, so we've tried to make sure that we work very closely with the business and their business needs, both internally and externally, to guarantee the most out of it.
Now, if I move here, this is where I'm a lot more happier, because this is my service, the one that I can talk the most about, so sorry for that. This is what happened to Siemens ID, on the customer side, and where we actually saw the best results of this connection between business and IT. We started, as I said before, with those 30-something users on the POC.
We started getting the trust of the different business units, started working closely with them, and then in 2023 became the de facto standard for the customer authentication, and we've been migrating all of the other existing IDPs into Siemens ID this last few years, so I can tell you that last year we migrated two big IDPs that we had from our digital industry side, and we migrated close to 2.5 million identities from those systems into ours with all the associated applications, so it has been a very fun experience, I can tell you that.
On the other side, we've got a lot of good feedback from the customers, because having such a spread out setup before, bringing it to a single authentication place where you can come in and you can potentially buy an HVAC system, potentially buy a train, all in the same place, you have a single identity set by the same rule sets that apply to the company everywhere, same experience for customers, this has been very beneficial for the whole of our business units, that's how we really managed to make it as a successful story.
This is effectively how Siemens is working right now when it comes to identity, dual IDP formula, of course I won't tell you there are still some cases where there may be a specific authentication system here or there, there are exceptions, there are very small things that we can't do yet here that don't fit the perfect mould of the use case that we have on a certain product, but we're trying to extend both of these to make sure that that doesn't happen anymore. It's going to take time. One tech and business, this is, or I guess I'll use this slide to really underscore that, or underline that.
If you want to have a successful transition from spread out identity systems into core ones, centrally managed ones, there is really no other way to do it besides having one management buy-in and besides reaching out really to your business. You can very easily say, oh, I will mandate that you guys do this, and then shadow IT grows exponentially, because you know they don't really want to do that.
For us, one of the tricks was start small, start gaining the trust of your business, because a lot of times IT or security, depending where IT or security, depending where IAM falls in your company space, tries to just say go left, go right, and businesses don't really like that.
So we have had to start small and try to bring little pieces here, little pieces there, really foster that open conversation, really say maybe you know better about this, let's talk a little bit more, this we must do, this we can do, that we may give you a little hand, we may give you some leeway to move into that direction. For us right now, what is going to happen next is this. This for us is really a problem. Even though we haven't fixed completely authentication, we still have those small pieces that we need to support, this is really going to be the next big thing.
There are multiple initiatives at the company looking into this. Those of you that have looked into this probably know this is going to be a nightmare. It's not going to be as easy as authentication was for whatever degrees of easy that may have been. We are really not sure yet what the best approach for this will be. We are pretty sure that it's not going to be just a dual system strategy, but it's something that we are currently running through. That was a nice gentleman that was supposed to be here. Please reach out for, let's call it, the more global questions to the gentleman on the left.
For more specific customer-related questions, you can reach out to me, and that's it. APPLAUSE I have some questions. Do you have questions?
Yes, we do. Then we can do some questions. Sorry. We don't want to get rid of you so quickly, Andre. The audience wants to know how do you ensure business continuity in production areas ? Sorry. Question moved. Sorry. How do you ensure business continuity in production areas with intra-ID if the WAN connectivity is down? Okay.
Well, you may have seen on one of those slides that we decommissioned some of the WAN connectivity domain controllers, but we still have an active on-prem AD. It still exists. It's still spread out. A lot smaller footprint. We are cloud-first. We're taking a cloud-first approach.
So, Azure and intra are the main thing, but we still have the local domain controllers. And that's how we can basically ensure in production areas.
So, that's the main thing. So, that's the main thing.
So, that's the main thing. So, that's the main thing.
So, that's the main thing. So, that's the main thing. And that's how we can basically ensure in, let's say, disconnected systems and there is still information there. And that's how we can basically ensure in, let's say, disconnected systems This is kind of a related question. How do you handle applications that cannot be connected to intra-ID and need to stick to on-prem AD? and need to stick to on-prem AD? We still have an on-prem AD. Okay.
Right, fine. And what's the size of your team that's been working on the authentication space? That depends.
So, for the external side, up until two years ago, we were doing all of that with three people. We were doing all of that with three people. For the customer side. We are now a ten-man team on the customer side. We are now a ten-man team on the customer side. On the intra-side, I think they are around ten-ish, twelve-two. On the intra-side, I think they are around ten-ish, twelve-two. Just pure Azure side. Just pure Azure side. Not counting operations. That's a different story.
Okay, thank you very much, André Sousa. Okay, thank you very much, André Sousa.