Many people. Sure.
So, this is quite challenging to put a four to five year project into 20 minutes. So, I'm not deep diving very much and I'm hoping to give an overview of what we did. I hope you can learn something from it. And mainly, I'm trying to answer the question and also give you the ability to answer the question if it was a good decision to do what we did in the time we had or not.
So, just a quick history for those of you who don't know. Mercedes-Benz and Daimler Truck split. It was the biggest spin-off in the automotive history and we had to come up with new solutions how we want to set up IT at Daimler Truck. There was no IT at Daimler Truck. It was a global IT department. It was a global IAM for whole Daimler AG.
So, we had very brave managers back in the days that decided to take a shot and a chance to take that opportunity to build something modern, innovative and to use IAM as one of the instruments to get to a better infrastructure, a more modern infrastructure and also a modern identity landscape. Diving right in, I want to just quickly spend a minute on what the legacy was. What was it that we had to replace or what we had to kind of live up to from Mercedes.
So, as any IAM system, Mercedes or Daimler AG built a system that's very complex. It had to serve a lot of use cases and it was grown in many, many, many years of history of the company starting obviously with Active Directory. It was homegrown.
So, Mercedes is using still today homegrown systems that were very comfortable and very customized to the need of the business. And it was also very expensive.
So, that was kind of the decision also to say we need something that's cheaper because we as small Daimler truck are not able to maintain what Mercedes is still using today. So, we had high ambitions and I can say most of them actually we achieved. It needed to be simple. It needed to be standardized.
So, find something that can be used everywhere. Secure but user-friendly, which is always a good ambition. And lean operations, as mentioned before, it can't be as expensive as Mercedes is because we just can't afford that.
So, what we came up with in the project was one of the big five transformational moves that Daimler truck did during the carve-out. And we had those four pillars that we identified that we wanted to do in real life.
So, do a central IGA tool. I think that is necessary in any company and very few actually achieve that in the size of a company always speaking as Daimler truck. Go with modern identity providers. That was a thing they said from the beginning. Let's go cloud first.
So, every application we touch, cloud. Everything we can modernize, modernize. We didn't only touch IAM or infrastructure. We touched HR. We touched SAP. We changed everything.
So, over the last five years what our users and employees had to endure was crazy. And identity was just on top of that or the basis of it. Self-service for IAM, huge struggle. Nobody is used to it. But we really still are thriving towards self-service in any way. Everybody is supposed to be the owner of their identity, their access, and so on. And as a last very high ambitious pillar, enable passwordless.
So, with our IAM transformation, we pushed digital workplace to become modern. We moved every single office client into the cloud. And we are using Hull for Business on a daily basis. I get regular calls and emails from people telling me there's something wrong with your IAM. You're not secure anymore. I don't get prompted for MFA. It's so seamless and so easy for them that they think it isn't there anymore.
So, the ambitions and what we actually did. What we had to do on an operational basis was quite different. We had to replace many, many tools. IGA tools that even with Mercedes aren't handled with an IAM. There's IGA tools that HR has and IGA tools that finance is really operating. And we said we will just stop that and everything goes into IGA. Everything is with one tool. We had to set up all the necessary IDPs. We're talking also new active directory, making sure it's set up in the most secure way. Migrate applications and communications.
And I brought some numbers with me just to understand the scale. In total, we're managing 350,000 cloud identities. More than 3,000 applications we had to migrate. On an AD perspective, that's quite impressive. We had 1.1 million groups to migrate. We had more than 25K servers, 200,000 accounts, and more than 200,000 servers.
So, it was a really, really big project. For the project itself on an IGA perspective, that's super impressive. We had more than 400 releases on our IGA tool. We had more than 1,000 communication artifacts that we created to publish everything to the company. And we had more than 3,000 features, a.k.a.
8,500 user stories that were pushed into our IGA tool. So, it was a vast amount of things we did to get to here. This is very simplified and you all know that. How our landscape looks like today. We're fully integrated with HR. Everything is automated. We also integrated with source systems for CM. And everything goes into IM Shop. And we gave it a branding. It's Empower ID in the backbone. We gave it a branding that really screams this is a self-service tool. This is a shop. You go there. You shop for identities. You shop for your access.
