Join our Newsletter — 33% off our NHI Course
Home› Guides› IAM and Identity Provider Buyer’s Guide
Buyer's Guide Identity & Access Management (IAM)

IAM and Identity Provider Buyer’s Guide

← All guides
By Lalit Choda, NHI Mgmt Group Updated 26 September 2026 4 min read
On this page

Your identity provider is the platform everything else depends on, so choosing or replacing one is a long-term decision. Workforce identity platforms now bundle SSO, MFA, lifecycle management, device trust, risk-based access and increasingly governance, privileged access and agent identity features. Suites from large platform vendors compete with independent identity specialists, and many organisations run more than one IdP after mergers or cloud migrations. This vendor-neutral buyer's guide helps you define requirements, compare platforms and plan a proof of concept and migration.

Key takeaways

  • Evaluate IdPs on security of the platform itself as much as features: it will be a primary target.
  • Core requirements are SSO breadth, phishing-resistant MFA, conditional access, lifecycle and provisioning, session security, admin security and logging.
  • Check support for non-human and AI agent identities: workload identity federation, OAuth client management, token exchange and agent registration.
  • Plan migration early: application integrations, MFA re-enrolment and coexistence drive most of the cost and risk.

Define requirements

  • Which user populations: employees, contractors, partners, customers? Workforce and customer identity often need different platforms. See the CIAM Guide.
  • Which applications: SaaS, custom, legacy on-premises (header-based, Kerberos), infrastructure access?
  • Which directories and HR sources must be integrated?
  • Which devices and operating systems, and what device trust is needed?
  • Regulatory, data residency and availability requirements.

Capability areas

AreaWhat to look for
SSO and federationOIDC, SAML and legacy protocol support; application catalogue breadth; custom app onboarding effort
AuthenticationPasskeys and FIDO2, device-bound credentials for admins, certificate-based auth, phishing-resistant enforcement, number-matched push
Conditional and risk-based accessPolicies using device, location, risk and application sensitivity; continuous access evaluation
Lifecycle and provisioningHR-driven joiner-mover-leaver; SCIM provisioning; group and role management
Session securitySession lifetime control, token binding, revocation, detection of token replay
Administration securityGranular admin roles, just-in-time admin, approval workflows, admin MFA, configuration change alerts
Recovery and help deskStrong verification options for MFA resets; self-service with safeguards
Logging and detectionComplete, exportable logs; built-in identity threat detection; SIEM integration
Non-human and AI identitiesWorkload federation, OAuth client lifecycle, managed secrets, token exchange, agent registration and delegation features
GovernanceAccess requests and reviews, or integration with an IGA platform

Evaluating the vendor's own security

  • How are signing keys protected and rotated? What is the history of security incidents and how were they disclosed?
  • How is support staff access to customer tenants controlled and logged?
  • What independent certifications and penetration tests are available?
  • How quickly can customers revoke sessions and tokens tenant-wide?

Past incidents involving identity providers, such as the Okta support system breach, the OneLogin API key vulnerability and the Microsoft signing key incident, show why this matters.

Questions to ask vendors

  • Show us enforcing phishing-resistant MFA for administrators, and what happens when an admin loses their key.
  • How do you detect and respond to session cookie theft and token replay?
  • How does help-desk MFA reset verification work, and can it be restricted for privileged users?
  • How do you support workload identity federation, OAuth clients for services and AI agents acting for users?
  • What are your availability commitments and what happens to user access during an outage?
  • What does migration from our current IdP involve, and what tooling do you provide?

Red flags

  • Admin roles that cannot be scoped, or no just-in-time admin capability.
  • Logs that are incomplete, short-retention or costly to export.
  • Recovery flows that rely on SMS or knowledge questions with no stronger option.
  • Vague answers about signing key protection or support access.

Proof of concept and migration

  1. Integrate representative apps: a major SaaS app, a custom OIDC app, a legacy app and infrastructure access.
  2. Test phishing-resistant enrolment and recovery for a pilot group, including admins.
  3. Test conditional access, session revocation and log export into your SIEM.
  4. Plan coexistence: federation between old and new IdPs during migration, and a phased MFA re-enrolment.
  5. Estimate the effort to migrate every application, not just the easy ones.

How NHI Mgmt Group can help

We provide independent requirements, RFP and evaluation support across IAM, IGA, PAM and NHI. Browse vendors in our products directory or contact us.

Related NHI Mgmt Group resources: IdP and SSO Security Guide · Passwordless and Passkeys Guide · Workforce Identity Security Guide · IGA Buyer's Guide

Explore further

Sign up to our weekly newsletter — get 33% off our NHI Foundation Level Course

    NHIMG Editorial Note
    Written and reviewed by Lalit Choda, NHI Mgmt Group. Last updated 26 September 2026.
    NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org