Because each additional platform introduces its own policy model, lifecycle path, and troubleshooting burden. When those paths are duplicated across tools, the work expands faster than staffing, so the marginal value of each new hire declines instead of rising.
Why mixed fleets slow teams as they grow
Mixed fleets usually start as a practical compromise, but at scale they create duplicated policy, duplicated admin work, and duplicated exception handling. Each platform adds another way to provision users, recover access, audit changes, and troubleshoot failures. The result is not just more tooling, it is more coordination overhead per person and per system.
That overhead compounds because the team must remember which control plane owns which account, which approval path applies, and which recovery process is safe to use. In small teams, that friction is tolerable. In larger teams, it becomes a tax on every onboarding, offboarding, escalation, and incident investigation.
Why dual identity providers create policy and lifecycle drag
Two identity providers mean two sets of roles, conditional access rules, federation settings, session controls, and recovery procedures. Even when the two platforms are integrated, they rarely behave identically, so teams spend time translating policy intent between systems instead of working from one consistent source of truth.
The lifecycle burden is often the bigger problem. Joiner, mover, leaver events must be handled in both places, and gaps appear when one system is updated before the other. That is why identity platform consolidation often improves throughput more than it improves security: it removes translation work, reduces misaligned entitlements, and shortens the time spent verifying whether a user has the right access in the right place.
For teams evaluating whether duplication is acceptable, the IAM and Identity Provider Buyer's Guide is a useful way to frame the operational differences between a clean standardised stack and a fragmented one.
Why the productivity loss gets worse, not better, at scale
Scale exposes the hidden cost of inconsistency. One team may document access one way, another may troubleshoot the same issue differently, and support staff end up learning two versions of the same process. That slows response times, increases handoffs, and raises the chance that work is redone because one system does not reflect the state of the other.
Fragmentation also increases the volume of edge cases. The more identities, apps, and admins that span multiple platforms, the more likely it is that an access request, token issue, or recovery flow will need manual comparison across systems. At that point, productivity declines because more effort goes into coordination than into actual delivery.
When identity operations are already stretched, the practical lesson from incidents is clear: weak or duplicated control paths are easy to miss until they are exploited. Events such as the Okta support system breach 2023 and the Cloudflare Thanksgiving breach 2023 show how stale or poorly managed identity paths can create downstream work and security exposure at the same time.
Risk and Threat Considerations
Mixed identity fleets do more than slow administration, they widen the number of places where drift, stale access, and inconsistent recovery can hide. That makes it easier for compromised accounts, mis-set permissions, or forgotten service credentials to persist longer than they should, and harder for teams to prove which system is authoritative.
Failure mechanism: Policy divergence and lifecycle gaps create inconsistent enforcement, so access can remain valid in one provider after it was changed or removed in another. Over time, that creates extra work for support teams and a larger attack surface for account takeover or token abuse.
Impact: Productivity drops because every exception requires manual reconciliation, while security teams inherit more uncertainty during audits, incidents, and offboarding. The organisation pays twice: once in slower delivery, and again in higher exposure to orphaned access and troubleshooting overhead.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
NIST CSF 2.0 and NIST SP 800-53 Rev 5 set the technical controls, while ISO/IEC 27001:2022 defines the regulatory obligations.
| Framework | Control / Reference | Relevance |
|---|---|---|
| NIST CSF 2.0 | GV.SC-01 — Supply Chain Risk Management | Mixed identity providers create dependency and concentration risk across access operations. |
| PR.AA-02 — Identity Management, Authentication and Access Control | Dual IdPs directly affect authentication, access control, and lifecycle consistency. | |
| Recommendation — Map identity platform dependencies and reduce duplicated control paths. Standardize authentication and access control across a single authoritative identity plane. | ||
| NIST SP 800-53 Rev 5 | IA-2 — Identification and Authentication (Organizational Users) | Dual identity providers complicate user authentication and support recovery paths. |
| IA-5 — Authenticator Management | Duplicate providers increase credential lifecycle and recovery burden. | |
| Recommendation — Consolidate user authentication flows and remove redundant identity enforcement points. Centralize authenticator lifecycle controls and align rotation, reset, and revocation. | ||
| ISO/IEC 27001:2022 | A.5.16 — Identity management | Mixed fleets create inconsistent identity ownership and administration across platforms. |
| Recommendation — Define one identity ownership model and keep lifecycle responsibility consistent. | ||
Practitioner Guidance
What to verify: Confirm which identity provider is authoritative for provisioning, authentication, federation, and deprovisioning. If two systems are unavoidable, document a single owner for each lifecycle step so support does not have to guess where the source of truth lives.
What to prioritise: Standardise the highest-friction journeys first, usually joiner-mover-leaver, password and MFA recovery, and federation troubleshooting. Those are the flows that consume the most time when platforms differ.
Practitioner takeaway: Mixed fleets are not just a tooling preference issue, they are an operating model issue. The more a team has to translate identity state between systems, the more headcount is absorbed by coordination instead of output.
Related resources from NHI Mgmt Group
Deepen Your Knowledge
Free weekly newsletter
Subscribe to the NHI & AI Identity Journal
The latest on NHI and Agentic AI security – articles, research, breaches, news and events every week.
Bonus 33% off our NHI Course when you subscribe.
Reviewed and updated by the NHIMG editorial team on October 8, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org