Your identity provider is the platform everything else depends on, so choosing or replacing one is a long-term decision. Workforce identity platforms now bundle SSO, MFA, lifecycle management, device trust, risk-based access and increasingly governance, privileged access and agent identity features. Suites from large platform vendors compete with independent identity specialists, and many organisations run more than one IdP after mergers or cloud migrations. This vendor-neutral buyer's guide helps you define requirements, compare platforms and plan a proof of concept and migration.
Key takeaways
- Evaluate IdPs on security of the platform itself as much as features: it will be a primary target.
- Core requirements are SSO breadth, phishing-resistant MFA, conditional access, lifecycle and provisioning, session security, admin security and logging.
- Check support for non-human and AI agent identities: workload identity federation, OAuth client management, token exchange and agent registration.
- Plan migration early: application integrations, MFA re-enrolment and coexistence drive most of the cost and risk.
Define requirements
- Which user populations: employees, contractors, partners, customers? Workforce and customer identity often need different platforms. See the CIAM Guide.
- Which applications: SaaS, custom, legacy on-premises (header-based, Kerberos), infrastructure access?
- Which directories and HR sources must be integrated?
- Which devices and operating systems, and what device trust is needed?
- Regulatory, data residency and availability requirements.
Capability areas
| Area | What to look for |
|---|---|
| SSO and federation | OIDC, SAML and legacy protocol support; application catalogue breadth; custom app onboarding effort |
| Authentication | Passkeys and FIDO2, device-bound credentials for admins, certificate-based auth, phishing-resistant enforcement, number-matched push |
| Conditional and risk-based access | Policies using device, location, risk and application sensitivity; continuous access evaluation |
| Lifecycle and provisioning | HR-driven joiner-mover-leaver; SCIM provisioning; group and role management |
| Session security | Session lifetime control, token binding, revocation, detection of token replay |
| Administration security | Granular admin roles, just-in-time admin, approval workflows, admin MFA, configuration change alerts |
| Recovery and help desk | Strong verification options for MFA resets; self-service with safeguards |
| Logging and detection | Complete, exportable logs; built-in identity threat detection; SIEM integration |
| Non-human and AI identities | Workload federation, OAuth client lifecycle, managed secrets, token exchange, agent registration and delegation features |
| Governance | Access requests and reviews, or integration with an IGA platform |
Evaluating the vendor's own security
- How are signing keys protected and rotated? What is the history of security incidents and how were they disclosed?
- How is support staff access to customer tenants controlled and logged?
- What independent certifications and penetration tests are available?
- How quickly can customers revoke sessions and tokens tenant-wide?
Past incidents involving identity providers, such as the Okta support system breach, the OneLogin API key vulnerability and the Microsoft signing key incident, show why this matters.
Questions to ask vendors
- Show us enforcing phishing-resistant MFA for administrators, and what happens when an admin loses their key.
- How do you detect and respond to session cookie theft and token replay?
- How does help-desk MFA reset verification work, and can it be restricted for privileged users?
- How do you support workload identity federation, OAuth clients for services and AI agents acting for users?
- What are your availability commitments and what happens to user access during an outage?
- What does migration from our current IdP involve, and what tooling do you provide?
Red flags
- Admin roles that cannot be scoped, or no just-in-time admin capability.
- Logs that are incomplete, short-retention or costly to export.
- Recovery flows that rely on SMS or knowledge questions with no stronger option.
- Vague answers about signing key protection or support access.
Proof of concept and migration
- Integrate representative apps: a major SaaS app, a custom OIDC app, a legacy app and infrastructure access.
- Test phishing-resistant enrolment and recovery for a pilot group, including admins.
- Test conditional access, session revocation and log export into your SIEM.
- Plan coexistence: federation between old and new IdPs during migration, and a phased MFA re-enrolment.
- Estimate the effort to migrate every application, not just the easy ones.
How NHI Mgmt Group can help
We provide independent requirements, RFP and evaluation support across IAM, IGA, PAM and NHI. Browse vendors in our products directory or contact us.
Related NHI Mgmt Group resources: IdP and SSO Security Guide · Passwordless and Passkeys Guide · Workforce Identity Security Guide · IGA Buyer's Guide