So, they do everything. Lifecycle management, access management, access governance, application management, group management, distribution lists, non-personal mailboxes. All of that is within IM Shop. And then we have various IDPs, an active directory, on-premise, mainly supporting our factories. Then we have something called Enterprise ID. That's Entra ID, our main IDP that we're using. And we have something called Business ID, CM, where we support our business, our suppliers, our dealers, our customers. They get their identity here. But they're also managed all in one tool.
And then our application is consuming that. Something that's very unique in our size company, we don't have hybrid.
So, we do have two completely separate identity zones between factory and office. They don't talk to each other. They're not synchronized. That's it. It was very hard for the business to grab that, to understand that their client is not talking to a file share anymore. You need a different identity to connect to your file share. What did we gain? There's a lot of security gains that we had. We have mandatory phishing-resistant MFA. And we have very, very few exceptions still.
So, we really hold our ground when it comes to MFA, especially on Entra ID. We have full M365 integration and transformation of digital workplace. As I mentioned, everything went to Intune. Everything is with Hello for Business. Seamless MFA on the highest security level that we can provide with Microsoft. We have unified management of our access and also the governance of the access with Empower ID, our IGA tool. Non-hybrid setup, which provides us with the segregation from office and factory. Especially in our business, it's super important to keep the factory protected.
But also to protect the office from the factory. We have a mandatory usage of Entra ID and SSO. And I'm still very thankful to my former boss for going to our board of management and telling them, Please give me the mandate. I need your mandate.
So, everything goes to one IDP and goes to one IGA solution. So, I had the backing from the highest management over the last four years to say, This is what we have to do. And as mentioned various times, there is a lot of security benefits that come with self-service.
So, we're still pushing for this to even enhance in the future. What was hard, and this is actually now the pain. I'm not going through all of this. You can read it yourself. Mindset. The two former people that were talking before me said the same thing. User adaption is hard. And in a way that we had to do it while everything else was changing was crazy. Nobody understood what was going on anymore. They had four or five identities to juggle every single user. Some applications had migrated already. Some were still with Mercedes.
They had to look at the login screen if there was still a car or a truck in order to know which credentials to use. Yeah.
Then, we are a company that produces trucks. So, we have a production environment that really works differently. And that needs to be protected in a way that all migrations can't break production.
So, especially in Active Directory migration, that was quite hard to achieve. And there are other complex topics we had to solve when it comes to the non-hybrid scenarios. Making MFA possible on the clients on the shop floor that are somehow still connecting to Outlook. How do you do that when the factory worker doesn't have a device?
So, we use FIDO tool keys. Works. But it's different.
Then, we have something called the field as truck company where we try to repair trucks on the street. And those people were complaining. I cannot do MFA. How can my application go to the cloud? This is not going to work. It's working. But it's a lot of convincing. It was really hard to get them there.
And then, we had the deadline. And I'm kind of at the fence if that was a good thing or a bad thing. Without the deadline, we would never have made it. But the deadline forced us to do a lot of dirty things. Make it just work. Workflow is there. ILM is integrated. We have five edge cases that don't work. I don't care. Let's move to the next thing. We don't have time. And that brings me today to a situation with escalations. Things aren't working yet. Processes aren't perfect.
I can't live up to the expectation that the company has for a central IM service because I have to do all of that in four years. So, it's a pain.
And also, it was quite good that we had the deadline. And what did we learn? And that's now my last slide.
And then, I hope you have some questions. Oh, I was very fast. I was really very fast.
Well, then, we might have a conversation. That's great. Every time I talked through this, I was completely over the 20 minutes. I was scared of not making the time. My first lesson is invest in communication. Invest in communication and invest in transparency. It was one of the highest budgets we spent was on communication. And we got so much good feedback on this. Because people knew what was going on. We did big events. We invited all the application owners. Come to the table. Talk to us. What's your problem? How can we solve it? And the same goes to making them understand why we're doing.
What is it that you're gaining? What is the good thing? Where are we moving? And why is it the right way? It was tough. It was really tough conversations. It was hard to get, especially also management there. But it was worth every single hour I spent crafting presentations and making sure it was simplified in a way that everybody could understand. Make an easy and followable discovery of the applications and documentation. We started with Excel. They hated us. And they had to redo it three times.
Because, of course, somebody corrupted the Excel sheet. It didn't work anymore. So it's really worth, if you want to do a big-scale application migration, to invest and think on how you want to gather the information.
Then, fourth point, very, very important, and I guess all of you know that. If you choose an IGA vendor, this is your partner for many, many years. Choose wisely. Make sure you're aligned on where you want to get to, how you want to collaborate, see them as a partner, work well together, have your collaboration and your escalations methods in place. That's really key to also being happy with your solution in the future.
