By NHI Mgmt Group Editorial TeamBased on RSA Security: “State Government Agency Enhances Security of Workforce and Citizen Access with RSA and Microsoft Integration” (September 19, 2025)

TL;DR: A US state agency modernised workforce and citizen access with RSA and Microsoft integration to support passwordless sign-in, hybrid identity management, BYOD protection, and secure proofing for onboarding and recovery, according to RSA Security. The underlying lesson is that convenience, fraud resistance, and hybrid interoperability now have to be governed together, not treated as separate IAM projects.


At a glance

What this is: RSA Security describes how a US state government agency modernised access for employees and citizens with hybrid IAM controls spanning Microsoft Entra ID, passwordless authentication, BYOD protection, and identity proofing.

Why it matters: This matters because government identity programmes increasingly have to secure workforce, partner, and citizen access in one operating model without weakening fraud resistance, device trust, or recovery governance.


Context

State identity security modernisation is no longer just a workforce IAM problem. This case is about a state agency that needed to protect employee and citizen access while operating across Microsoft-centric infrastructure, hybrid cloud, legacy systems, and mobile devices.

The security gap is broader than authentication alone. Secure onboarding, credential enrollment, passwordless access, recovery, and device trust all sit in the same lifecycle, so any one weak control can undermine the whole identity programme. The article reflects a typical public-sector pattern rather than an edge case.


Key questions

Q: How should security teams govern cloud IAM across hybrid environments?

A: Security teams should govern cloud IAM by separating human, contractor, and machine identity workflows, then assigning each a lifecycle owner, review cadence, and expiry rule. The key is to treat cloud identity as a distributed control plane, not a single directory problem. That approach makes access scope, offboarding, and privilege reviews more reliable across AWS, Azure, and on-prem systems.

Q: Why do passwordless programmes need stronger identity proofing rather than just fewer login prompts?

A: Because the control objective changes from convenience to assurance. If the identity binding is weak, passwordless simply moves the failure from the password field to enrollment, recovery, or device registration. Strong identity proofing is what lets the organisation trust that the biometric or credential being presented belongs to the right person.

Q: What breaks when organisations allow BYOD without tight session and device controls?

A: Without strong controls, access can persist after a device is lost, stolen, or left unattended. Shared credentials, uncontrolled logon times, and missing device records make it harder to tell who is accessing the network and from where. That weakens incident response, increases the chance of unauthorised access, and makes it difficult to remove access cleanly when users leave.

Q: When should agencies re-evaluate their identity recovery process?

A: Any time recovery becomes easier than routine authentication, or when citizen and workforce recovery use the same low-assurance path. Recovery is a high-risk control point because it can bypass normal sign-in protections, so agencies should review it whenever fraud pressure, device diversity, or hybrid access expands.


Technical breakdown

Hybrid identity management across cloud and legacy environments

Hybrid identity management is the operating model where cloud, on-premises, and legacy access paths are governed together rather than as separate stacks. In this article, the key issue is interoperability with Microsoft Entra ID while preserving controls for employees, third parties, and citizens. That means authentication, federation, and recovery cannot be designed only for the cloud front door. They have to account for the full access path, including older systems that still matter operationally.

Practical implication: map each identity flow end to end before adding new sign-in methods so legacy dependencies do not create ungoverned exceptions.

Passwordless authentication and adaptive risk controls

Passwordless authentication removes the password as the primary verifier, but it does not remove the need for strong assurance. The article pairs passwordless access with adaptive authentication, which uses contextual signals such as device state, user behaviour, and environment to decide whether to step up or allow access. For government access, that matters because convenience, continuity, and fraud resistance must be balanced at the policy layer, not in the user experience alone.

Practical implication: apply risk-based policy to passwordless journeys so assurance can increase when device or behaviour signals degrade.

Identity proofing for enrollment and recovery

Identity proofing is the verification step that confirms a person is who they claim to be during onboarding or recovery. The article treats enrollment and credential recovery as high-risk lifecycle events because they are common targets for impersonation and fraud. Secure proofing closes the gap between initial authentication and trusted identity creation, especially when citizens or employees need to regain access after account loss. In public-sector programmes, recovery is often the weak link because it can be easier to exploit than first-time login.

Practical implication: strengthen proofing workflows for recovery as tightly as onboarding, because account reset paths often carry higher fraud exposure than login.


Threat narrative

Attacker objective: The objective is to obtain trusted access to government and constituent systems by abusing weak onboarding, recovery, or device trust controls.

  1. Entry begins at onboarding, recovery, or device access paths where an attacker can impersonate a legitimate user or exploit weak identity validation.
  2. Credential or session abuse follows if proofing, authentication, or BYOD trust checks are too permissive for high-risk accounts.
  3. Impact occurs when fraudulent access or compromised devices reach sensitive government and constituent data through trusted identity channels.
  • Poland ArcGIS password leak 2023: An ArcGIS login emailed in 2020 was published from stolen mail in 2023 and still worked, exposing Polish military and infrastructure maps.
  • Indian government breach 2021: Sakura Samurai found exposed .git and .env files across Indian government sites, leaking 35 credential pairs, private keys and personal data.

Read and download The State of NHI & AI Agent Breach Report 2026, covering 200+ breaches impacting Non-Human Identities including AI Agents.


NHI Mgmt Group analysis

Hybrid IAM is now a governance problem, not a product integration problem. The article shows that government identity programmes have to coordinate cloud authentication, legacy interoperability, recovery, and device trust as one control plane. That is the real challenge because failure in any one path can compromise the whole access model. Practitioners should treat hybrid IAM as a lifecycle governance discipline, not a collection of sign-in features.

