Capability areas
Phishing-resistant authentication and passkeys (14)
In: passkey sign-in on platform authenticators, roaming security keys (USB, NFC, Bluetooth), synced versus device-bound passkey controls, cross-device sign-in, user verification, conditional mediation, smart card certificate sign-in, desktop OS login, shared and kiosk devices, relying party ID design, attestation and authenticator allow/block lists, server certification status, and alternatives for users who cannot use biometrics or lack a supported authenticator. Out: enrollment and recovery flows, which are covered under ENR, and policy rules that decide when a method is required, which are covered under POL.
Enrollment and account recovery (13)
In: passwordless first enrollment, enrollment prompts for existing users, multiple named authenticators, administrator pre-registration of keys, identity proofing before enrollment, single-use expiring enrollment links, new-device enrollment rules, lost-device self-recovery, helpdesk-assisted recovery with caller verification, temporary access passes, recovery codes, revocation of lost authenticators, and user notifications. Out: general helpdesk staffing and support SLAs.
Adaptive access policy and session control (12)
In: policy per application and group, allowed authenticator types and assurance levels, step-up for sensitive apps and actions, risk signals (location, IP reputation, impossible travel), device trust from endpoint tools, disabling SMS, voice and email codes, enforcing phishing-resistant-only groups, rate limiting of failed sign-in and recovery attempts, session lifetime, reauthentication, continuous session evaluation, and behavior when the service is degraded so it does not fall back to weaker methods. Out: post-authentication threat detection, which is covered under ITD.
Single sign-on and application federation (11)
In: acting as identity provider over SAML 2.0, OpenID Connect and WS-Federation, acting as the passwordless step for an existing identity provider, header-based and agent-based access to legacy and home-grown apps, VPN and RADIUS sign-in, verified prebuilt integrations for the buyer's named apps, interoperability testing, and token signing key rotation. Out: the vendor's own product SSO for its admin console, which is covered in the security module.
Joiner-mover-leaver lifecycle and provisioning (13)
In: the HR system as authoritative source, joiner, mover and leaver automation, SCIM 2.0 and LDAP provisioning, provisioning to apps without SCIM, deprovisioning that blocks sign-in and ends sessions, contractor, partner and seasonal populations with sponsors and end dates, self-service access requests, handling of dirty or duplicate HR data, and integration points to identity governance and privileged access tools. Out: full certification campaigns and privileged session vaulting, which belong to separate governance and PAM evaluations.
Directory and hybrid architecture (10)
In: the cloud or universal directory, coexistence with on-premises Active Directory and LDAP, hybrid agents and their failure behavior, write-back, multi-domain and multi-forest support, groups populated by user attributes, and the blast radius and failure isolation of the directory and authentication service as a dependency. Out: generic hosting regions and DR commitments, which are covered by the deployment-hosting and business-continuity-dr modules.
Identity threat detection and response (11)
In: post-authentication risk evaluation, session and token theft detection, anomaly signals, identity security posture (dormant accounts, over-privilege, MFA and passkey coverage gaps), automated response such as session and token revocation, and two-way signal exchange with the SIEM and XDR including event delivery latency. Out: the vendor's own SOC and vulnerability management, which are covered in the security module.
Machine, workload and AI-agent identity (10)
In: OAuth client-credentials and workload identity federation for services and APIs, scoped short-lived credential issuance, discovery and inventory of service accounts and other non-human identities, ownership assignment, secrets handling, rotation, revocation, and identities for AI agents acting on a user's behalf with delegated, limited scope. Out: controls over AI agents inside the vendor's own product, which are covered by the ai-agentic-autonomy module.
Migration, coexistence and password retirement (9)
In: running the new platform in parallel with the incumbent identity provider, cutover by application tranche, coexistence of password and passkey users, removal of passwords by user or group once a passkey is held, import of existing WebAuthn public-key credentials, account linking without duplicate users, and migration tooling for app configurations and policies. Out: contract-end data export, which is covered by the migration-exit module.
Administration, delegation and audit (11)
In: the admin console, scoped roles such as a helpdesk role that can recover users but cannot change policy, delegated administration by business unit, phishing-resistant sign-in for administrators, configuration export and change control, non-production tenants and promotion to production, authentication and admin event logs with before and after values, tamper protection for logs, and reporting on enrollment, method use, failures and recovery. Out: generic log retention commitments and vendor staff access, which are covered in the security module.
Sign-in experience and developer tooling (8)
In: no-code configuration of registration, sign-in, recovery and step-up flows with versioning and preview, editable flow templates, hosted sign-in pages branded and served on the buyer's domain, web, iOS and Android SDKs that handle WebAuthn and passkey prompts, the API for users, authenticators and policies, and lifecycle and authentication webhooks. Out: generic API availability, rate limits and deprecation policy, which are covered by the integration module.