Then, management buy-in is key, especially in larger organizations. As I mentioned, I was really happy we had the mandate. I don't know how many times I had to look for the document that had basically this is what they said and this is what happened, and now please move. You have to go to my system. Give your external partners autonomy. And I'm happy I see some of you here. We really tried to build one team.
My own team and what we built already in Diamond Truck is very, very small, so we had a lot of external support from various companies, and we tried the best we could to treat them as equals. Make sure they get management attention, that they're heard, that we really pull into the same direction and there's no, I mean, I'm telling you what to do because whatever, you're just a consultant. That would have killed us, and at the end, I think we did achieve what we achieved because they knew that we trusted them and they also believed we can make it work.
And that created a momentum in our team that actually pulled and pushed the whole thing to the finish line. And the last point was also a lot of mentoring within the team because every problem has a technical solution. We're in IT. We just built one. Negotiating the solution in a secure way is a skill that every IM team should have, in my view. Go sit with them, understand their use case, and then find something that is better than an MFA exception. Yeah. So now we have actually quite a lot of time for conversation, and I hope you have interesting questions that we can answer. First of all.
Thank you. Fabrice? Thanks. I think you nailed on every nail. So in terms of what is important to have in check when you start such a complex endeavor, so congrats and thank you for sharing your experience here. I've only got one question, and it's about the banning of hybrid. I'm just curious why you made that decision because, I mean, I'm working with a lot of manufacturing companies, and being able to enable shop floor to do a simple thing as booking holidays is a necessity. So I'm just wondering why you made that decision, and how did it look like then?
So back in the day, I wasn't part of that decision. I took that decision and made it work. But the main driver of the decision was that our former CISO was convinced we could get rid of Active Directory. And making it the primary identity was absolutely the wrong decision. And the enablement of cloud and cloud first that you can get with getting rid of hybrid was just so enormously attractive to them back in the days that they said, let's just go for it. And once we were on the track, there was no way back. So once we started, we already took this, we can't go back to hybrid.
There were discussions, but it would have been put everything in the bin and start again. And that wasn't an option. Today we're happy. I have a question for you, Anja. Yes. One thing I've always wondered, how did Daimler have such a good corporate culture? Did you guys, did it develop over the project, or was it just baked into the DNA? Because was it all the communication?
I mean, because a lot of big companies have challenges, they have isolated islands, there's a lot of infighting. How do you guys pull as one team where everyone was just trying to reach the goal? That's a good outside-in perspective. Thank you. I think what IT did, because IT was new, the whole IT was built from scratch. So there was no legacy, I don't like you, and IM doesn't talk to HR because they're always in a fight. That just didn't exist. And we had such fast decision-making power that it created a momentum in all IT to push forward.
So it was this common goal, and our former CIO really pushed for this, that we need to move forward. It's progress before perfection. We all have to look at the same direction, get rid of Mercedes. We have to get the separation done. And that really helped pulling us all together and making sure that we stuck together as one team.
Okay, Martin? So with Entra, Join, Machines, and Windows Loft for Business, how did we resolve things like the... Thank you. How did you resolve things like the file shares and legacy applications that only speaks Windows VIA, for example? Can you repeat again? So how did you resolve how to get the users a user-friendly way to access things like file shares? So SMB stores and stuff like that.
Yeah, so there were long discussions with Microsoft about this because there is no solution how you can securely access a file share from an Intune-hosted client. So we just, at the end, we opted into directly integrating it in your directories in the client and using the Active Directory credentials to access it. So we used the same identity on the client. Which is obviously security-wise not perfect, but it works. And we could build... It was Digital Workplace doing that, not my team. We built an application that allows the user to map the files and to use their credentials in a secure way.
Okay, so to Martin, this is the final question, but I have one more left from the chat. Is this a complete separation of IT and OT, so factory and office, without any trust? And did you implement AD tiering models? So yes to the tiering models.
And no, unfortunately, we still have office applications in Active Directory because they couldn't modernize. But on the roadmap, they all have termination dates. They all want and have to modernize. And the goal is to completely separate.
One day, AD will only be for OT. And everything else goes to the cloud. That is the plan. I don't know who asked the question, but the plan is really to segregate completely. And there is no trust between Android and Active Directory.
Okay, so now we need two rounds of applause, first of all, for your presentation.