Identity proofing has become a core control for public-sector fraud resistance. When onboarding and recovery are open to impersonation, authentication strength later in the journey cannot compensate. The article makes clear that secure verification at enrollment and recovery is part of the access architecture, not an adjacent administrative step. Practitioners should evaluate proofing as a risk control for the identity lifecycle itself.

Passwordless is only safe when recovery and device trust are equally governed. Removing passwords reduces one attack path, but it shifts pressure onto registration, recovery, and endpoint confidence. In a state environment with BYOD and citizens in scope, that means the assurance model has to follow the user across devices and lifecycle events. Practitioners should stop treating passwordless as a standalone modernization goal.

Hybrid identity programmes succeed when operational friction is designed out of the control model. The article ties faster deployment and reduced support burden to the integration of identity and device controls across Microsoft Entra ID and adjacent processes. That signals a broader market direction: agencies will adopt controls that reduce complexity only if they also preserve governance. Practitioners should prioritise controls that simplify administration without weakening verification.

What this signals

Hybrid identity governance: public-sector programmes now have to treat authentication, proofing, device trust, and recovery as one policy stack. If those controls are managed separately, the strongest sign-in method in the environment can still be bypassed by a weaker enrollment or reset path.

The practical shift for IAM teams is to evaluate access assurance by lifecycle stage, not by login method alone. Passwordless sign-in reduces friction, but the real control boundary sits in onboarding and recovery, where identity claims are first established and later revalidated.


For practitioners

  • Map hybrid identity flows end to end Document how employees, citizens, and third parties move through onboarding, authentication, recovery, and privileged access across cloud and legacy environments. Identify every point where Microsoft Entra ID, on-premises systems, or mobile access changes the assurance level.
  • Harden identity proofing for enrollment and reset Require stronger proofing for account creation, credential enrollment, and recovery than for routine sign-in. Separate low-risk login from high-risk identity proofing so fraud resistance is built into the lifecycle rather than bolted onto access requests.
  • Apply risk signals to passwordless journeys Use adaptive authentication rules that react to device posture, unusual context, and behavioural anomalies instead of assuming passwordless access is automatically trustworthy. Tie step-up decisions to the sensitivity of the resource and the trust level of the device.
  • Set BYOD trust boundaries before rollout Define which government data and functions can be reached from personal devices, then enforce mobile access controls consistently across managed and unmanaged endpoints. Make device trust a policy decision, not an exception handled case by case.
  • Measure recovery as a security control Track recovery volume, recovery failure rates, and high-risk reset paths as governance signals. If recovery is easier to complete than a normal authentication event, the identity programme is creating a fraud path instead of a trust gate.

Key takeaways

  • The article shows that modern government IAM has to coordinate cloud and legacy access paths, not just improve sign-in convenience.
  • Identity proofing for enrollment and recovery is a core security control when fraud and impersonation are part of the threat model.
  • Passwordless access only improves security when device trust and lifecycle governance are enforced with equal discipline.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

NIST CSF 2.0 and NIST SP 800-63 set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
NIST CSF 2.0PR.AA-05 — Access Permissions, Entitlements and AuthorizationsThe article is about governing access across hybrid identity paths and user groups.
PR.DS-10 — Data-in-Transit ProtectionHybrid government access spans sensitive data flows across mobile, cloud, and legacy systems.
DE.CM-01 — Networks and network services are monitored to find potentially adverse eventsAdaptive authentication and BYOD protection depend on observing risky behaviour and endpoint state.
Recommendation — Apply PR.AA-05 to keep permissions and authentication aligned across cloud, legacy, and citizen access flows. Protect identity and session traffic in transit wherever users move between managed and unmanaged networks. Monitor access and device signals continuously so anomalous identity activity is detected early.
NIST SP 800-63SP 800-63A — Enrollment and Identity ProofingIdentity proofing during enrollment and recovery is a central control in the article.
SP 800-63B — AuthenticationPasswordless and adaptive authentication are core themes in the article.
Recommendation — Use SP 800-63A to strengthen proofing for onboarding and account recovery workflows. Use SP 800-63B to align authentication assurance with passwordless and risk-based access decisions.

Key terms

  • Hybrid Identity Management: Hybrid Identity Management is the coordinated control of identities across on-premises and cloud environments. It links directories, authentication, authorization, and lifecycle processes so people, applications, and machines can access resources consistently. Technically, it spans federation, synchronization, policy enforcement, and governance across multiple identity domains.
  • Identity proofing: The process of verifying that a person is who they claim to be before granting or restoring access. In higher-risk recovery paths, proofing can include stronger evidence checks such as government ID validation or liveness-based facial verification so the assurance level matches the sensitivity of the request.
  • Passwordless Authentication: An authentication approach that removes passwords and uses a device-bound cryptographic key plus local user verification. It reduces phishing and replay risk, but it only improves assurance when enrollment, recovery, and revocation are tightly governed.
  • Adaptive Authentication: Adaptive authentication changes the strength of login checks based on context such as device, location, source network, and session history. It helps IAM teams respond to suspicious access without forcing every user through the same high-friction path.

Deepen your knowledge

NHI governance, agentic AI identity, and machine identity lifecycle are core topics in our NHI Foundation Level course, the industry's only accredited NHI security programme. If you are building or maturing an IAM programme, it is worth exploring.
NHIMG Editorial Note
Published by the NHIMG editorial team on June 24, 2026.
Updated on October 11, 2026.
NHI Mgmt Group, the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org