Case 02 / Systems integrator, public sector
Federated SSO and domain-locked authentication across programs
Cloud PlatformDefenseTelecom
- Challenge
- Programs federated with Google, Microsoft and Apple in inconsistent ways, and no one could state which origins were allowed to start an auth flow.
- Approach
- SSO providers are registered centrally, domains and origins are allowlisted per application, and registration is either automatic or admin-approved depending on the program's clearance rules.
5
identity providers unified
100%
origins explicitly allowlisted
-80%
identity review effort per launch